I want to transition our Single Sign-On from Google Workspace to Microsoft Entra without losing their identity and access to their data.
What is the best option to do it?
@Joel Francisco I am assuming you are not on the Atlassian Enterprise plan, as Enterprise would allow you to configure multiple Identity Providers (IdPs) simultaneously, making this migration much smoother.
In your case, the safest approach would be:
Create a new authentication policy where Atlassian native authentication is enabled and SSO is disabled.
Move all users to this temporary authentication policy first. This ensures users can still log in directly with Atlassian accounts during the transition.
Before making any changes, take a backup/screenshot/export of your current Google Workspace SSO configuration so you can quickly roll back if needed.
Configure Microsoft Entra ID as the new Identity Provider.
Move a small group of test users back to the SSO-enabled authentication policy and validate:
Login flow
User provisioning/sync
Group mapping (if applicable)
Product access
As long as the users’ email addresses in Microsoft Entra match their existing Atlassian account email addresses, they should retain their identity, permissions, and access to their Jira/Confluence data without issues.
Once testing is successful, you can gradually move the remaining users to the new Entra-based SSO policy.
Hello @Akash Singh ,
I am new to this and has been assigned to take over the task. How do I see what kind of subscription we have? Also, can I use the "upn" instead of the email address format. Our users have different email address now because of the buyout but they kept their existing "upn" which match their existing credentials to login with Atlassian.
@Joel Francisco You can check your organization’s subscription by navigating to Atlassian Administration (https://admin.atlassian.com/) and reviewing the Billing section.
If the users will be using different email addresses after the migration, I would recommend raising a support request with Atlassian and providing a mapping CSV containing each user’s current and new email address. Atlassian Support can then assist with performing a bulk email update from their end.
Once all users have been updated to their new email addresses, you can proceed with the previously suggested steps to configure and add the new Entra IDP.
Thank you for your quick reply. Really appreciate it. I guess I need to Raise a support request with Atlassian.
It looks like you're new here. Sign in or register to get started.