Hi,
I just got done setting up SAML SSO in Azure but when I go to our company's organization, I have to click sign in with Microsoft even tho I clicked Jira through myapplications.office.com. I followed the instructions in this document https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/atlassian-cloud-tutorial and I think the sign on URL is what's giving me problems.
Basically I am getting 2 atlassian verification page when I should only get 1. Any ideas?
If you, instead of clicking on the icon in the Azure portal, simply navigate to your atlassian cloud URL, then instead of clicking on sign in with Microsoft, type your email, as if you are going to use password credentials - what happens then? If you are not redirected to Azure then - your SAML SSO hasn't been setup correctly.
When I type my email it says "opening single on" and works but Jira should also open in myapplications.microsoft.com when i click the tile. even when signed into our microsoft account it asks me to sign in my account again. any suggestions? thanks for the help as well!
So, SSO works when doing "SP-initiated" but not when doing "IdP-initiated"
Did you do step 4 here: https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/atlassian-cloud-tutorial#configure-azure-ad-sso
Atlassian document also mentions it: https://confluence.atlassian.com/cloud/saml-single-sign-on-943953302.html#SAMLsinglesign-on-1.AddtheAtlassianproducttoyouridentityprovider
"For identity provider initiated SAML, enter your organization's URL as the default relay state. Include https:// as part of your organization's URL."
https://
We want SP-initiated mode, but we don't want the second id.atlassian.net verification page - we want it to go straight into the app.
I have done quite a lot of tests on iOS 11 and at this point, I have come to the conclusion that the SFAS sometimes doesn't work as expected.
Here is what I have done:
myaccount.google.com
Step 7 doesn't always work, sometimes I have to enter my credentials again.
Have you guys come across anything similar before? I think in order to reproduce this, you have to make sure remove the existing cookies from Safari first. It looks like SFAS doesn't always sync the cookies from SFAS back to Safari.
I tried with Keycloak and I see the same behaviour. Sometimes the SFAS syncs the session back to Safari, and when this happens, the other apps can perform SSO. But sometimes this doesn't happen and SSO doesn't work in other apps.
This is not a bug with AppAuth itself, I just want to make sure I am not the only one seeing this issue. If this is the case, I think it should be documented the SSO doesn't always work.
It looks like you're new here. Sign in or register to get started.