I am looking for community advice on how best integrate existing on-prem Confluence, Jira Software with ADFS.
Currently, each application connects directly to an LDAP user directory (Active Directory). Vast majority of our users are AD users (99%) and practically all permissions and access rights are assigned via membership in AD groups. Overall, we have over 1000 users and groups in AD that are used by Confluence and Jira (space/project permissions, 3rd party addons permissions and such).
Both Confluence and Jira have a regular Server license (not DC), so there is no direct way to integrate with a SAML based IdP such as ADFS.
According to a diagram in this document here, using Atlassian Crowd might be a solution to overcome that limitation (scroll down to "using Atlassian Crowd ... with Active Directory Federation Services"), however the document doesn’t give any further details.
I have deployed a new Crowd instance, but it's not yet connected to any external directories (there is only one internal directory created by the setup wizard).
Specific questions that I'm looking for your input (focusing on Confluence first):
- How do I add (integrate) existing Confluence application into Crowd, and at the same time ensuring that existing AD users and groups continue to work as they do today (user permissions, access rights don't change)? Available documentation that I found so far covers only adding an application that uses local accounts and groups, whereas my application uses AD users and groups.
- After I have Crowd doing the authentication part for Confluence, how do I switch Crowd from LDAP to ADFS?
- Does this plan make sense (doable)? If I'm missing something and you would do it differently, what way would you do it?
Any advice and suggestions will be greatly appreciated!
Installed Crowd version: 3.7, Confluence: 7.1, Jira: 8.5