Skip to content

Incident detail

Degraded Radius Service - EU region

Resolved incidentMinor1 affected service

Timeline window

to

Get alerted the next time JumpCloud breaks

Free email alerts for the handful of vendors you cannot afford to miss. No card, live in about a minute. Paid plans add Slack, Teams, Discord, and webhook delivery across your whole stack, plus higher API quotas.

Timeline

Incident updates

Every update on the official status source, oldest to newest, exactly as it appeared there.

  1. Investigating

    We are currently investigating an issue where after a password reset, some RADIUS sign-ins (VPN/Wi‑Fi) may fail with the new password. However - impacted users can still login with old password.

    We are investigating the cause of the issues currently, and will provide an update within one hour.

  2. Monitoring

    A fix has been implemented and we are monitoring the results.

  3. Resolved

    This incident has now been resolved.

  4. Resolved

    ![](https://jumpcloud.com/wp-content/themes/jumpcloud/assets/images/logos/jumpcloud-logo-tm-oceanblue.svg)

    # Incident Report

    Date: Sep 21, 2026

    Date of Incident: Sep 14, 2026

    Description: Root Cause Analysis for RADIUS authentication failures affecting EU users

    Region: European Union (EU)

    Summary:

    On September 14, 2026, JumpCloud identified an issue affecting RADIUS authentication for users in the European Union region. Users who had recently changed their password were unable to sign in with their new password, while their previous password continued to work.

    The issue originated with a database replica in the EU region that stopped receiving updates from the primary database following a planned infrastructure upgrade. As a result, RADIUS authentication in the EU region was served from an out-of-date copy of directory data, and recent account changes were not reflected there.

    JumpCloud restored service by rerouting EU RADIUS authentication to healthy database replicas in other regions, then rebuilding and resynchronizing the affected EU replica. Authentication in the EU region was fully restored the same day.

    What Happened:

    As part of a planned infrastructure upgrade, the database instances supporting RADIUS authentication were upgraded in place. In the EU region, the database read replica did not resume replication after the upgrade and stopped receiving updates from the primary database beginning September 10, 2026. Equivalent replicas in other regions recovered normally; only the EU replica was affected.

    Because RADIUS authentication in the EU region was served from this replica, it relied on a copy of directory data that was current only up to September 10. Any account change made after that point was not reflected in the EU region until the issue was resolved. The most visible symptom was password changes -  a newly set password would fail while the previous password still worked.

    As a result, during the affected window, account changes made in the EU region may not have taken effect there, including changes intended to remove or suspend a user's access. Once the issue was resolved and the replica resynchronized, all pending changes were applied and EU directory data returned to a fully current state.

    Contributing Factor:

    The delay in detection between September 10 and September 14 occurred because the affected database instance continued to report a healthy status at the infrastructure level even though replication had stopped. Our alerting was oriented around these instance-level availability metrics and did not cover this particular replication condition, so the stopped replication did not trigger an automated alarm, masking the underlying issue. Closing this detection gap is the focus of the corrective actions below.

    Corrective Actions:

    JumpCloud is taking the following actions to prevent recurrence:

    1. Replication-health monitoring and alerting. We are adding automated alerting that detects when a database replica stops replicating, independent of its general availability status, so this class of failure is caught immediately. Status: In progress.

    2. Stricter readiness validation for authentication traffic. We are strengthening our health checks so that a replica that is not fully synchronized is automatically removed from serving authentication traffic, ensuring requests are answered only from up-to-date data. Status: Planned.

    3. Staged rollout with replication validation for infrastructure changes. We are updating our procedures for database instance changes so they are applied one region at a time, with explicit verification that replication has fully recovered before proceeding to the next region. Status: In progress.

Keep exploring

More from JumpCloud

Neighboring incidents on JumpCloud's timeline and the rest of their record on OutageDeck.