Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,555,306
Community Members
 
Community Events
184
Community Groups

Atlassian Access issues / Authentication Policy missmatch ?/ SSO issue

Hi all,


maybe you can help me:

I have migrated 2 Organisation:

  • Orga A and Orga B
  • Orga A has Atlassian in place.
  • Login to atlassian is done via SSO.

I want to connect users from Orga B to Atlassian Access as well.

I have successfully verified the B-Domain and claimed their users.

  • SSO login to Orga A works
  • SSO login to Orga B does not work

However when trying to access the Orga-B via Atlassian-SSO the login does not work:

https://id.atlassian.com/login/callback?error=unauthorized&error_description=authentication-policy-strategy-mismatch%3FcurrentConnection%xxxxxxxxx%26policyConnection%3Dnull&state=https%3A%2F%2Fstart.atlassian.com%2F

Due to the URL Error I thought this might be related to "recently" released feature "Authentication policies" atlassian released end of last year (https://support.atlassian.com/security-and-access-policies/docs/understand-authentication-policies/)
Keep in mind OrgaA has been created before October2020 and OrgaB just recently

 

In general the SAML connection between our IDP and Atlassian works: 

When updating e.g. the Email addr in the IDP for a user in OrgaB the Email addr will indeed be updated in the user management. 

 

thanks in advance for your help

Felix

1 answer

0 votes
John Price
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Aug 03, 2022

I don't have an answer but have a similar error.  We have Okta SSO set up and due to a merger, logins are from two domains (both verified).  Users from one can log in but users from the other get the above error.  I will file a support case. 

Did you get a resolution for this error? - we are also seeing this error

John Price
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Sep 14, 2022

In our case we had several problems. One was that the AD attribute mapping needed to be different for each org (email, name, etc. weren't stored the same way in the two source directories), so the identity team added some logic like "if domainA.com, pass X to Atlassian else pass Y to Atlassian".  Another was that the new IdP feature had to be toggled on by Atlassian for our org.  I would reach out to support for this; given that they have added/changed a lot around Access lately (for the better), there could be something non-obvious going on.

That's great thank you 

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events