Domain Configuration Options for Jack Henry Identity
Financial institutions using a product or products integrated into Jack Henry Identity must choose the authentication method that works best for their institution’s unique email domains. Because users log in using their email addresses, Jack Henry needs to know where to verify their passwords. For example, if a financial institution chooses the Active Directory (LDAPS) integration, users will simply sign in using their existing Active Directory credentials across all their integrated products.
Take a look at the comparison chart below to learn more about which domain configuration options make the most sense.
Configuration Options Comparison
| Jack Henry Identity Standard | Active Directory - LDAPS | Microsoft Entra ID | |
|---|---|---|---|
| Password | Jack Henry Identity is authoritative | On-prem AD is authoritative | Entra is authoritative (sometimes synced from on-prem AD) |
| Password Rules / Policies / Recovery | Jack Henry Identity is authoritative | On-prem AD is authoritative | Entra is authoritative |
| 2FA Requirements | Jack Henry Identity is authoritative | Jack Henry Identity is authoritative | Entra is authoritative |
| IP Restrictions | Not Supported | Not Supported | Entra is authoritative |
| Authorizations and Permissions | Managed by FI in Users & Groups app, OR separate authorization system (Varies by Product) | Banno and Platform group membership can be synced from AD security group membership (Optional) | Managed by FI in Users & Groups app, or separate authorization system(Varies by product) SCIM integration coming in future |
| New Users | Must be invited through Users & Groups | Must belong to 1+ AD security group that is mapped and synced to Users & Groups, OR be invited | Must be invited through Users & Groups |
| Profile (Name, Phone) | Jack Henry Identity is authoritative | Jack Henry Identity is authoritative (May change in future) | Name synced from Entra; Jack Henry Identity authoritative for phone (May change in future) |
Choosing the Best Configuration
Choosing the best configuration depends on a financial institution’s specific needs and priorities:
- If group syncing is prioritized: Financial institutions may prefer the Active Directory (LDAPS) option, as it allows syncing existing AD Security Groups with Banno and Platform groups to manage permissions.
- If Entra authentication is prioritized: Financial institutions may choose the Microsoft Entra ID option. Note that while this provides streamlined authentication, automatic group syncing is not yet available; institutions will need to manage permissions separately within each product’s authorization system.
Updates on the roadmap are planned, including plans for SCIM integration and automatic user provisioning, with a tentative target date of late 2026.