Appreciate you brining this forward. We literally have one of the domains we manage systematically changing their email domain. It might not help us this time (as we may not be able to implement before that changes completes), but would make future occurrences much easier.
The upside to the change is obvious: maintaining a 1:1 relationship between Entra ID accounts and Atlassian Cloud accounts, are there downsides to this change?
Hi @David Cowley - thank you for your comment. I'm not an EntraID expert, but from what I've understood, there shouldn't be downsides to this change.
Hi Antti,
Thanks for this blog/info, we also hit this issue.Just wondering what is the best practice for Matching precedence on groups ?
Setting it to objectid/externalid doesn't work on groups.
Hi @Stephan van Hienen - thank you for your comment. For some reason provisioned groups is one of the blind spots for Atlassian. They currently don't support changing the names of the groups when provisioning, so matching precedence setting doesn't matter to my understanding.
My latest knowledge is that if a group name changes in Entra ID for example, the group members stay in sync in Atlassian but with the old group name. So the solution is to contact Atlassian support via ticket and ask them to rename the group on Atlassian Cloud's side...
Just some info for people having the issue and ending up with 'duplicate' users, you can remove the scim flag using the api :
The User provisioning REST API REST API
It looks like you're new here. Sign in or register to get started.