Skip to main content

JumpCloud Go & JumpCloud Protect Setup

This guide walks through registering JumpCloud Go on your managed computer and installing JumpCloud Protect on your mobile device. Both are part of Legion's Zero Trust device and identity stack, and most employees will need to complete each of them once.

1. What is JumpCloud Go?

JumpCloud Go is passwordless authentication for your managed computer. Once your device is registered, you verify your identity with your device's built-in authenticator (Touch ID, Windows Hello, or equivalent) instead of typing your email, password, and MFA code every time you access a JumpCloud-protected resource.

Registration is valid for 12 hours at a time, after which you'll be asked to verify again.

2. Registering JumpCloud Go

Complete this on the computer you use for work. You'll need the JumpCloud Go browser extension, which the JumpCloud agent installs automatically on managed devices.

  1. Open Google Chrome on your managed device.
  2. Go to the JumpCloud User Portal: console.jumpcloud.com/userconsole.
  3. If you land on the Administrator Portal login, click User Portal Login in the top left.
  4. Click Register Device.
  5. Enter your Legion company email address (firstname@legionsecurity.ai) and click Continue.
  6. Enter your password and click Log in.
  7. If prompted, approve the MFA request using your configured authentication method.
  8. The Passwordless Login screen confirms your device is registered, and you'll be redirected to the User Portal.

Note: You'll be asked to re-register any time you change your JumpCloud password, or if you intentionally log out of JumpCloud Go from Security > Multi-factor Authentication in the User Portal. If the Register Device button doesn't appear at all, contact IT — JumpCloud Go may not yet be enabled for your account.

3. What is JumpCloud Protect?

JumpCloud Protect is the companion mobile app (iOS and Android) used for Multi-Factor Authentication. Once installed and enrolled, it can approve MFA login requests as a push notification or generate a time-based verification code (TOTP) — you enroll each method separately. On enrolled devices, it also supports JumpCloud Go for Mobile, enabling passwordless access from your phone.

4. Installing and Setting Up JumpCloud Protect

Step 1 — Install the app

  1. On your mobile device, open the App Store (iOS) or Google Play Store (Android).
  2. Search for JumpCloud Protect and install it.
  3. Open the app once installed and allow camera and notification permissions when prompted — both are required to enroll and to receive push approvals.

Step 2 — Enroll for Push MFA

  1. On your computer, go to the User Portal: console.jumpcloud.com and log in.
  2. Navigate to Security > Multi-factor Authentication > JumpCloud Protect Mobile Push and click Enroll Device.
  3. A QR code appears in the User Portal.
  4. In the JumpCloud Protect app, tap + Add Account and scan the QR code (or tap Enter Code Instead in the portal to enter the details manually).
  5. A green checkmark in the app confirms the device is verified. Tap Done in both the app and the User Portal.

Step 3 — Enroll for Verification Code (TOTP), if required

Push and TOTP are enrolled separately. Only complete this step if your role requires a backup verification code method — check with IT if you're unsure.

  1. In the User Portal, go to Security and select the TOTP / Verification Code option.
  2. Scan the QR code shown using the + button in JumpCloud Protect.
  3. Enter the 6-digit code the app generates into the portal and click Submit to complete enrollment.

Note: JumpCloud Protect currently supports enrolling only one device at a time. If you're switching to a new phone, enroll the new device first — before wiping or discarding the old one — or you'll need IT to step in.