I'm admin on a Jira Data Center instance with several hundred users. So far we've gotten away with manually provisioning users in the Jira Internal Directory and using G-Suite for SAML/SSO.
We've decided to move to Okta for SSO and Universal Directory. We've already spun that up and gotten all of our employees into Okta, and connected Slack and G-Suite to it. The next step is to connect Jira to it. The implementation/setup of this seems straightforward, but I have some questions about how things will work one it's all set up, mostly in regards to groups, roles, etc. I think I know how it will work, but I'd like some confirmation if anyone has gone though this before. Also I think these are mostly the same questions I would have connecting with any kind of LDAP, but Okta might have it's own peculiarities. What's the best way to ensure that when everyone starts logging in through, for lack of a better term, their Okta managed user account, they retain all of the group/project role membership they had from their Internally managed user account?
Based on this doc: https://confluence.atlassian.com/adminjiraserver/connecting-to-an-ldap-directory-938847052.html
We will be connecting Jira to Okta as an OpenLDAP, using 'Read Only with Local Groups', and we will place this connection ABOVE the Jira Internal Directory. This does mean that users will exist in both directories, if I understand things correctly. So, lets say a user bsmith tries to log in. He logs into Okta, then clicks on the Jira application and is signed into Jira via SSO. When this happens:
- Will the Okta bsmith retain the local group membership of the Internal bsmith?
- Will the Project Roles recognize the Okta bsmith in place of the Internal bsmith?
- Will the Okta bsmith be seen as the Internal bsmith in regards to issue assignments, comments, etc?