Automated JumpCloud MFA Coverage Audits
Every Monday, WebRun opens the JumpCloud console, checks every active user for MFA enrollment, notes which groups and applications each unprotected account can reach, records the gaps in Airtable with a first seen date, and posts the list to Telegram worst first.
How do I find users who still have no MFA enrolled?
WebRun audits your JumpCloud directory every Monday, checking every active user for MFA enrollment and noting the groups and applications each unprotected account can reach. It records the gaps in Airtable with a first seen date and posts the list to Telegram, ordered by how much access is exposed.
- Coverage gaps get closed instead of assumed
- Every unprotected account named with the apps it can reach
- A dated audit trail showing how long each gap stayed open
Built for IT admins · security teams · MSPs · compliance managers
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
console.jumpcloud.comin a real browser with your saved login - no setup, no API keys. -
1
JumpCloud - audit MFA enrollment
WebRun opens JumpCloud to audit MFA enrollment. - Open the JumpCloud console and list every active user account
- For each user, check whether MFA is enrolled and which policies apply to them
- For users with no MFA enrolled, note the user groups they belong to
- Note the applications those groups grant, so the reach of each gap is clear
Done when Every active user has been checked for MFA enrollment and their reach recorded.
-
2
Airtable - record the coverage gaps
WebRun opens Airtable to record the coverage gaps. - Open your security base and upsert one row per unprotected account
- Fill in user, groups, applications reachable, and the date the gap was first seen
- Mark rows resolved when a user no longer appears in this week's list
- Keep resolved rows so the audit history stands up to review
Done when Every current gap has a dated row and closed gaps are marked resolved.
-
3
Telegram - post the unprotected accounts
WebRun opens Telegram to post the unprotected accounts. - Post this week's unprotected accounts to your IT channel
- Put the accounts reaching the most sensitive applications at the top
- Show how many days each gap has been open and the week over week count
- Leave enforcement to your admins. WebRun never changes a policy or a user
Done when The IT channel has this week's coverage list, worst first.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it enforce MFA or suspend an account?
No. WebRun only reads user, group, and policy state in JumpCloud. It never enrolls a user, changes a policy, suspends an account, or emails anyone. Enforcement stays with your admins.
Does it contact the users who are missing MFA?
No. The list goes to your IT channel and your Airtable base only. Nobody outside your team receives a message, so you decide how and when to chase each person.
How do I know a gap actually got closed?
Each account carries a first seen date in Airtable. When a user enrolls, they drop out of the live list and their row is marked resolved, so the audit trail shows how long the gap was open.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.