I would like to configure SSO for my JIRA platform however it is used by external clients, can I enforce SSO for some users but not all using Microsoft's provided plugin?
@[deleted]
There are multiple SSO plugins (SAML and OAuth/OIDC) on the Atlassian Marketplace which allows you to enable SSO for some users based on their groups or domain.
Thanks,
Lokesh
Full Discloser:- I work for the miniOrange one of the top SSO vendors in the Atlassian Marketplace.
As a miniOrange representative are you able to confirm if your product would work with Azure AD as described?
Hi Alex.
I work for Kantega SSO, and our app allow you to apply SSO for a limited group of users. The screenshot below shows how you can redirect members of a group ( "external_clients") to SSO authentication (AzureAD in this example). As an alternative to group memberships, you can also limit SSO redirections based on email domain or user directory existence. We type of SSO redirection is called 2-step login, as we first ask users to type in their username. You can read more about it and see a video of the user experience here: https://kantega-sso.com/articles/2steplogin/Regards,Jon Espen IngvaldsenKantega SSO
Hi @[deleted],
Yes, you can configure the plugin with Azure AD to achieve your use case, and in case, if needed, we can also customize the app to achieve your use case.
Here are the documents to configure the plugin with Azure AD for SAML SSO.
https://plugins.miniorange.com/saml-single-sign-on-sso-jira-using-azure-ad-idp/
Feel free to reach out to miniOrange support in case of any questions or need assistance with the plugin configuration.
Hi Alex,
to close the circle - you already got the posts from the fellow Kantega & miniOrange colleagues.
I'll add our answer as well - them you have the Top 3 Plugin Vendors (https://marketplace.atlassian.com/search?query=saml) in this thread.
We probably give you the most flexible approach by having multiple Ways to do what we call "IdP selection".
Here is a link to a YouTube tutorial I recorded a while ago, which demo's the methods available in our plugin: https://youtu.be/DoNir7eN87o (8 mins).
That hopefully gives you a very good impression of what is possible.
If you like to get more of a general impression about the setup of our plugin with AzureAD you'll find our step-by-step guides & video tutorials for Azure here: https://wiki.resolution.de/doc/saml-sso/latest/jira/setup-guides-for-saml-sso/azure-ad
Hope this helps!
Cheers, Chris
P.S. Full disclosure, I work for resolution, a marketplace vendor.
Since we already have three SSO app vendors here, I'll join the party with our EasySSO for Jira!
First, a rhetorical question: if you haven't yet performed authentication - how do you know who the user is in order to exclude them from that authentication?
As @Jon Espen Ingvaldsen Kantega SSO mentioned you need to ask them for the username... but if you have to ask their username the 0-step promise of SSO becomes moot and you end up with a 2-step process.
At the time we decided against implementing something like that and instead opted for an approach based on IP Filtering that for external users is often configured based on reverse proxy IP address. This way you can segregate your network and offer different behaviour to different segments e.g. SAML for external users and NTLM/Kerberos for the internal ones, or SAML for those on the internal network and no SSO for the external ones.
With SAML in EasySSO you can also configure a SAML Login button to be added to the login forms, including Jira Service Desk login form - so your internal users can press that, and your external ones can continue using password credentials.
It looks like you're new here. Sign in or register to get started.