Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root


1 badge earned


Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!


Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.


Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!


Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
Community Members
Community Events
Community Groups

Azure AD SCIM User Provisioning Question

Hello all!

We're migrating our on-prem JIRA and Confluence server instances to Cloud.

While setting up Atlassian Access, upon verification of our domain, I have a bunch of managed accounts present. (great, but not quite what I want long term)

We've set up SAML SSO with O365/Azure AD successfully (cheer). For the couple of test users who've tried it out, this is working as expected. 

I'm now working on SCIM user provisioning (from the same Azure AD to the same Enterprise App as used for SAML).  My questions are with adding scoping filters.  Or - maybe there is some other means besides scoping filters to accomplish the following?

  1. Can I scope to provision users from a specific OU rather than syncing everything from Azure AD into Access? 
    1. If not, and I have to use one of the listed attributes, I'm curious as to which you're using for your envrionments (hoping inspiration strikes from your suggestions)
  2. Same question for group provisioning. We'd like to sync the groups in a specific OU only, and not ALL of them in our AD. 

Thanks in advance for you help and insights!

1 answer

2 votes
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Jul 02, 2021 • edited

If you configure your Atlassian Cloud Enterprise Application to "Sync only assigned users and groups" (a drop-down in Manage/Provisioning/Edit Provisioning/Settings) it will only sync individual users and users from groups you assigned to the application in Manage/"User and groups".

It will also sync only groups listed there i.e. if you had a user who is a member of 30 groups, but you assigned only 1 group out of these to Atlassian Cloud – only this group will be synced.

This is why it is recommended to have 2 instances of Atlassian Cloud application - one for SSO, where the assigned groups define who are allowed to do SSO into Cloud, and the other for Provisioning, where the assigned groups get synced with the users who belong to them and can be used for more fine-grained permissions inside the Cloud applications.

Obviously you'd want to have all groups set on the SSO-related application to be in the list of groups set on the Provisioning-related application, but possibly not the other way around.

Thanks for the response.  So what I'm hearing is, we need to use groups.  There isn't a means to pull from an OU (because the traditional OU structure doesn't exist in Azure AD). 

I appreciate the support for the recommendation to use a second app instance.  Now to figure out how to remove the provisioning from the SSO app.

Suggest an answer

Log in or Sign up to answer
AUG Leaders

Atlassian Community Events