Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Portal-only account - SCIM available now!

SCIM for Portal-only accounts

Learn about how to configure SCIM for Portal-only accounts here

Today we're leaving a quick note that SCIM (System for Cross-domain Identity Management) for Portal-only accounts is now available for all sites.

What SCIM functionality is available for Portal-only accounts?

SCIM for Portal-only accounts will allows you to seamlessly provision/update/de-provision as required to ensure the right people have the right access.

SCIM for Portal-only accounts also allows for syncing of IdP groups with customer organizations so you can ensure your grouping are reflected and always in sync.

Who should use Portal-only account SCIM?

To use Portal-only account SCIM you'll need the following:

  1. Your organizations is subscribed to Atlassian Guard Standard or Premium
  2. You use Portal-only accounts for external service management on JSM
  3. You use an IdP (Identity Provider) which can be used to set up SCIM/SAML SSO

Note: Portal-only accounts do not contribute to your Atlassian Guard bill - SCIM for Portal-only accounts is available for any sites where the organization has an active Atlassian Guard subscription.

A quick refresher on whether your should use internal vs external customers for your site


Leave a comment here with any questions or suggestions - we’re always looking for feedback from the community!

1 comment

James Rickards _SN_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 17, 2025

Does this finally allow us to auto-provision portal access for guest accounts registered in Microsoft Entra that do not belong to our claimed domain?  (e.g. if we claim asdf.com and the customer belongs to fdsa.com but is registered as a Guest in our Entra). It would be great to finally prevent random emails from creating a customer account and creating dodgy requests.

Also, can we allow our JSM staff to see the email address of these guest users to help minimise the risk of a "customer" raising a request via email emulating an internal employee's name.

Comment

Log in or Sign up to comment
AUG Leaders

Atlassian Community Events