Hi,
I'm interested in migrating to google apps sign in for my organisation, however the documentation seems to be a little patchy when it comes to understanding what will happen for existing users, what their flow will look like, etc.
I have an org of about 60-70 people, and therefore if I do the migration I would like to know exactly what state things end up in before I do hit the button and cause confusion throughout the business.
So, in no particular order:
- Once accounts are synced, will it only be possible to log in via google accounts or will it also be possible to continue to log in via the original atlassian password? I can see from https://confluence.atlassian.com/cloud/how-g-suite-users-log-in-744721643.html that the atlassian password remains and needs to be used for some things (that our team won't be using), so I need to make sure that we get the benefits of SSO and MFA through google and this can't just be worked around by someone not realising (or by a malicious party trying to gain access to accounts)
- Do groups in google map to groups in atlassian directly? And therefore should I create groups that I am using right now for application access, permissions access etc? E.g. If I am providing access to jira via a "All Jira" group, should I ensure these groups are set up before I start syncing to avoid people being removed?
- What happens once the sync has taken place in the case of the above where you can only log in via google? Does everyone get logged out and they have to log in via google again? This would be good to know for a comms piece
- I assume the login via google takes the user to the google sign in page to do SSO type signin?
- Based on https://confluence.atlassian.com/cloud/enable-or-disable-g-suite-integration-873918510.html, it says "Your users will still be able to log in to your Atlassian Cloud site with their Google credentials. However, their details won't be synced.". Does this mean that atlassian copies over passwords from google (this would be surprising/not good), or if not how does this continue to work if the SSO link has been broken?
Thanks!
Rob