Hi Team,
We have one organization with two cloud sites one is production instance and second one is test instance.
We are trying to enable SAML SSO by following below link:
https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/atlassian-cloud-tutorial#configure-atlassian-cloud-sso
As per the above mentioned guide in one of the step we have to provide our instance details.
On the Basic SAML Configuration section, if you wish to configure the application in IDP initiated mode, enter the values for the following fields:
a. In the Identifier text box, type a URL using the following pattern: <a href="https://auth.atlassian.com/saml/<unique" target="_blank" rel="nofollow noopener noreferrer">https://auth.atlassian.com/saml/<unique</a> ID>
b. In the Reply URL text box, type a URL using the following pattern: <a href="https://auth.atlassian.com/login/callback?connection=saml-<unique" target="_blank" rel="nofollow noopener noreferrer">https://auth.atlassian.com/login/callback?connection=saml-<unique</a> ID>
c. Click Set additional URLs.
d. In the Relay State text box, type a URL using the following pattern: https://<instancename>.atlassian.net
so my question here what should we provide in the Relay state text box (point d). If we provide only one of the instance link test site/prod site. Will the SSO is enabled only for that particular instance?
Also in other step it is mentioned that
Click Set additional URLs and perform the following step if you wish to configure the application in SP initiated mode:
In the Sign-on URL text box, type a URL using the following pattern: https://<instancename>.atlassian.net .
What is the difference between IDP initiated mode and SP initiated mode. Do we need to both the steps?