Hi all,
I'm trying to set up Atlassian Access for SSO with Azure Active Directory and so far, everything is working fine for regular accounts. e.g. account@verifieddomain.com.
My question is: can Azure B2B guest users also log on to Atlassian Access (e.g. account@somedomain.com)?
On the face of it, it does not seem possible, as their email address domains are not registered as verified domains in Atlassian Cloud. I worked around this by logging in with the Azure UPN (e.g. test1_somedomain.com#EXT#@verifieddomain.com), which correctly redirects to the Azure login page.
Atlassian receives the SAML message, but then displays this message:

I assumed that this was due to the fact that Azure would deliver "test1@somedomain.com" as an assertion inside the SAML message and Atlassian checks that against the verified domains (say, "verifieddomain.com") and the mismatch leads to the message.
Now, I configured Azure so that "whatever@verifieddomain.com" is delivered inside the SAML message:
<Attribute Name="http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress"> <AttributeValue>whatever@verifieddomain.com</AttributeValue>
The same message still appears though. I'm at a loss now. Any suggestions? Has anybody got this to work?
What exactly is happening behind the scenes here in Atlassian Access?
Thanks and cheers
Nils