> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SAML SSO JumpCloud

# 🔑 **SAML SSO JumpCloud**
> **"Schakel veilige single sign-on in met JumpCloud en Brainframe GRC."**
> *Volg deze stappen om SAML-authenticatie te configureren tussen uw JumpCloud-tenant en Brainframe GRC.*

---

## 1️⃣ De applicatie aanmaken

1. Ga naar de **JumpCloud admin console** → User Authentication → SSO Applications en klik op **Add New Application**.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_10ob3v3.png)




2. Klik op "Select" bij **Custom Application**, en klik op **Next** op het volgende scherm

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_hf1vva.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1kr9iwz.png)
3. Selecteer **Manage Single Sign-On (SSO)** en **Configure SSO with SAML**

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_4c54hs.png)

4. Voer de applicatienaam "Brainframe GRC" in, en voer een beschrijving voor de gebruikers in. Upload een logo of behoud een kleur (laat alle andere instellingen op standaard), klik vervolgens op **Save application** en klik op het volgende scherm op **Configure Application**

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1kmwjxg.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_gazg7x.png)



---

## 2️⃣ De JumpCloud SAML-instellingen configureren

1. Ga naar Brainframe Werkruimte-instellingen > Authenticatie, en schakel de SSO login in om de verschillende SAML-instellingen te ontvangen ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_oppdis.png)

1. Selecteer binnen de nieuw aangemaakte JumpCloud SSO Application het tabblad SSO, en kopieer de "SP Entity ID" en "Default ACL URL" vanuit de Brainframe-instellingen ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_rikso5.png)
2. Zorg ervoor dat u "Assertion" configureert als ondertekeningsmethode ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_v9z0mw.png)
3. Configureer nu in JumpCloud de gebruikersattributen firstname en lastname, evenals het constante attribuut "WorkspaceId" (let op: dit is hoofdlettergevoelig). U vindt de geldige werkruimte-ID in Brainframe ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_gk6izi.png)
4. Klik in JumpCloud op SAVE om de SSO-instellingen af te ronden.




---

## 3️⃣ Brainframe-configuratie

Zodra JumpCloud gereed is, ronden we de Brainframe GRC-kant af in **Werkruimte-instellingen → Authenticatie**.

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/brainframe-grc-07-13-20261217p_hnqsqp.png =756xauto)
1. Kopieer de "IdP URL" vanuit JumpCloud naar het veld "IdP Single sign on (SSO) Login URL" van Brainframe SSO ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_7pq4tm.png)![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_xrtjrw.png)
2. Download het certificaat van de applicatie (open het certificaat en kopieer alles ZONDER de regels **BEGIN/END CERTIFICATE**) → Plak dit in het veld **IdP application certificate** in Brainframe. ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_irqxcb.png)](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_1azgin6.png)
3. Klik nu op **SAVE** in Brainframe om SSO voor deze werkruimte op te slaan en in te schakelen.

| Wanneer een gebruiker tijdens het inloggen zijn e-mailadres invoert, ziet hij nu de SSO-inlogknop voor uw werkruimte. U kunt optioneel controleren of gebruikers na het invoeren van het e-mailadres automatisch worden doorgestuurd naar de SSO-pagina van de IdP (werkt alleen als dit e-mailadres gekoppeld is aan één enkele werkruimte met SSO ingeschakeld).
---

## 4️⃣ Groepen toewijzen en testen

1. Vink de groepen aan die toegang moeten krijgen in de JumpCloud-applicatie en klik op SAVE. ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_ltd5q5.png)

2. Nu kunt u de applicatie testen via de JumpCloud SSO-pagina ![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image_15fq1ij.png)


3.
---

## 5️⃣ Veelvoorkomende fouten en oplossingen

||| ❌ Failed to read asymmetric key: u moet het "IdP application certificate" in de Brainframe GRC-instellingen bijwerken met het BASE64-certificaat van de IdP (zonder de regel BEGIN/END Certificate)


||| ❌ Attributes mismatch → Alle attributen zijn hoofdlettergevoelig (bijv. WorkspaceId moet exact overeenkomen).
