Hi
We recently started using Atlassian Guard and have set up SSO with our identity provider. There was an original default authentication policy containing all users (active and inactive). I created the new SSO policy and added all the active users to it (except one break-glass admin account) and made it default. But now there are two authentication policies both marked as default:
- the original 'Applies to all users' containing inactive users and the break-glass account
- the SSO-enforced policy containing all active users
I was expecting that when I invite a new user they would fall into the 'default' SSO-enforced policy but that didn't happen. I needed to manually move them from the original 'default' policy to the SSO-enforced 'default' policy which means an extra step every time a new user is invited - this can't be right!
How can I solve this? The documentation doesn't cover this scenario https://support.atlassian.com/security-and-access-policies/docs/what-is-a-default-authentication-policy/
I tried deactivating the account of an inactive user but this had no effect in the authentication policies.
I am thinking that the only solution would be to create a new 'non-SSO' policy for the break-glass account and then move all the inactive users into the SSO-enforced policy. Would this work? When there are no members in the original 'Applies to all users' policy, will I be able to make it non-default?
If this method should work, is there any way of doing it other than manually one user at a time? I have searched and do not see any API for changing users' authentication policies.
Thanks,
Julia