Strangely Atlassian is freezing support requests as soon as I open them, so will try to ask here:
I understand the concept of a non-billable authentication policy. What I don't understand is how that works when the users for our site are managed by an external IdP & we enforce SSO. In order for an account to access Jira, it must be part of the jira-users group. jira-users group is sync'd & managed by our IdP.
But according to Atlassian's documentation: You can't add the users you sync from your identity provider (e.g., Okta, Azure AD, Google Workspace) to a non-billable policy.
So in this case, how can I add an existing account to a non-billable policy if it's managed by our IdP? Or create a new account to be part of the non-billable policy if it requires an email invite link to be valid and also needs to be part of the jira-users group anyways to access?
Thank you,
Jason