Good afternoon Fountain Life, Health, and Digital!
We’re excited to announce that we’re transitioning from our current identity provider platform JumpCloud (or Okta for you Digital folks), to Google Workspaces! Please read through this document to understand what this means to you.
TL:DR: THERE ISN’T ONE. READ THE WHOLE THING. THERE ARE CHANGES THAT YOU WILL NEED TO BE AWARE OF!
Who is impacted: The entirety of Fountain Life will be moving platforms. For applications which use Jumpcloud/Okta today for authentication (more than 40 distinct apps), we will now be logging in with a new Google Workspaces account. Your applications are being transferred over as I type this.
What does this mean for me: You will have a few changes to adjust to.
- Instead of going to JumpCloud to login to applications, you will now go to; myaccount.google.com
- You will need to configure MFA. See below for more details.
- You should STOP using individual logins wherever possible. We understand this isn’t fully practical, but if you are using a service and don’t see it in Google Workspaces, please let the Trust team know as soon as possible. Google Workspaces should provide you a seamless experience.
- If you have two different accounts, such as a @fountainlife.com and @fountainhealth.com, you no longer will. Instead we expect you to use your primary and let Google Workspaces handle the logic of separating identities. Please report any weirdness with this. (This is the one area we have not had time to fully test out).
Where do I check email: Your email will still go to Outlook today, and you will still use JumpCloud for that. Stay tuned for when we cut this over!
Can I store documents in Google Drive and Docs: Yes! You can safely store documents inside of Google Drive today. Of course, please exercise caution when sharing any confidential information.
What is an identity provider: An identity provider exists as a source of truth for an employee’s access into other applications and data. It helps us ensure that the right people have the right access to the right things.
I don’t know how to access my apps from here: That is ok, I will send out more information about how to use SSO soon. We just didn’t want to overwhelm you with a HUGE message. We need you to get your account up and going, though. JumpCloud and Okta are both still active and in place.
Why are we implementing this change: In addition to a host of new technology team members, the acquisition of LifeOmic (now Fountain Digital) has brought about a diverse stack of new technology which we will be integrating into our platforms and workflows. A decision to unify the Identity Management Platforms has been made, and Google Workspaces was the winning platform. This will prime the pump for other migrations in the mid-future. It will also provide drastic cost savings.
When will we be making this change: Technically, we already have! Everyone should now have a Google Workspaces account.
Caveat: If you already had a Fountain Google account for things like Google Docs or Sheets, you only need to setup your MFA.
To get started:
- Go to myaccount.google.com
- Bookmark this site
- Login with your primary email address, and the temporary password Fountain2023!
- Primary email address being your normal email address.
- You will be prompted to change this on your first login.
- You should be prompted to setup MFA (more info below).
- This will likely require you to login to Google on your mobile device, or use a phone number.
- Mobile device prompting is more secure than text messaging, however, we left text messaging as an option initially. This may change in the future.
The faster you are able to sign in, setup MFA, and start working with applications, the simpler the transition will be.
--- JumpCloud access will be shut off on March 8 ---
--- Okta access will be shut off once the AWS SAML Roles are migrated ---
A Note on Multi-Factor Access:
Multi-Factor Access (MFA) to accounts is the number one defensive measure we can put into place to prevent hackers from hacking. There are a multitude of methods to enable MFA, but the simplest, and the expected version today, is to use an MFA app on your phone.
At this point in time, not having MFA is unacceptable. Trying to access patient data, infrastructure, or other technical assets without MFA has been found negligent by courts of law. Very large fines will follow if we have an incident and are not using MFA.
However, the Trust team will NEVER be able to spy or search your mobile device. We don’t care what you do on it. We don’t want to know what you do on it. We just want to ensure that when you login to Fountain accounts, we can verify that it is actually YOU using that username.
The Trust team is here to support you if you encounter difficulties during this.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article