Hello!
Is the following scenario possible to achieve in JIRA/Confluence with or without Crowd:
- In Active Directory (AD) we create a group called DepartmentA.
- In Internal Directory (ID) we create a group called Users.
- In JIRA/Confluence/Crowd we nest AD-group DepartmentA inside ID-group Users.
- In JIRA/Confluence/Crowd we manage authorization/authentication via ID-groups
- Removing/adding user in AD-group DepartmentA is reflected in ID-group Users.
So basically authentication and "lower level" (from JIRA & co.'s point of view) group membership is implemented in AD, but there exists an additional abstraction layer within ID.
What i am after is the ability to add several external groups (from AD) inside a single internal group (f.ex. in Confluence). Here is an additional extended example:
- In Active Directory (AD) we create a group called DepartmentA.
- In Active Directory (AD) we create a group called DepartmentB.
- In Active Directory (AD) we create a group called DepartmentC.
- In Active Directory (AD) we create a group called ManagersA.
- ...
- In Internal Directory (ID) we create a group called UsersA.
- In Internal Directory (ID) we create a group called ManagersA.
- ...
- In JIRA/Confluence/Crowd we nest AD-group DepartmentA inside ID-group UsersA.
- In JIRA/Confluence/Crowd we nest AD-group DepartmentB inside ID-group UsersB.
- In JIRA/Confluence/Crowd we nest AD-group DepartmentC inside ID-group UsersC.
- In JIRA/Confluence/Crowd we nest AD-group ManagersA inside ID-group UsersA.
- In JIRA/Confluence/Crowd we nest AD-group ManagersA inside ID-group ManagersA (etc)
- In JIRA/Confluence/Crowd we manage authorization/authentication via ID-groups
- Removing/adding user in AD-group DepartmentA is reflected in ID-group Users.
- Removing all AD-groups and users created in steps 1-6 has no effect on ID-groups
So my primary interest is in creating a single "failure point" for the case our AD gets reorganized (very likely to happen in near future).
If all those DepartmentX/ManagersX-groups (and users!) would get removed from AD, then that would have no effect to the organization described with groups in Internal Directory. When new AD groups are implemented, i'd simply map/nest the relevant ones to the Internal Directory groups that i created in ID before AD reorganization.
Does that make sense?
Best Regards,
J. Arola
p.s. This would be so much more easier to draw :-)