hi all,
we use LDAP for user authentications and JIRA groups for permissions in JIRA. we want to move to AD groups for authentications and group membership and auto-disabling the users when they leave.
Our AD groups have everyone within the company and we want to have users only with certain permissions added to our JIRA groups. EX - we do not want business users to have the "Release" function.
when a new user is on board, they will send an email to the network team with the details on what level of access they would need. if they need Confluence, JIRA, Bamboo access, they will specify the AD group and users will be added to those groups. when they leave, they should be disabled from all these groups.
1) From my understanding, I would need the "Read Only" because we want to control the licenses. our JIRA is only internal to IT and not intended for all of the company. so, if we chose Read Only, with Local Groups, user will be automatically added to certain groups.
I think we need "Read Only"
am I on the right path here ?
2) Nested Groups - we want to enable this option. so, As per our permission scheme, SU group in JIRA gets all of the standard permissions. so, we will have a group "IT_JIRA_SU" in AD and map it to SU in JIRA.
and if a user needs "Release" permission ( this permission is mapped to "PA" group in JIRA). I will have another group IT_JIRA_PA" in AD and this group will be nested within the parent "IT_JIRA_SU". when user needs all standard permissions + release permission, they can be added to both these groups in AD.
would this work or am I overlooking anything here ? please suggest.
thanks !