Hi, We are currently using Atlassian cloud - JIRA and confluence and we have standard users using their email and password to login. We have some internal users as well as external users. For example
Internal Users - user1@mycompanydomain.com.au
External Users - user2@externaldomain.com.au
We want to move the authentication to Azure AD using Single Sign on. As i understand so far, we will need to
1. Verify the domain (mycompanydomain.com.au)
2. Create the Atlassian cloud application in Azure AD and exchange SAML metadata.
3. Create users and groups in Azure AD and assign it to the Atlassian Cloud application in Azure AD
4. SCIM provisioning of users from Azure AD to Atlassian cloud.
The questions I have is:
Q1. We currently have multiple confluence pages, workspaces, JIRA boards, etc. How will it impact the users when we move from Standard Credentials to SSO ?
Q2. Is it correct understanding that the authentication is managed via SSO, however authorization is still managed via Atlassian cloud ?
Q3. we currently have multiple groups in Atlassian. For ex. groupA_internal, groupB_internal, groupC_external and so on. When we move to SSO, How would Atlassian know that the users in groupA_internal to use the same level of permission to confluence/JIRA that it has as part of the same credentials? Is there any mapping required to be done in Azure AD?
Q4. There are few users (at executives level) who has access to certain confluence pages, which others don't have. will there be any impact to them ?
Q5. When a new user is added to Azure AD group that is assigned to Atlassian application, what level of access the new user will have ?
Q6. once we cut over to SSO, how do we remove the standard login method?
I am doing similar set up
https://community.atlassian.com/t5/Atlassian-Access-questions/Existing-Users-When-Moving-to-Atlassian-Access-and-SSO/qaq-p/1308240