Good day,
Our company uses standalone atlassian products such as: Jira Core, Jira Software, Confluence, Bitbucket
At the moment every time user switch from one service to another - an authentification is requiered. We would like to implement pass-through authentification that would allow us to connect accounts from all the services listed above by making single user database and to make switching between services seamless.
Reading through forum posts we came up with a few solutions, but your consultation in choosing them would be appreciated:
1. Request for Atlassian Crowd product license
2. Install one of the suggested plugins. such as Kerberos
We have also noticed that ISS helps some companies, but we don't find it suitable for our architecture, since we expect our users to operate from their personal computers, using not only Windows OS.
If any of this solutions can help us or our problem can be solved using built-in tools - please confirm that and provide sufficient instructions for our administrator.
Hi Mikhail, welcome to the Community!
While I can't provide a specific recommendation for you, I can provide a little more food for thought that might help you decide.
Regarding Crowd
With multiple Atlassian products, Crowd would certainly help your single-sign-on situation. One of the major benefits that Crowd provides is centralized directory management for Atlassian applications - for example, if you have multiple Active Directory domains, you can manage the users all in Crowd vs. in Jira/Confluence/Bitbucket individually.
Regarding Plugins
In contrast to connecting your applications to Crowd, an SSO plugin would need to be installed and maintained on each application separately. This isn't necessarily a bad thing; most vendors provide apps that work across all three applications and are very similar to set up.
I would consider the environment you're working in. You mentioned that Windows passthrough might not be helpful because there are personal computers in the mix (they might not be joined to a Windows domain or are running MacOS or Linux). Are there other applications that you might want to connect to single-sign-on and do you already have some backend infrastructure to support a centralized identity provider? For example, many companies that use Active Directory can take advantage of ADFS or Azure AD to get a SAML identity provider at no extra infrastructure/licensing cost. SAML is pretty well adopted across the industry at this point, so you could leverage a SAML-capable identity provider for any other applications in your environment that support SAML.
There are many well-supported SSO plugins on the Atlassian Marketplace. I'm sure several vendors may chime in on this thread with information about their specific offerings. I'll just mention that the Data Center options for our on-premise products come bundled with SAML support (you are on Server, so you would need to use a plugin). For the Cloud products, Atlassian Access handles identity management such as SAML.
Cheers,
Daniel
Thank you for the quick response
Would it be possible to start using Atlassian Crowd without installing additionally LDAP services or other packages?
Sincerely,
Mikhail Kolesnikov
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.