All I want to do is update the "Full Name" field of user, using the REST API. Our environment:
- Atlassian Access, JIRA and Confluence
- claimed domain with all our users. All managed accounts.
- using an Identity Provider - SAML integration with our internal SSO system
- two Authentication policies one for "local" accounts which does not go through SSO (a handful of service accounts), the other for SSO users.
For users in the "Local" authentication policy, I can use the User Management API to successfully update the Full Name, no problems.
For users in the "SSO" authentication policy, this errors out:
{"key":"forbidden.fieldMutation","context":{"name":{"allowed":false,"reason":{"key":"authPolicy.saml"}}},"errorKey":"forbidden.field-mutation","errorDetail":{"name":{"allowed":false,"reason":{"key":"authPolicy.saml"}}}}
Ok, so I assume this is because we need to use the User Provisioning API to manipulate users in the SSO policy. However, when I try to use this API, it can't even find the user:
curl --request GET \
--url 'https://api.atlassian.com/scim/directory/<User Provisioning Dir ID>/Users/<user key>?attributes={attributes}' \
--header 'Authorization: Bearer <user provisioning API key>' \
--header 'Accept: application/json'
{"schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"status":"404","detail":"Resource [USER] <user key> not found"}
Just to clarify, we do not use SCIM user provisioning to automatically create or provision users. Our internal SAML provider does not support this. But when users are created, they are automatically claimed into our domain and placed into the SSO default authentication policy.
Users can be manually edited via the GUI, but I've got a couple hundred names to fix and would like an automated method.
Suggestions?
Thank you in advance
EDIT 2024-05-07: Ok, I'm learning how more of this works. I was able to use the User Provisioning API to outright create a brand new user, as well as add an existing user to the list of "synced" users. This generates yet ANOTHER user id string, specific to the identity provider. THIS id can be used in the API call above, and in the User Provisioning API call to update DisplayName.
HOWEVER
We do not (yet) sync our Atlassian Cloud managed users to anything, and thus using the UP-API to update names seems like overkill. Is there no other way to just update a name for a managed, SAML-authenticated user?