Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

What is the best practice for migrating from Google Workspace to Microsoft Azure AD for IdP?

Michael Hotchkiss
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
January 7, 2026

Our organization is migrating from Google Workspace to Microsoft 365. We would like to change our identity provider to Microsoft without losing any user data. All users have the same email addresses. We do not have enterprise, so we can only have one provider at a time.

1 answer

0 votes
Robert DaSilva
Community Champion
January 9, 2026

Hey @Michael Hotchkiss , my understanding here is that this shouldn't be too challenging, but will require a few steps to occur in a specific order.

In your current state, you've got your Google Workspace configured as your identity provider. I'm assuming you also have SCIM enabled, such that new users on Google Workspace get new Atlassian Accounts configured automatically.

The good news is that all of your users have Atlassian Accounts already, they are just being forced through Single Sign On via Google Workspace, instead of using an Atlassian Account specific password.

Here are some assumptions I am making that you'll want to double confirm:

  • You currently have SCIM enabled, such that any new user in Google Workspace syncs with Atlassian automatically, and has a new Atlassian Account created for them.
  • The email address for every user is the same on Google Workspace and Office 365.
  • The unique id for each user is their email address or prefix, and is the same across both Google Workspace and Office 365.
  • You have a user account which has Organization Administrator privileges, that is NOT part of your Identity Provider configuration

Here's what you'll need to do:

  1. Ensure your email domain is claimed and verified. This should already be the case due to the existing SSO configuration.
  2. Export a list of your Claimed and Managed users, so that you have a record of which accounts you have claimed and managed, ideally for use later.
  3. Disconnect your Google Workspace identity provider. This should release all of your user accounts from Single Sign On, but may not release them from being Managed. This won't be an issue, once Office 365 is connected, you can connect them back into SSO.
  4. Connect your Microsoft 365 identity provider, and configure SSO as required.
  5. Re-claim all accounts you previously had claimed. This likely will happen automatically once the IdP is connected, and the user list syncs.

If you do this quick enough, and ideally on off-hours, you can likely avoid a lot of confusion from your users with how they sign in.

Here are some documents and other Community threads I encourage you to read just to get your head around the process:

Hope this is helpful! You can always reach out to Atlassian Support directly via support.atlassian.com if you run into any specific issues.

The biggest takeaway I have though: Keep at least one account completely disconnected from your Identity Provider for the migration. Ideally, use a completely different domain (like a free gmail.com email account) to ensure you maintain administrative access if something does go wrong. Once you verify everything is working properly, you can remove that accounts access, but it's a great safety net to have.

Cheers,

Robert

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events