Domain Configuration Options for Jack Henry Identity

Financial institutions using a product or products integrated into Jack Henry Identity must choose the authentication method that works best for their institution’s unique email domains. Because users log in using their email addresses, Jack Henry needs to know where to verify their passwords. For example, if a financial institution chooses the Active Directory (LDAPS) integration, users will simply sign in using their existing Active Directory credentials across all their integrated products.

Take a look at the comparison chart below to learn more about which domain configuration options make the most sense.

Jack Henry Identity StandardActive Directory - LDAPSMicrosoft Entra ID
PasswordJack Henry Identity is authoritativeOn-prem AD is authoritativeEntra is authoritative (sometimes synced from on-prem AD)
Password Rules / Policies / RecoveryJack Henry Identity is authoritativeOn-prem AD is authoritativeEntra is authoritative
2FA RequirementsJack Henry Identity is authoritativeJack Henry Identity is authoritativeEntra is authoritative
IP RestrictionsNot SupportedNot SupportedEntra is authoritative
Authorizations and PermissionsManaged by FI in Users & Groups app, OR separate authorization system (Varies by Product)Banno and Platform group membership can be synced from AD security group membership (Optional)Managed by FI in Users & Groups app, or separate authorization system(Varies by product) SCIM integration coming in future
New UsersMust be invited through Users & GroupsMust belong to 1+ AD security group that is mapped and synced to Users & Groups, OR be invitedMust be invited through Users & Groups
Profile (Name, Phone)Jack Henry Identity is authoritativeJack Henry Identity is authoritative (May change in future)Name synced from Entra; Jack Henry Identity authoritative for phone (May change in future)

Choosing the best configuration depends on a financial institution’s specific needs and priorities:

  • If group syncing is prioritized: Financial institutions may prefer the Active Directory (LDAPS) option, as it allows syncing existing AD Security Groups with Banno and Platform groups to manage permissions.
  • If Entra authentication is prioritized: Financial institutions may choose the Microsoft Entra ID option. Note that while this provides streamlined authentication, automatic group syncing is not yet available; institutions will need to manage permissions separately within each product’s authorization system.

Updates on the roadmap are planned, including plans for SCIM integration and automatic user provisioning, with a tentative target date of late 2026.

Note: Whichever option is selected will apply to all users with that email domain across all products integrated with Jack Henry Identity.

Related