Hello Jira community, I'd like to ask about a specific use case for the mobile app.
Suppose a company uses EntraID as their IDP and wants to restrict login to the Jira Cloud mobile app to devices only managed by their EMM/MDM provider. I don't see a particular appconfig value that accomplishes this.
An example of this would be the "Slack for EMM" app. They have an appconfig value called "ApprovedDevice" and if set on the tenant, any mobile client that attempts to authenticate without that appconfig value set would be denied access by Slack.
Does Atlassian/Jira cloud support anything like this?
Hi @Rico.Viqueira ,
Welcome. Here's some articles that will help in this regard.
This article covers how to configure for specific users to be able to use mobile:
https://support.atlassian.com/security-and-access-policies/docs/create-a-mobile-policy/
This articles covers the MDM configuration:
https://support.atlassian.com/security-and-access-policies/docs/mdm-security-controls-and-supported-apps/
Hope this helps gets you the right direction.
Thanks, I've reviewed those articles already and understand the data loss prevention (DLP) controls available and such, but I still don't see how any of those controls prevents a user from logging into an app like Jira cloud from an unmanaged device.
For example, I create a mobile policy scoped to all users that does the following
Or if I do the same with the MDM and push out AppConfig.
Neither "Mobile Policy" nor the AppConfig prevents me from logging into our Jira cloud instance from my child's iPhone which wouldn't be managed from a MDM, like Ivanti Neurons for example.
The only control I see which would theoretically accomplish this very specific scenario (ensuring users logging into our Jira Cloud instance from a mobile device are on a device managed by the company's MDM/EMM) is to turn on the IP allow list and then distribute the app with a Per-App-VPN. Now we're needlessly tunnelling the app traffic and probably impacting performance.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.