I want to transition our Single Sign-On from Google Workspace to Microsoft Entra without losing their identity and access to their data.
What is the best option to do it?
@Joel Francisco I am assuming you are not on the Atlassian Enterprise plan, as Enterprise would allow you to configure multiple Identity Providers (IdPs) simultaneously, making this migration much smoother.
In your case, the safest approach would be:
Create a new authentication policy where Atlassian native authentication is enabled and SSO is disabled.
Move all users to this temporary authentication policy first. This ensures users can still log in directly with Atlassian accounts during the transition.
Before making any changes, take a backup/screenshot/export of your current Google Workspace SSO configuration so you can quickly roll back if needed.
Configure Microsoft Entra ID as the new Identity Provider.
Move a small group of test users back to the SSO-enabled authentication policy and validate:
Login flow
User provisioning/sync
Group mapping (if applicable)
Product access
As long as the users’ email addresses in Microsoft Entra match their existing Atlassian account email addresses, they should retain their identity, permissions, and access to their Jira/Confluence data without issues.
Once testing is successful, you can gradually move the remaining users to the new Entra-based SSO policy.
Hello @Akash Singh ,
I am new to this and has been assigned to take over the task. How do I see what kind of subscription we have? Also, can I use the "upn" instead of the email address format. Our users have different email address now because of the buyout but they kept their existing "upn" which match their existing credentials to login with Atlassian.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Joel Francisco You can check your organization’s subscription by navigating to Atlassian Administration (https://admin.atlassian.com/) and reviewing the Billing section.
If the users will be using different email addresses after the migration, I would recommend raising a support request with Atlassian and providing a mapping CSV containing each user’s current and new email address. Atlassian Support can then assist with performing a bulk email update from their end.
Once all users have been updated to their new email addresses, you can proceed with the previously suggested steps to configure and add the new Entra IDP.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for your quick reply. Really appreciate it. I guess I need to Raise a support request with Atlassian.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Akash Singh , I tried raising a support request with Atlassian but the AI chatbot will just reply with the some reference link and not actually submitting the ticket. Is there another option to submit a request that will be routed to the actual support team or person?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Joel Francisco You can avoid talking to the chatbot and submit a ticket directly by clicking on the link given at the bottom of the page, see screenshot.
If you found my response helpful, could you please consider accepting it as the answer? This helps other community members quickly find useful solutions and keeps the forum organized.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.