Currently, our company utilizes single sign-on in order for our employees to log into and access Jira. Since we use google, as our single sign-on provider that means all users who wish to access Jira, must have a google account, and when they go to log into the Jira site, they log in through google. We recently merged with another company that does not use google, so in order to get them access to the site we have had to generate google users for all new employees that need to access Jira, but they don't use said google profile for any other operations other than to log into Jira, and as a result, it costs us money we could be saving.
My question is multifaceted, so I will break things down below:
- Is it possible to allow single sign-on as an option but not require it? That is to say we want the users with google profiles to still be able to log in the same way they always have, but new users who do not have a google profile can authenticate via username and password.
- assuming that question 1 is true and we can have a mixed ecosystem of both single sign-on and username/password authentication, for a user who previously signed in via google single sign-on, if they then log in via username and password but use the same email as their single sign-on email, will this create a new user profile for them, or will Jira know its the same person and merge the 2 users.
I believe that is the root of my question but as discussion happens on this thread I may follow up with some more questions.
Thanks