Dear Atlassian-Community,
I´ve got a very special requirement and tbh. I´m overwhelmed with information I´ve found so far and (also because of lack of the deep technical knowledge) I can´t provide a dedicated answer.
The situation and requirement one of my customers is comming up with looks as follows:
They have Jira & Confluence Server. The internal main ID provider is PingIdentity which will be connected to their Active Directory and provide a Ping-Directory (which, as far as I understood that right will just replic the AD and is for authentication --> please correct me if I´m wrong).
They want to have SSO (with SAML or OAuth) for both Confluence and Jira but the authentication should be handled via the above mentioned IdP (Ping).
Could anyone give me advice how this could be done? What´s the best way to do? Do I sill have to have the users in Jira/Confluence then? or is it sufficient to have them in the ping directory? or is there any automatic provisioning needed?
One more thing: Does installing crowd help in this sceneraio? As far as I understood crowd would be the Atlassian native tool to offer SSO on Server/DC. It seems to me that it would then be just another tool in between that would be capable of doing authentication but instead I´m using PingIdentity for this. From my point of view Crowd would then be redundant.
Looking forward to your answers/advices/best practices/explanations.
Best
Stefan