Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIRA OKTA Integration

vihar garlapati September 20, 2018

Hello everyone,

I am looking for information when I integrate JIRA / Confluence (On-premise) with OKTA (SAML), how can local JIRA users still login in to JIRA?(These would be the local users and will not have an account in OKTA).

2 answers

1 vote
Daniel Eads
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
September 21, 2018

Hi Vihar,

For Jira Server, you'll need to use one of the many SAML add-ons in the Marketplace. I have personal experience with the one offered by re:solution.de and know that they allow local users to bypass SSO - they will even book time with you to set up OKTA. Their plugin allows you to have a selection screen so users can choose if they want to use SSO or log in locally. You can also give users an SSO-bypass URL and force everyone not using that special URL to use SSO.

Having a look at the SAML plugin offered by miniOrange makes it appear that they also allow local users to log in - for their plugin I see a screenshot indicating that you can log in locally or opt to use OKTA from the login screen. They also have a bypass URL option.

So I definitely think it's possible, just might require some extra configuration when you're setting up the SAML plugins.

Cheers,
Daniel

Christian Reichert (resolution)
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 21, 2018

Hi Vihar,

I work for resolution@Daniel Eads - thanks for the praise!) - Daniel is right with our plugin you can do both, login via OKTA and allow local logins.

We support multiple Ways how to achieve that here are the two most common scenarios used:

Via Link:

If you access your instances via a link like to one below:

JIRA: https://<jira-baseurl>/login.jsp?nosso
Confluence: https://<confluence-baseurl>/login.action?nosso

You don't get redirected to Okta but see the normal login prompt.

This is a great solution if typically all your Users are in Okta and only a few people (like admins) need to login locally. It gives your large Userbase the SSO exprience and the few other people need to login via this link.

Via IDP Selection Page

If you have multiple IdPs (or want at least the Selection Login via OKTA, Login with Local Username/Password) presented to every unauthenticated User, then you can turn on the IdP selection (see link above).

Then every unauthenticated User gets a choice presented to them. That choice can be saved in a cookie that for the next time the User can be automatically redirected.

The IdP Selection dialogue is fully templated, so if you don't like out default layout or options - you can change it easily.

--

Here are some more links that you might find interesting:


Cheers,
    Christian

Like Marko Slijepčević likes this
0 votes
vihar garlapati September 20, 2018

I do see a similar article @https://community.atlassian.com/t5/Jira-questions/OKTA-single-sign-on-but-not-for-all-users/qaq-p/189462 but no resolution yet. It does look like when JIRA is integrated with OKTA, local JIRA users will not be able to login into JIRA. 

Please confirm. 

Suggest an answer

Log in or Sign up to answer