I am wondering if Atlassian Guard is necessary to have in my Cloud target instance?
I will give you a bit context about my case; I have my Jira Data Center instance, actually I have started my Assessment with JCMA (I have the instance assessment completed). Than, in my DC instance, I have my user management Delegated to an LDAP Auth and I have Microsoft Azure Active Directory SSO for Jira installed. So, in my Cloud target instance I only have Jira, Zephyr, Confluence, and Bitbucket, Atlassian Guard was not considered (Idk why!) and this makes me wonder;
- Not having Atlassian Guard in Cloud target instance could be a migration blocker?
- If Atlassian Guard was not considered in Cloud, What would be the main cons of this?
- (if applies) On those cons, How could I turn those cons around?
I hope someone has gone through something like this, and tell me how managed to resolve it.
Hi @Sergio Abdallah Rios Ramos
In addition to the answers provided so far, I'd like to offer my thoughts as well as I've not that long ago faced the same scenarios at work.
"Not having Atlassian Guard in Cloud target instance could be a migration blocker?"
A: Not having Guard is absolutely not a blocker. However, you should ensure the "decision makers" have a clear understanding of what features will and won't be available in the cloud with your current list of planned subscriptions. For example, the assumption that users will continue to have a seamless login experience post migration (without Guard) would be a false assumption.
"If Atlassian Guard was not considered in Cloud, What would be the main cons of this?"
A: If Atlassian Guard isn't adopted in the cloud you'd not have access to the features Brant and Mikael mentioned. The real world impact of not having Atlassian Guard features probably affects the organisation more than the end user experience. For example,
"(if applies) On those cons, How could I turn those cons around?"
A: If your organisation has particular requirements around auditing, data loss prevention controls or more formal data classification features, then the decision is simple; you essentially require Atlassian Guard Premium.
The additional benefits of SSO and SCIM syncing with Microsoft Entra / Azure AD do carry substantial benefits when having to manage user accounts. Currently your DC setup with LDAP and MS offer this. When you move to cloud each user will receive a global Atlassian Cloud identity tied to their email address. Without Guard+SSO+SCIM you'll effectively have no simple way of reconciling the Atlassian + Microsoft user accounts.
I hope this additional info. answers your questions, or is informative at minimum. :)
Regards,
Ben
@Sergio Abdallah Rios Ramos In addition to SSO and SCIM (which is worth it) standard also provides API Token Controls and Activity Audit Logs.
Premium provides added security and business continuity like Data Classification, Threat Detection, and Data Loss Prevention.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
If you are on the enterprise plan Guard Standard is already included. Guard allows you to set up SSO and SCIM provisioning. If you are on a lower plan and do not consider Guard, you would have to handle the provisioning and the user would have to have a separate login/password to access you cloud instance.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.