We have AzureAD / Atlassian Cloud enterprise app setup / groups setup / users in groups / SCIM setup - all good. We have 2 authentication policies in Atlassian Access (one billable and one non-billable for trello free users).
When we turned on SCIM the group used for access to the Atlassian Cloud azureAd enterprise app (some of which were in the billable profile and a good amount in the non-billable profile) > all went into the billable profile and now show they are taking a license (which included all the people that I had in the non-billable profile).
We are working with a consulting group and as part of it was ensured that end users in the company did NOT need an Atlassian Access license to get to the JSM portal via SSO, only the agents that needed a license would need to have Atlassian access licenses.
Once we turned on SCIM I am unable to move any of the managed users that landed in the billable profile, over into the non-billable profile. I don't see how I can ensure that our 4,000 employees can get to a JSM portal via SSO and not get billed Atlassian access licenses for all of them.
I can't find anything on the internet, nothing in Atlassian support, that addresses this situation. The consulting team we are working with are digging into this as well as we just turned this on today and are seeing it.
Thanks!