Hi, I have SAML/SSO working with Azure AD. I can manually add a user in Azure AD and have them show up as a user in Atlassian. I'm struggling to do the following:
- I have two Azure AD groups that I want to assign to groups in Atlassian
- Atlassian-JSD (AAD group) I want to map to the builtin group jira-servicedesk-users
- Atlassian-JiraCore (AAD group) I want to map to the builtin group jira-core-users
- I want to automatically provision the rest of the users in my Azure AD as customers (basically atlassian accounts with NO application access)
Do I need to create an AAD group called "Atlassian-Customers" and add all the non-jira users to it and then synchronize that group? or can I use scoping or something else to say all users in the "mydomain" domain should be synchronized.
I find lots of small docs in the Atlassian confluence that only give me part of the story, but I'm having a tough time finding how to resolve my issue above.