Hi,
I’m trying to understand whether this is just expected Atlassian Cloud behavior or whether there is a supported workaround.
Our setup:
- Atlassian Cloud org with Atlassian Guard
- Microsoft Entra ID as SAML IdP
- External user policy set to Single sign-on
- External test user has:
- Jira Product Discovery -> Contributor
- Jira Service Management -> Customer
Problem:
For external users (unclaimed domains), Atlassian keeps sending them to the generic login experience at id.atlassian.com/login, where they can see password/social/Microsoft/etc options.
If they click Microsoft, the flow seems to use Atlassian’s generic Microsoft login path, not a clean organisation-specific SAML-first route.
What I’m trying to achieve:
- External partner users should access JPD/JSM resources through a clean SSO-first route
- I do not want them landing on a generic Atlassian login page with lots of options
- I want something closer to an org-specific instance/login flow
What I want to know:
- Is this generic login behavior expected for external Atlassian-account users?
- Has anyone found a supported way to avoid the generic login page and force a cleaner org-specific SSO- first flow?
- Is the answer basically “you only get that with managed accounts”?
- Has anyone solved this with:
- portal-only customers
- a broker/IdP layer
- shadow managed identities
- some other pattern
I’m not asking about internal verified-domain users. Those work differently. I’m specifically asking about external Atlassian-account users who still need access to Jira/JPD/JSM.
If anyone has gotten this to work cleanly, I’d like to know what the actual supported pattern is.