I am exploring ways to integrate Jira, Confluence etc. with SSO to AzureAD. My idea so far is to use the direct directory integration of Crowd with Azure AD to provision users and groups. SSO auth with Atlassian tools should happen with snap-ins like "Microsoft Azure Active Directory single sign-on for JIRA".
This article seems to point in the same direction:
https://community.atlassian.com/t5/Crowd-questions/Authenticate-Azure-AD-users-against-Crowd-and-Atlassian-products/qaq-p/849794
Has anybody get such an setup already up and running?
So far I fail already in my test setup with the following error message when trying to sync Crowd with AAD:
2019-02-19 09:31:45,005 Caesium-2-4 INFO [microsoft.aad.adal4j.AuthenticationAuthority] [Correlation ID: b28eb4bb-e5f4-4433-bb59-c4881b655d50] Instance discovery was successful2019-02-19 09:31:46,520 Caesium-2-4 ERROR [atlassian.crowd.directory.DbCachingDirectoryPoller] Error occurred while refreshing the cache for directory [ 1277954 ].
Thanks a lot for your input!
Peter
Crowd sync error with AAD solved:
https://community.atlassian.com/t5/Crowd-questions/Invalid-Login-Error-and-no-sync-with-Azure-Active-Directory/qaq-p/809117
If anybody is interested: Works as expected! You can use all "bells and whistles" of Azure AD authentication as:
Very cool stuff.
Would be nice to see Atlassian having an official documentation on that.
Hi Peter,
Maybe you can help us out;
Can you give us some pointers and/or share details of your setup? It would be much appreciated!
Kind regards,
Joost
Joost, I am using on-prem Crowd to sync accounts from Azure AD to Jira/Confluence. For Jira/Confluence auth happens with Microsoft‘s SSO plug-ins for AAD. I know, that the cloud version of Crowd supports SAML, but have never tried to use this for SSO.
Ok, thanks for your reply. We were hoping that Crowd would be able to replace any additional SSO plugins, but it seems to be only in addition then. The MS plugins are not available for Bitbucket & Bamboo as far as I know. That would then mean that users need to use Jira or Confluence before going to Bitbucket or Bamboo to have a full SSO experience. We will do some testing with this setup, and I'll let you know how it went.
kind regards,
On your Feb 19 post, you said:
>>>If anybody is interested: Works as expected! You can use all "bells and whistles" of Azure AD authentication as:
>>>
Are you integrating Crowd with Azure AD? We are about to integrate Atlassian with AAD, but if following the instructions on this doc: https://confluence.atlassian.com/crowd/configuring-azure-active-directory-935372375.html
It says "Crowd doesn't support multi-factor authentication.You'll need to disable it for your users in Azure AD, or they will not be able to log in to Crowd or any integrated applications. ".
Would you care to share more details what you did?
Thanks
Tony Liu
Tony, the trick is, that you don't use Crowd for SSO. The approach that I have followed is to install SSO plug-ins for AAD from Microsoft on Jira and Confluence. These support of course all AAD supported sign-in methods incl. conditional access and MFA. Crowd is just used as central user directory for Jira and Confluence. You can sync users between Crowd and AAD and then from Crowd to Jira/Confluence. This is how it works for me in a PoC for a larger environment.
Peter, Thank you and thank you for the quick response.
Regards,
Tony
the Alternative to this can be one of the commercial Plugins like ours. For example with our Plugin you can synchronise Users straight into Confluence / Jira and also do all the authentication via SAML.So depending on our exact setup you could get some of these benefits:
In short there are multiple Ways to get to a working solution - you need to judge depending on your use case, which one suits you better.
Here are our plugins on the marketplace: https://marketplace.atlassian.com/vendors/1210947/resolution-reichert-network-solutions-gmbh
We are not the only choice, there are more: https://marketplace.atlassian.com/search?query=saml
Here is the Setup for Azure AD described: https://wiki.resolution.de/doc/saml-sso/latest/all/setup-guides-for-saml-sso/azure-ad/azure-ad-with-user-sync
Cheers, Chris
Regarding our final setup;
Joost, if you do not rely on Crowd on-prem, this is a valid approach, too.
"SLDAP for Azure" means, you have enabled the additional product "Azure AD Domain Services", right?
It would be nice to see, that Atlassian supports Azure AD beside AD in all their products, so that Crowd, AAD-DS, third-party tools which all add complexity are not required anymore.
@Joost van Orsouw , Thank you so much for sharing your experience. Yes, it'd be greatly appreciated and helpful if you could send your setup doc. What's the best way I send my email address to you?
Give me some time tomorrow, and I'll create a short setup guide for it. Maybe we can post it here, otherwise I will share a link
kind regards
@Joost van Orsouw could you please share a brief setup doc?thank you!
@Peter Meuser
Hello, I was able to set up SSO using the free plugins as well. However, you made a point that plugins have "Support for external IDs (B2B guests)". Can you verify this to be true? Currently, my internal users work fine but my B2B users sync to crowd with a #EXT#dosinvest.onmicrosoft.com added to the end of the userprincipalname.. this makes it impossible to use the plugin. Do you have any experience with this?
Thank you
Hi Peter, did you manage to address this? We may be observing a similar issue with external users and the plugin
(It is working for external Gmail users with a MS live account, but failing for other users with their own external AzureAD accounts - those accounts can successfully access other resources on our Office365 area, e.g. SharePoint, so we know their external SSO accounts are working...just not through JIRA)
Please have a look at the recently introduced value "user.localuserprincipalname" for an additional claim in SSO section of your AAD enterprise app setting.
Much appreciated for the pointer there @Peter Meuser - claim added and awaiting feedback
It looks like you're new here. Sign in or register to get started.