Hello everyone,
I am looking for information when I integrate JIRA / Confluence (On-premise) with OKTA (SAML), how can local JIRA users still login in to JIRA?(These would be the local users and will not have an account in OKTA).
Hi Vihar,
For Jira Server, you'll need to use one of the many SAML add-ons in the Marketplace. I have personal experience with the one offered by re:solution.de and know that they allow local users to bypass SSO - they will even book time with you to set up OKTA. Their plugin allows you to have a selection screen so users can choose if they want to use SSO or log in locally. You can also give users an SSO-bypass URL and force everyone not using that special URL to use SSO.
Having a look at the SAML plugin offered by miniOrange makes it appear that they also allow local users to log in - for their plugin I see a screenshot indicating that you can log in locally or opt to use OKTA from the login screen. They also have a bypass URL option.
So I definitely think it's possible, just might require some extra configuration when you're setting up the SAML plugins.
Cheers,
Daniel
Hi Vihar,
I work for resolution ( @Daniel Eads - thanks for the praise!) - Daniel is right with our plugin you can do both, login via OKTA and allow local logins.
We support multiple Ways how to achieve that here are the two most common scenarios used:
If you access your instances via a link like to one below:
JIRA: https://<jira-baseurl>/login.jsp?nosso
Confluence: https://<confluence-baseurl>/login.action?nosso
You don't get redirected to Okta but see the normal login prompt.
This is a great solution if typically all your Users are in Okta and only a few people (like admins) need to login locally. It gives your large Userbase the SSO exprience and the few other people need to login via this link.
If you have multiple IdPs (or want at least the Selection Login via OKTA, Login with Local Username/Password) presented to every unauthenticated User, then you can turn on the IdP selection (see link above).
Then every unauthenticated User gets a choice presented to them. That choice can be saved in a cookie that for the next time the User can be automatically redirected.
The IdP Selection dialogue is fully templated, so if you don't like out default layout or options - you can change it easily.
--
Here are some more links that you might find interesting:
Cheers,
Christian
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I do see a similar article @https://community.atlassian.com/t5/Jira-questions/OKTA-single-sign-on-but-not-for-all-users/qaq-p/189462 but no resolution yet. It does look like when JIRA is integrated with OKTA, local JIRA users will not be able to login into JIRA.
Please confirm.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.