So we have Guard Configured on a test instance and have proved SSO is working and also SCIM provisioning of users, but I need some help to understand the migration of users, e.g. how to we maintain product access, group and role member ship etc
Great answer @Darryl Lee.
I feel like this could be a whole article.
I started writing an article on our website about different types of security setups within Atlassian products, from our last community thread. It can get very complex...
@matthew_hickman - I'd also add that more info on your current Server/DC security setup/policies/groups will help provide better guidance on how to replicate it in Cloud. e.g. If you need to have separate groups that grant access to each Jira Project and everything is really locked down; vs everything is open and only a few projects are locked down to individual users. Both are doable in Cloud, and there are multiple ways you could achieve it. This could mean the difference between managing thousands of groups with 5-10 users per group, vs managing 100 groups with 50-1000 users per group...
Your scale and complexity will determine how easy or hard some methods of securing your products are.
There's also user authentication policies, both for internal users (within your company) and external users to consider, https://support.atlassian.com/security-and-access-policies/docs/understand-authentication-policies/