I've configured Active Directory integration for Jira configured for Read Only with Local Groups which works, AD user account and AD groups are presented under User Management. The AD groups are an AD eqivalent of the 3 internal groups that are automatically created (jira-software, jira-servicedesk, jira-adminstrators).
I've applied the AD groups to the Application Access for Jira Software and Jira Servidesk alongside the existing internal groups (jira-software, jira-servicedesk, jira-adminstrators).
I've also applied the AD groups to the 6x Global Permissions, again to match the internal groups. i.e. AD\JIRA_Admin to Jira System Adminstrators etc
I've read that using Global permissions is not the optimal approach and therefore, specifically for the Service Desk project, I want to apply the AD groups to the Project roles. However it only seems to present users and internal Jira groups and not the AD groups. Is this not supported / recommended?
Should I put the AD groups into the internal jira groups instead and use them?
e.g.
AD user -> AD group -> Internal Jira Group ->Project Role
AD user -> AD group -> Internal Jira Group -><global permission>
I assume putting AD groups into internal Jira groups is supported?
Thanks in advance,