Managed IAM handles the setup, configuration, and ongoing management of your organization's identity platform (JumpCloud), so your team can focus on business priorities. It's a collaborative service—Deel IT manages the environment on your behalf, but your input shapes how it works.
- Service: Managed Identity and Access Management (IAM)
- Availability: Global
- Platform: JumpCloud
- Type: Ongoing managed service
What's Included
- Setup and environment configuration
- User provisioning integration between Deel and your IAM platform
- User and group management
- Application configuration and Single Sign-On (SSO)
- Multi-Factor Authentication (MFA) and access policies
- Day-to-day changes and updates on request
In this article
Scope of Service
Setup and Onboarding
Deel IT configures the user's IAM environment from the start — tenant setup, baseline access and security configuration, and the foundation for groups and applications — informed by requirements gathered at kickoff: applications in use, access structure, and security goals.
Provisioning Integration
Deel IT sets up the integration between Deel and the IAM platform so that users with a valid work email on their Deel profile provision and deprovision from Deel as the source of truth. Once configured, user lifecycle events in Deel drive account creation and deactivation in the IAM platform. The user is responsible for ensuring work emails are populated on its Deel profiles.
User and Group Management
Deel IT configures user groups to the structure defined by the user admin, and maintains and updates them on request.
Application Configuration
Deel IT configures the user's applications in the IAM platform and maps them to the correct user groups. Applications are set up in the way each one supports:
- Single sign-on (SSO) - one secure login across applications, via SAML or OIDC
- Automated provisioning (SCIM) - where supported, accounts are created, updated, and removed automatically as users change in the IAM platform
- Bookmarks - for applications without SSO or SCIM support, access from the user portal without deeper integration
Application Plans: The user is responsible for maintaining the application plan tiers that support SSO and automated provisioning. Where a plan lacks these capabilities, Deel IT configures the application as a bookmark instead.
Administrative Access: Deel IT does not take admin access to the user's applications. The user holds admin access and provides the technical details Deel IT requires, such as SSO URLs, certificates, and metadata.
Access and MFA Policies
Deel IT configures and enforces MFA policies and conditional access rules, applied to the user groups established at onboarding, to the user's security requirements or recommended best practices.
Day-to-Day Operations
Deel IT implements requested changes to the environment such as new application configurations, group updates, and policy modifications. Requests must be submitted through the official Deel IT support channel (techsupport@deel.com) and are validated and implemented by Deel IT. Routine changes are included; wholesale redesign of the access environment is handled separately.
IAM-Related End-User Support
Deel IT can assist with IAM-related end-user issues: password resets, account unlocks, and registration help. (Only when requested by the user's point of contact) There is no direct line from end users to Deel IT under Managed IAM; direct, always-on end-user support is delivered under 24/7 Tech Support.
What's Not Included
- License management
- Custom integrations or scripting beyond platform capabilities
- Direct end-user support (unless specifically requested)
- On-premise implementations
- Architectural or strategic consulting