There is one customer that is not able to login to Jire Service Desk Portal.
The user goes to the portal link and sees the login prompt "Log in to Service Center".
The user enters their email and is redirected to Microsoft sign in.
The user enters their email and email password
Microsoft asks if the connection should be remembered. "No, Yes"
The user chooses yes
The user is redirected back to "Log in to Service Center"
We use Single Sign on with Azure AD
The user is in the correct Azure Enterprise App Group
The user shows up in managed users in Jira Cloud
Jira shows the user signed in at the time and on the computer they attempted it from
No other user is having this issue
I was able to sign in on the users computers
We have tried firefox, chrome, and chrome incognito
I cleared all the cache from both browsers
I restarted computer.
Hello, Jared.
Since the user is being redirected to Azure when logging in into the Portal, they must have been migrated to the Atlassian Account in Admin/<site>/JSM/Portal Customers, so they will be a site user, visible in Admin/<site>/User Management/Users.
I assume you have already checked the users site access, and active/deactivated status there?
This can point to a misconfiguration of your SSO with Azure. Azure *MUST* be sending user's email address as the NameID, as Atlassian Cloud uses the email to identify the users. Atlassian has been incorrectly suggesting to use UPN for some time. And the User Provisioning *MUST* be configured to use objectID as the matching attribute – as in true enterprise scenarios both email and UPN may change. So it's possible that Azure is sending something back Cloud as the user-id but such user doesn't exist (or is deactivated), and since the user is going to Portal, they are not being asked to enrol automatically.
This needs to go to Atlassian Support, with a [HAR file|https://confluence.atlassian.com/kb/generating-har-files-and-analyzing-web-requests-720420612.html] recorded at the attempt to login and screenshots of the SSO and User Provisioning configuration in Azure AD.
I am sure there are people here who could help too, but you would have to share these details, that are by definition sensitive.
Thanks for the reply ED,
Yes I have checked the users status and it is enabled.
I have also checked the Azure side.
The user is syncing over to Jira in the "managed users" group.
Also, all other users are working, so I would assume it's NOT an azure misconfiguration.
at leas not a site wide configuration.
I have entered an Atlassian Support ticket, but still awaiting a response.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
What I meant re: Azure misconfiguration – if your Azure is misconfigured, e.g. is using UPN for the matching attribute and not objectId, and this user had their UPN changed in the past – then when they login they will be treated as a new Portal-only user, different from the one you may be seeing in the "managed users".
Anyway, I am sure Atlassian Support will help. If you can do describe what the problem actually was (in general terms) after you have it resolved for the sake of others who may step into this.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.