Hi
We have recently set up user provisioning for our Atlassian Products and added a SAML configuration to enforce SSO in a policy. If I understand it correctly, the suggested default policy should include all users provided by the connected identity provider, in our case this would mean all the users in our products that have our verified domain. However, looking at the policy right now, there is only 1 user in there instead of the roughly 90 that should be in there. Does anyone know what the reason for this migh be? Do I have to do something to add all user that are being provisioned? Adding them all manually is not the solution.
Only users that have been provisioned (synchronized) into your Atlassian organization and linked to your verified domain are covered by SAML SSO policies.
Enforcing SSO is not the same as provisioning users (either through SCIM, User Sync, or just-in-time SAML provisioning). The policy is only applicable to users who are physically present in the Atlassian company.
Only users who have been successfully deployed and synchronized are listed by authentication policies (where SSO is enforced).
SAML-enabled just-in-time (JIT) provisioning only generates users upon their initial SSO login. Users will not show up in the policy if they haven't logged in yet.
Most likely, only one user has been provisioned or has logged in via SSO so far.
The rest of your users either:
Have not been synced from your identity provider (if using SCIM or User Sync)
Have not yet logged in via SAML SSO (if relying on JIT provisioning)You do not need to add users manually. Make sure your user provisioning (SCIM/User Sync) is set up and run, or, if using SAML JIT, users must log in at least once to appear. Check your sync settings and domain linkage to ensure all intended users are included.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.