You're on your way to the next level! Join the Kudos program to earn points and save your progress.
Level 1: Seed
25 / 150 points
Next: Root
1 badge earned
Challenges come and go, but your rewards stay with you. Do more to earn more!
What goes around comes around! Share the love by gifting kudos to your peers.
Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!
Join now to unlock these features and more
Starting a discussion thread to see how people are using SAML SSO -
Thank you @Capi _resolution_ for your response, some interesting points there.
Small/Large organizations can both benefit from a third party plugin if they don't want to take overhead of setting up identity infrastructure and configuration part themselves.
A plugin is obvious choice if there are certain requirements that cannot be accommodated by the Data Center SAML SSO. And having complete user management lifecycle in place comes in very handy for managing new joiners/leavers etc. which otherwise could be a manual and time consuming process in some cases.
The Atlassian native SAML SSO is relatively easy to setup/implement and most customers are happy using it depending on their requirements.
You are right, I should post something similar in Enterprise Group as well :)
Hi, we are in the process of switching from Jira LDAP with Microsoft ADFS to Jira SSO with Azure AD and wanted to use the out of the box SAML SSO provided by Atlassian.
Initial testing shows a rather large shortcoming for us, for anyone probably, that is the fact that names of users and groups are not returned, but rather IDs and this is not useful for us.
We are currently evaluating third party add-on "User Sync for Jira" from vendor re:solution, because the vendor has the highest ratings and most downloads for their products and it seems to be doing the job for us. We are still evaluating how to deal with 'service accounts' we inherit from LDAP and how to do this with the new setup and I had some weird experience where I was kicked out of the sys-admin group and had to request another sys-admin to add me back; possible related to logging in sometimes via SSO and other times with LDAP still as we have them next to each other.
We also have to check and see if we can disable or hide LDAP login completely and we use the Atlassian SSO together with re:solution's User Sync so we are not completely dependent on a third party solution.
So we have our users login via SSO from Atlassian's SAML SSO and we enrich the user and group data with re:solution's add-on. Does that make sense?
So yes there are benefits to using a third party add-on and yes we prefer to do that because of the additional features which we really require for our setup.
On a side-note I have worked with the Insight Azure module to import users and groups from Azure AD as well and this works nicely.
I was able to set up a periodic import from our Azure AD and this way we can retrieve additional information about our users (such as location, department, manager, etc), but I am still unable to apply this in the way I would like: I was hoping to enrich the user fields (mainly reporter and assignee) to show a hover-over panel with additional details like we do now with the User Profiles add-on from Communardo Products GmbH. I'm still reading up on Inisght's possibilities but so far don't see how this can be used in a way that will help us much. Tips are appreciated for this by the way ;)
Cheers