I am having an SSO issue which is basically the same as below, but with Confluence.
[https://answers.atlassian.com/questions/222631/jira-ad-custom-sso]
Previously, we have been using the Internal Confluence Directory autenticated via LDAP.
Addition of a custom SSO authenticator (written by a 3rd party) has been successful in a test environment, but only for users who already had a confluence account. Users who did not previously have an account are not added to {noformat}cwd_user{noformat}, nor are any default groups added to the internal directory.
I'm unwilling to hand over all control of users and groups to an external SSO provider since that would limit the use of user-groups within individual spaces. Ideally I'd like a way to use the default confluence authenticator if the user has not previously logged on via LDAP and otherwise use the SSO authenticator.
Does anyone have any suggestions on this?