Hi all,
I have a question about logging into the customer portal of Jira Service Management.
Does anyone know whether portal-only customers (i.e. those without an Atlassian account) will still be able to login via username + password AFTER I enable SAML SSO (see docs here).
Essentially we have both internal and external accounts that need to access the portal and we want to use SAML SSO for internal accounts but still use username + password for externals.
Thanks in advance for your help!
Thanks @Ste Wright. I ended up raising a ticket with Atlassian Support and got the following response:
Yes, it is possible for Portal-only customers to have both SSO and Username+Password enabled.
Hopefully that helps anyone else who has the same question!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @MJCorcoran
You can setup Customer SSO here - https://support.atlassian.com/jira-service-management-cloud/docs/configure-settings-to-authenticate-your-customers/
I envisage it's possible to set up SSO for a selection of customers, rather than all/none.
Ste
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes, I've just set up SSO for portal-only customers in Jira Service Management. There's a toggle/setting that lets you keep password-based login enabled alongside SSO, so both options ("Continue with SSO" and "Login with password") can appear on the login screen.
However, this isn't ideal from a security perspective. If password login remains available as a fallback, it undermines the main purpose of implementing SSO — which is to eliminate the risks associated with storing and transmitting reusable passwords/credentials that could be stolen, phished, or compromised. For true security benefits (e.g., enforcing stronger centralized controls, MFA via the IdP, no local password exposure), it's best to disable password authentication entirely once SSO is working reliably.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
This is a new setting, so you might not find everyone has tried this yet. I'd envisage though a mix will be acceptable.
It does offer these settings though when you modify your customer authentication settings:
^ I'd use (2) and test with a test portal-only customer account, and see what happens!
Ste
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.