All templates

Automated JumpCloud MFA Coverage Audits

Every Monday, WebRun opens the JumpCloud console, checks every active user for MFA enrollment, notes which groups and applications each unprotected account can reach, records the gaps in Airtable with a first seen date, and posts the list to Telegram worst first.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 JumpCloud audit MFA enrollment
2 Airtable record the coverage gaps
3 Telegram post the unprotected accounts
In short

How do I find users who still have no MFA enrolled?

WebRun audits your JumpCloud directory every Monday, checking every active user for MFA enrollment and noting the groups and applications each unprotected account can reach. It records the gaps in Airtable with a first seen date and posts the list to Telegram, ordered by how much access is exposed.

  • Coverage gaps get closed instead of assumed
  • Every unprotected account named with the apps it can reach
  • A dated audit trail showing how long each gap stayed open

Built for IT admins · security teams · MSPs · compliance managers

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens console.jumpcloud.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    JumpCloud - audit MFA enrollment
    jumpcloud.com
    WebRun in JumpCloud: audit MFA enrollment
    WebRun opens JumpCloud to audit MFA enrollment.
    • Open the JumpCloud console and list every active user account
    • For each user, check whether MFA is enrolled and which policies apply to them
    • For users with no MFA enrolled, note the user groups they belong to
    • Note the applications those groups grant, so the reach of each gap is clear

    Done when Every active user has been checked for MFA enrollment and their reach recorded.

  3. 2
    Airtable - record the coverage gaps
    airtable.com
    WebRun in Airtable: record the coverage gaps
    WebRun opens Airtable to record the coverage gaps.
    • Open your security base and upsert one row per unprotected account
    • Fill in user, groups, applications reachable, and the date the gap was first seen
    • Mark rows resolved when a user no longer appears in this week's list
    • Keep resolved rows so the audit history stands up to review

    Done when Every current gap has a dated row and closed gaps are marked resolved.

  4. 3
    Telegram - post the unprotected accounts
    telegram.org
    WebRun in Telegram: post the unprotected accounts
    WebRun opens Telegram to post the unprotected accounts.
    • Post this week's unprotected accounts to your IT channel
    • Put the accounts reaching the most sensitive applications at the top
    • Show how many days each gap has been open and the week over week count
    • Leave enforcement to your admins. WebRun never changes a policy or a user

    Done when The IT channel has this week's coverage list, worst first.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
console.jumpcloud.com
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
MFA gap list · Telegram
OutputWhat each run produces - Every active user with no MFA enrolled, their groups, the applications they can reach, and how long the gap has been open.
Table
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it enforce MFA or suspend an account?

No. WebRun only reads user, group, and policy state in JumpCloud. It never enrolls a user, changes a policy, suspends an account, or emails anyone. Enforcement stays with your admins.

Does it contact the users who are missing MFA?

No. The list goes to your IT channel and your Airtable base only. Nobody outside your team receives a message, so you decide how and when to chase each person.

How do I know a gap actually got closed?

Each account carries a first seen date in Airtable. When a user enrolls, they drop out of the live list and their row is marked resolved, so the audit trail shows how long the gap was open.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.