We're having quite an interesting use case, which I would love to hear ideas/recommendations for.
Current Situation
We have a current setup where users have to connect via a VPN to access Jira, Confluence, Bitbucket & Bamboo. Some content on Jira & Confluence is "public", so available for anyone without logging in. The VPN makes it so that only company employees are able to view this content as they have to login to the VPN first.
Other users, that need to update the content or work on issues, login to the tools which authenticates to the Active Directory via Crowd. Single Sign On is not enabled currently.
Problem
The VPN is slowly fading out of the business, making our tools one of the few to live behind them. While trying to onboard other teams across the organization, we encountered users that can no longer work with the VPN.
Solution
We're now looking for a way to remove the VPN, while preserving the ability to have some content public, without actually putting it out in the open for the entire internet to read.
We have lots of features of Azure, so many teams are looking into possible solutions, but I wanted to check if there are others out there who have a similar setup.
Our idea would be to create some sort of environment where users are brought to a login page, where they enter their AD credentials and login with 2FA. While being logged in there, they should be able to browse the available content that is 'public'. They can choose to login to the specific Jira or Confluence, but don't have to if they don't have a license.
If they haven't logged in to the central page with 2FA, they should not be able to view the tools at all.
So basically we are looking at ways to let people pre-authenticate on the AD, providing them access to the tools, without being logged in to the tools (so that we don't need to have a thousand fold of our current licenses).
Any ideas or similar use cases?
Looking forward for any feedback!