The Atlassian Community Forums are currently in read-only mode. We will be relaunching on a new platform on September 22 (read more here). We apologize for the extended downtime. For concerns or questions, please email communitymanagers@atlassian.com. See you on the other side, on the new Atlassian Community Forums! :)

×

Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Changing order of the names in Access

Peter Cselotei - Lupus Consulting Zrt_
Contributor
August 5, 2023

How to use the Displayname attribute at Atlassian Access instead of the format Firstname Lastname?

Why

In some countries, the companies store their employee names in their IDP-s (Identity Provider) other than the format of Firstname Lastname. These formats are usually stored in Displayname.

How

I can show the Microsoft Azure - Atlassian Access solution.

There are 2 different mappings to handle: provision mapping and SSO handling. Both have to be modified in order to use Displayname.

Provision mapping

(If somebody hasn’t utilized Access before, they can jump to step 3.)

  1. If names are already in sync with Access, then Firstname and Lastname fields have to be cleared from Access. This can be done by first deleting Firstname and Lastname attributes from IDP. (We will write it back after handling the mappings)

  2. Name values have changed, so Provision will run on them. If it didn’t yet, or it needs to happen faster, it can be done by running Provision On-demand.

  3. Now it’s time to modify the mapping, so Firstname and Lastname should be deleted from it:

    • Original mapping:

       1.png

    • Modified mapping:

       2.png

  4. From now on, attributes of Firstname and Lastname won't sync by provisioning. But before writing back the names in the IDP, SSO mapping should be handled too.

SSO mapping

SAML Single Sign-on will Just-in-Time update a User's Atlassian account based on the givenName and Surname Attributes sent as part of the SAML SSO authentication. This means if a User was synced via User Provisioning with a Custom Display Name value, it will be overwritten if SAML sends something else via givenName and Surname.

  1. Modify SSO Attributes & claims by deleting surname and givenname attributes

    1. Original:

       3.png

    2. Modified:

       4.png

  2. After the modification, Lastname and Firstname attributes can be written back to IDP

Summary

By modifying the mapping of Provisioning and SSO, from now on only Dispalyname will be synced to Atlassian Access for all of the currently existing users and for new users too.

 

Related ticket:

https://jira.atlassian.com/browse/ACCESS-1229

0 answers

Comments for this post are closed

Community moderators have prevented the ability to post new answers.

TAGS
AUG Leaders

Atlassian Community Events