Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JSM SSO problem

HKSTP Support December 12, 2023

Dear All,

We have two domains, AAD and AAD B2C, that require integration using the KEYCLOAK platform. However, we have encountered a few challenges.

First, the "Change Password" function in JIRA is causing a synchronization issue with the IDP. Is it possible to disable or hide this function within

Please note that there is also the issue of users logging in through SSO, with the SSO session remaining active after login, preventing them from accessing other accounts.

1 answer

1 accepted

4 votes
Answer accepted
Joseph Chung Yin
Community Champion
December 12, 2023

@HKSTP Support -

Welcome to the community.  SInce you are using your own IDP, I am assuming you are also using Atlassian Access product to use your IDP as the account provider.

In this case, what do you mean by "Change Password" functionality in Jira/JSM cloud?  Your IDP controls the user accounts and not at the Atlassian host front.  Please clarify with more details.

In your second question, are you looking for auto timeout of user session?  Here is a reference link on this matter - https://support.atlassian.com/atlassian-account/docs/login-issues-related-to-browser-cookies/

We will await for your clarifications, so we can assist you better.

Best, Joseph Chung Yin

Jira/JSM Functional Lead, Global Technology Applications Team

Viasat Inc.

HKSTP Support December 13, 2023

Dear Joseph,

Thank you for your assistance in this matter.

1. use the  'Change Password' Function at the top-right of the page to User Profile 

2. No, i mean the Keycloak session ,may i know jira how long will time out to log off the user and request login again? and for for the jira after login though the SSO, if disconnected the SSO session will jira can still login to use?

Joseph Chung Yin
Community Champion
December 13, 2023

@HKSTP Support -

In this case, your users should not be using User Profile to change his/her password as the PWD is control via your IDP source.  They should be using your IDP source to change the PWD.  Lastly, he/she should not see this functionality at all when they visit the "Profile" option.

How did you implemented your IDP source in the JSM env? Lastly, your "User Profile" link points to a older version of Jira.

Here is the proper link on the topic - https://support.atlassian.com/jira-service-management-cloud/docs/manage-your-jira-user-profile/  As you can see there is no place/option where one can change his/her account pwd.

In regards to Keycloak session, are you using another application (not provided by Atlassian) to conduct the session control?  If so, you should contact the application vendor to address your issue.

Please advise.

Best, Joseph

HKSTP Support December 14, 2023

Dear Joseph,

Here is the screenshot for the user porfile.

frWjio.png (933×939) (upload.cc)


We are using the standard Version due to the Jira cannot integrate with multi domains, we need to use the other application for working on it, the jira now is integrate with the KEYCLOAK , the keyclock setup 2 IDP.




Joseph Chung Yin
Community Champion
December 15, 2023

@HKSTP Support -

In this case, you need to contact Atlassian Support (https://support.atlassian.com) for the support team to assist you further.  In addition, you should also contact your third party application vendor for support too.

Best, Joseph

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events