Access & Security Manager Setup Guide

The Access & Security Manager is the administrative hub within JPMorgan Access that allows System Administrators to manage company entitlements, user profiles, and security configurations. This guide covers the key features and setup procedures for administrators responsible for configuring and maintaining their organization's JPMorgan Access environment.

Administrator Roles

JPMorgan Access defines several administrative roles with different levels of authority:

RoleCapabilities
Primary AdminFull control — can activate features, manage all users, configure IP Security, activate Dual Control
Proxy AdminCan review administrative tasks pending approval (if Dual Control is active), manage users within their scope
System AdministratorManage user info, account-level rights, company-level rights (subject to Dual Control if enabled)

User Management

Through the Access & Security Manager, Primary Admins can add additional users to the platform. The user management process involves:

  1. Creating a user profile — Enter user details including name, contact information, and organizational role
  2. Assigning entitlements — Define which products, accounts, and actions the user can access
  3. Setting account-level rights — Specify which accounts the user can view or transact on
  4. Setting company-level rights — Define broader permissions such as reporting access, payment initiation, or approval authority
  5. Configuring daily transaction limits — Set dollar limits for payment initiation and approval
  6. Activating the user — Once configured, activate the user profile to enable login

Entitlements Management

Entitlements are the core access control mechanism in JPMorgan Access. They determine what a user can see and do within the platform. Entitlements can be configured at both the company level and the account level:

IP Security Configuration

IP Security is a critical protective measure that restricts platform access to specific IP addresses or ranges. When enabled, only requests originating from approved IP addresses can access the JPMorgan Access login page. This prevents unauthorized access attempts from unknown locations.

Only Primary Admins can activate IP Security. The configuration involves:

  1. Navigating to the Access & Security tab
  2. Selecting IP Security configuration
  3. Adding approved IP addresses or CIDR ranges
  4. Choosing whether to apply at company level or user level
  5. Activating the IP Security policy

RSA Authenticator Setup

The RSA Authenticator is a mandatory component of JPMorgan Access authentication. Primary Admins must ensure that IP Security is activated alongside the RSA Authenticator, choosing either a company-level or user-level configuration.

For non-authenticator clients (users who do not yet have an RSA token), an activation code must be obtained by calling J.P. Morgan service. Once the activation code is received, the user can complete the token setup process through the "Set Up Your Token" option on the login page.

Dual Control — Administration

Dual Control Administration is an advanced security feature that requires two administrators to approve administrative actions before they take effect. When activated:

Activating Platform Features

New JPMorgan Access users (referred to as Connect users) must review and activate applicable features before building user profiles. The main feature categories that need activation include:

Once these features are activated, administrators can begin building user profiles with appropriate entitlements and access rights.

Best Practices for Administrators

Related Guides