Hi everyone,
When you create an organization in Atlassian, you are _required_ to create an Atlassian cloud account. All good. Actually, no, it's not all _that_ good, because you have to do this in private mode, otherwise Atlassian creates an account for you with the wrong email (your currently logged in Google account) without asking you, ever.
So, you register an account that will be the super administrator for your company, e.g. admin@foobar.com. You enroll in Jira Service Desk + Confluence + Access trial, good. Then you verify your domain, foobar.com, which is again more painful than should be. It wants you to set the @ (root) TXT record for verification, which I swear I've never seen anyone else do, and for a reason: that normally goes for SPF records. So you can't verify via DNS unless you're willing to kill some of your email flow. So you do the verification via HTTPS, whatever.
Then you set up SAML using Azure AD, where the order in which you should do things is kinda messed up in the Atlassian portal, but you eventually figure out using the Azure docs. Whatever.
Then you properly enroll your first user in your site, and all seems to be fine.
... then you try to log in as admin@foobar.com again. Guess what: it redirects you to Azure AD login. Which is great except there's no password for admin@foobar.com, since it's a _group_. Before you ask, why, because IT staff comes and goes, it's senseless to assign god mode to any one person. That's common practice. It's also senseless to assign super admin rights to your everyday user as then you'll never possibly face any permission issues that your co-workers might face. Much like we stopped logging into Windows as "Administrator" and instead, elevate rights only when necessary. Again, common practice.
So now the _only_ way I can access the admin sites is by going to "Can't log in" and clicking on the recovery link. Which expires in an hour. I know my Atlassian password, I just never get to enter it, because it immediately redirects me to Microsoft Online, based on my email domain.
Is there a better way to do this, without adding unrestricted admin rights to all IT staff? The only other way I can think of is changing the admin account's email address to one of our alternative domain names, but that seems plain stupid to me.
Suggestions?