Let us say that:
- A domain has been verified
- It is set to claim accounts automatically
- An Authentication Policy is configured to enforce SAML SSO through Okta
- An IdP has been set up for Okta
- The IdP has been linked to the Okta Authentication Policy
- The client will SCIM provision users as needed to grant app access.
Is this sufficient to ensure that any Atlassian Cloud Account created independently by a user using the verified domain will be required to authenticate through Okta? The scenario presented by the client is:
Somebody creates a google group with an email address within the verified domain. Can they now go to Atlassian Cloud and create an account with that email address? Would the user be assigned to the default Local Directory policy that doesn't require SSO? Or would the account be associated with the Okta Authentication Policy that requires SAML SSO?
This is not my area of expertise, so I want to make sure nothing is missing that would be required. I read about also linking domains to the IdP, but I was not sure if that was also required in this situation. The reference was in a workaround here, and was in reference to JIT user provisioning, so I'm not sure it is applicable.
https://jira.atlassian.com/browse/ID-6802