Access & Security Manager Setup Guide
The Access & Security Manager is the administrative hub within JPMorgan Access that allows System Administrators to manage company entitlements, user profiles, and security configurations. This guide covers the key features and setup procedures for administrators responsible for configuring and maintaining their organization's JPMorgan Access environment.
Administrator Roles
JPMorgan Access defines several administrative roles with different levels of authority:
| Role | Capabilities |
|---|---|
| Primary Admin | Full control — can activate features, manage all users, configure IP Security, activate Dual Control |
| Proxy Admin | Can review administrative tasks pending approval (if Dual Control is active), manage users within their scope |
| System Administrator | Manage user info, account-level rights, company-level rights (subject to Dual Control if enabled) |
User Management
Through the Access & Security Manager, Primary Admins can add additional users to the platform. The user management process involves:
- Creating a user profile — Enter user details including name, contact information, and organizational role
- Assigning entitlements — Define which products, accounts, and actions the user can access
- Setting account-level rights — Specify which accounts the user can view or transact on
- Setting company-level rights — Define broader permissions such as reporting access, payment initiation, or approval authority
- Configuring daily transaction limits — Set dollar limits for payment initiation and approval
- Activating the user — Once configured, activate the user profile to enable login
Entitlements Management
Entitlements are the core access control mechanism in JPMorgan Access. They determine what a user can see and do within the platform. Entitlements can be configured at both the company level and the account level:
- Company-level entitlements — Control access to platform-wide features such as reporting, payments, analytics, and administration tools
- Account-level entitlements — Control access to specific bank accounts, including the ability to view balances, initiate payments, or approve transactions
- Product entitlements — Control access to specific J.P. Morgan products and services integrated with the Access platform
IP Security Configuration
IP Security is a critical protective measure that restricts platform access to specific IP addresses or ranges. When enabled, only requests originating from approved IP addresses can access the JPMorgan Access login page. This prevents unauthorized access attempts from unknown locations.
Only Primary Admins can activate IP Security. The configuration involves:
- Navigating to the Access & Security tab
- Selecting IP Security configuration
- Adding approved IP addresses or CIDR ranges
- Choosing whether to apply at company level or user level
- Activating the IP Security policy
RSA Authenticator Setup
The RSA Authenticator is a mandatory component of JPMorgan Access authentication. Primary Admins must ensure that IP Security is activated alongside the RSA Authenticator, choosing either a company-level or user-level configuration.
For non-authenticator clients (users who do not yet have an RSA token), an activation code must be obtained by calling J.P. Morgan service. Once the activation code is received, the user can complete the token setup process through the "Set Up Your Token" option on the login page.
Dual Control — Administration
Dual Control Administration is an advanced security feature that requires two administrators to approve administrative actions before they take effect. When activated:
- All administrative actions require approval by another System Administrator
- This includes updating user info, account-level rights, and company-level rights
- Only Primary Admins can activate the Dual Control feature
- Proxy Admins can review administrative tasks pending approval if they have account rights
- This creates a separation of duties for administrative changes, reducing the risk of unauthorized modifications
Activating Platform Features
New JPMorgan Access users (referred to as Connect users) must review and activate applicable features before building user profiles. The main feature categories that need activation include:
- Pay & Transfer — Payment initiation and management capabilities
- Collect & Deposit — Receivables and deposit management features
- Security — Authentication, IP Security, and fraud prevention tools
Once these features are activated, administrators can begin building user profiles with appropriate entitlements and access rights.
Best Practices for Administrators
- Activate Dual Control Administration for sensitive changes
- Enable IP Security to restrict access to known locations
- Regularly review user entitlements and remove access for departed employees
- Ensure all users have RSA SecurID tokens properly configured
- Set appropriate transaction limits based on user roles
- Maintain an audit trail of all administrative changes
- Use the principle of least privilege when assigning entitlements