Control access with Access Groups¶
An Access Group links users to computers. Every user in a group can connect to every computer in the group. Groups save you granting access computer by computer and keep sets of users apart, for example one group per office or department.
Applies to¶
- Jump Desktop for Teams Pro plan (up to 5 Access Groups) or Enterprise plan (unlimited). See pricing.
- Team administrators.
How access works¶
A user can connect to a computer when either is true:
- The user and the computer are in the same Access Group.
- The user was added directly to the computer's Remote Access list.
A user or computer can be in several groups. Users can reach every computer shared through any of their groups.
Remote access also requires that:
- The user's remote access is turned on. See Team roles and remote access.
- The team's subscription or trial is active.
Team roles, including Admin, don't grant remote access. Admins need a group or a direct permission too.
Example: to keep three offices separate, create New York, LA, and Tokyo groups and put each office's users and computers in its group.
Create an Access Group¶
- In the Teams dashboard, open your team and click Access Groups.
- Click + (New Access Group).
- Enter a Group Name and click Add.
Add users and computers¶
- In Access Groups, click the group.
- In Remote Access Permissions, click Add users or computers.
- Select users and computers, then click Add.
You can also give access from:
- A computer's page: in Remote Access, add Access Groups or users.
- A user's page: in Remote Access, add Access Groups or computers.
- An installer: when you add computers, choose the Access Groups and users that get access.
Remove users and computers¶
- Open the group.
- In Remote Access Permissions, click the menu (⋮) and click Remove users or computers.
- Select the users and computers, then click Remove.
They lose the access this group gave them. Access from other groups or direct permissions stays.
Removing access blocks new connections but doesn't end sessions already in progress. See End active sessions.
Rename or delete a group¶
- Open the group and click the menu (⋮) next to its name.
- Click Rename access group or Delete access group.
Deleting a group removes the access it granted. The users and computers stay in the team. Sessions already in progress aren't ended.
End active sessions¶
After you remove a user's access, disconnect the sessions they already have open. The dashboard shows active connections only for computers you can connect to yourself, and only if your team's plan includes them.
- In Users, open the user. Active Connections lists the computers they're connected to.
- Open a computer from that list.
- In Current Active Connections, click Disconnect next to the user.
- Click Disconnect to confirm.
The user can reconnect only if they still have access to that computer.
To disconnect all of a user's sessions at once, turn off their remote access. They then can't connect to any of the team's computers until you turn it back on.
To change several groups at once, select them in the Access Groups list and use the actions menu.
Connect Configurations¶
A Connect Configuration assigned to an Access Group applies to every computer in the group. The group's page shows it under Connect settings. For how group and computer configurations combine, see Which configuration applies.
SCIM-managed groups¶
Groups pushed from your identity provider with SCIM show a SCIM badge. For these groups:
- Manage the name and users in your identity provider. Rename access group and Delete access group are unavailable in the dashboard.
- Add and remove computers in the dashboard with Add computers and Remove computers.