AD user group in profile

satortunov_vniia_ru October 8, 2018

Hello!

We get users from ActiveDirectory. The user profile displays groups that I would not like to show. How can I hide them or not get these groups from AD, and use only local ones? In three options for setting up a connection with AD, there is a reading of groups of AD ...

1 answer

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
October 9, 2018

In Jira you have the options for read only, read only with local groups, and read/write when adding an external user directory to Jira.  Regardless of which of these options you select, Jira has the ability to also sync the group memberships that exist in Active Directory / LDAP.   That is why these LDAP groups can appear within Jira.

If I understand your request, you only want to get the user accounts into Jira from this AD directory.  As such, you could use the read only with local groups option, and in turn then update the group ldap filter in jira for this directory to eliminate these groups you don't want to see.  Details on how to do this are in How to write ldap search filters.

The problem with doing this is that it is possible the accounts you have might be depending on one or more of these LDAP/AD groups in order to grant permissions or even grant application access.  If all your groups exist in the Jira internal user directory AND you have added these users as members of these groups, then you should be fine.  But making a change like this to a production instance can potentially leave your users locked out of Jira. For this reason, I would recommend testing this kind of ldap change in a staging server first.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events