Hello,
I want to use UPN like a login I think is here but I don't find how I can do.
Please help
Thx
Short answer - DO NOT. Nothing else but email will work.
"name" attribute (on the left) is not used by Cloud at all
"urn:oid:0.9.2342.19200300.100.1.1" won't be used by Cloud
the "Unique User Identifier" absolutely MUST be set to user.mail – Cloud uses the email address for everything (whether you want it or not)
Please note, this doesn't prevent you from actually logging into Azure AD with whatever you want – the email, the UPN or the username...
Please see this post as well for how the Atlassian Access User Provisioning should be configured:
https://community.atlassian.com/t5/Jira-Service-Management/Azure-AD-login-and-incoming-email-not-matching-up/qaq-p/1821809#M88619
and for a longer read:
https://community.atlassian.com/t5/Atlassian-Access-questions/Integrate-Azure-AD-with-Atlassian-Cloud/qaq-p/1852575#M3417
This is not accurate. Although you emphasized that everyone should use user.mail, if you have your Azure configured in a way that this attribute is empty in users profiles, it won't work.
Additionally, the instructions from Microsoft mention 2 different scenarios (step 14): if you have MS 365, they recommend you configure this Unique User Id to user.mail, but if you don't have MS 365, then this attribute is not used in Azure, so they recommend you use UPN.
See here the official documentation with instructions to set up SAML SSO with Azure https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/atlassian-cloud-tutorial.
There is no right or wrong, it all depends on how each company's Azure is configured.
To respond @Vincent Arancio , if you have the UPN attribute configure with a valid email address, then yes, you can change the Unique User Identifier (or Identificateur unique del utilisateur) to be UPN.
@gabriel.muller
I will agree to disagree at least on some the parts of your statement. Being an SSO vendor (on Server and Data Center) I know that this "official" documentation is written by Atlassian, not Microsoft. Having engaged with Atlassian multiple times specifically on the matter of integrating Atlassian Access with Azure AD, and having forced the change of this very documentation several times – I know how inaccurate it may be.
I do agree that a lot depends on how your Azure AD is setup, but the original purpose was to describe what matters to Atlassian Cloud. Atlassian Cloud wants to identify the user by an email, though yes, it doesn't matter where the value actually comes from.
One may need expressions in the mapping to address all possible situations e.g. when there are no mail attribute (e.g. for guest users)
I suspect the issue is conflation of UPN and email address between Atlassian Access and their products (Jira, Confluence, etc.) due to reliance on email address as key identifier field for so much functionality. This is unfortunate and I think you are likely right @Ed Letifov _TechTime - New Zealand_
One remedy for Orgs with users carrying mismatching UPN and email domain may be using transformation and expression mappings for provisioning and SAML claims. If we can align provisioning with SAML claim expressions/transformations, it may work?
For instance, SSO claim transformation mapping:
Thoughts? Any experience with this?
Even better would be able to do the mapping to an attribute that doesn't change ie EmployeeID.
This means that regardless of email address changes over time .. the users will still map.
Today, if someones email address changes it'll create a new user in the Access and my guess is we have to get support to re-map the user.
On prem this was solved with separating the username from the email.
We also have multiple internal domains, so we can't do a simple mapping as suggested.
When someone migrates from the cloud then the username could be imported into the unique id field.
I'm guessing there is still a uniqiue ID under the hood on the Atlassian side, but we have no control of it.
Anyone know if Atlassian has looked at this possibility?
It looks like you're new here. Sign in or register to get started.