At the moment, we're running Jira, Confluence and Service Desk as self-hosted server products. Each of them syncs to our LDAP infrastructure, which holds account information for internal and external users.
I'm trying to map all of this onto the Cloud offerings and I'm stuck with how to deal with the external users.
I've got Atlassian Access syncing against Google for the internal users, with our verified domain.
It looks like we can't use Atlassian Access to hold accounts for our external users, even if we tried to use the REST API to do so, because the documentation says:
"A user account can only be created if it has an email address on a verified domain."
and I'm not going to be able to claim verification on every domain.
In theory, I think I could work around this by creating "local" users on each of the actual Cloud products ... but then the group membership breaks because the groups are held in Atlassian Access ... and they are going to be incomplete because they can't hold external users.
What the heck can I do? I thought that I could use our Keycloak SAML server but (a) that isn't one of the supported IDPs and (b) I think we'd hit the external domain problem again.