New to Bitbucket server, but I think we are going to like it. We have two stumbling blocks to going ahead with it.
1) From what I read, Bitbucket Server requires the identity of the daemon/service interacting with A/D to have administrative rights. That just aint gonna fly with our already paranoid IT guys. Is this true?
Is there any way around it - I read that there are a few permissions needed, and making the user a full on admin is overkill. Is there a guide of some kind that describes how to give a run of the mill user just these permissions?
If we dont make this user an admin, it seems the consequence is that a deleted user in A/D does not get removed in BitBucket. Correct? Is this the only gotcha with a non admin user for the service identity?
2) Conceptual question: It seems that there are two features to A/D integration. One provides for the normal authentication with A/D but management of what users can access BitBucket left to BitBucket mechanisms.
The other option seems to be more fully functional integration - who can access BitBucket and their group membership along with authentication is handled via A/D.
Do I have it right (oversimplifying I'll bet)? Im kind of at a loss as to how to manage the second of the two. How do I tell BB which groups mean what? Sorry so clueless on this one....
Thanks in advance for any help -
Joe