Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Deleted user
0 / 0 points
Next:
badges earned

Your Points Tracker
Challenges
Leaderboard
  • Global
  • Feed

Badge for your thoughts?

You're enrolled in our new beta rewards program. Join our group to get the inside scoop and share your feedback.

Join group
Recognition
Give the gift of kudos
You have 0 kudos available to give
Who do you want to recognize?
Why do you want to recognize them?
Kudos
Great job appreciating your peers!
Check back soon to give more kudos.

Past Kudos Given
No kudos given
You haven't given any kudos yet. Share the love above and you'll see it here.

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Does Atlassian Access allow different users to have same email address? Edited

Hi,

We are exploring Atlassian access for user and SSO provisioning to Jira Service Desk Cloud.
We have a mobile app where our users log in using a unique Agent Code and password that is authenticated to AD. However these users may share the same email address. What we want is once the user is authenticated by AD, they can access JSD Customer Portal (Web view embedded in the mobile app) without further login.

If we want to use Atlassian Access for user and SSO provisioning with the condition specified above, is that possible? what will be the pros and cons?

I have read the following article, that might be a conflict if the AD is not configured properly.

https://confluence.atlassian.com/cloudkb/how-to-overcome-email-is-already-taken-error-when-trying-to-change-email-address-of-an-atlassian-access-managed-account-959790039.html

image2018-10-18_0-23-23I guess that if we configure Agent Code as internal id for the users that will not change then our scenario is possible even though these users may share same email id. However, that's only my guess.

I am open to any suggestion from experts and more experienced folks.

Thank you!

1 answer

Hi Priska, 

Thanks for using Atlassian Community. 

To start off with Atlassian Access which provides the SSO solution in Atlassian cloud is done via SAML. Unfortunately, it's not possible to directly use the session token generated by third party AD into accessing a Jira Service Desk portal in cloud. 

With Atlassian Access, the SSO login flow is always via our centralized identity service in https://id.atlassian.com. Our ID service will communicate with your AD via SAML during end user's authentication. On a successful authentication, the browser session token is generated for Atlassian cloud and that will be used when accessing the service in Atlassian cloud (ie. Jira service desk cloud portal). 

The solution also requires the following :

  • The end user has an Atlassian Account in cloud. This is the online identity of your end user in Atlassian and it is identified by a unique email address. This account can be granted access to a Jira service desk portal which makes the user a customer to your service desk.
  • The Atlassian Accounts are under a domain owned by your company. SSO can only be enforced in Atlassian Cloud to all Atlassian accounts that has an email address under your domain. 

The mapping on the KB Page you mentioned refers to how the Atlassian Account is connected to the account on AD side via SAML. Technically, you can have an Atlassian Account under a shared email address under your domain and you can enforce the SSO to that with your AD. On Atlassian side though, the end users' identity will be lost under one shared Atlassian Account, so I would not recommend it. 

On the other hand, Atlassian Access SSO is free to use for unlicensed domain users which makes it free for service desk portal customers. 

May I ask what is your identity service provider and does it support SAML?

Regards,
Ramon

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Atlassian Access

We're launching improved navigation for admins

Hi Atlassian Community, My name is Avni Barman and I am a Product Manager on the Atlassian Access team! One of my top priorities is to help make the administrator's life easier through improved pro...

1,085 views 2 12
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you