Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Effective Use of Jira Service Management with Microsoft Entra ID for Access Requests

Enma Phillips
July 28, 2026

We recently migrated from our on-premises Active Directory to Microsoft Entra ID, and the migration itself went really well. Now that everything is up and running, we're taking the opportunity to rethink how we handle application access requests and user lifecycle changes. Rather than simply continuing with our existing process, we're interested in learning how other organizations have approached this after making a similar move.

One area we're particularly looking to improve is reducing the amount of manual work involved for our IT team. It would be great if access requests could automatically reach the appropriate application owner or IT administrator for approval, and once approved, have that approval trigger the rest of the provisioning process. Ideally, application access, group memberships, role assignments, and lifecycle events like onboarding, department transfers, role changes, and offboarding would all happen automatically, while still maintaining a complete audit trail and keeping everything easy to manage.

I'm curious to know what has worked well for others. Are you using Microsoft Entra ID's native approval and lifecycle capabilities, or have you implemented an Identity Governance & Administration (IGA) solution? We'd love to hear what approach you've taken, what challenges you've encountered, and any lessons learned that you'd recommend to teams designing a similar process today.

1 answer

0 votes
Gabriela - LeanZero
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
July 29, 2026

Hi @Enma Phillips, for the Atlassian side of this the grant should come out as a group membership in Entra and nothing else. Once user provisioning is connected, your users and groups sync into the organization and product access is granted off those groups, so an approval doesn't have to end with someone opening admin.atlassian.com. That needs Atlassian Guard Standard.

Group syncing covers Jira, Confluence and Trello and still doesn't cover Bitbucket, so if Bitbucket is in scope that request keeps a manual step no matter what you build around it.

On native versus IGA, I'd settle whether Entra ID Governance is licensed for you before anything else. Entitlement management already holds the request, the app-owner approval, the expiry and the access review. Without it you end up rebuilding all four in JSM.

https://support.atlassian.com/provisioning-users/docs/understand-user-provisioning/

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events