Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Next challenges

Recent achievements

  • Global
  • Personal

Recognition

  • Give kudos
  • Received
  • Given

Leaderboard

  • Global

Trophy case

Kudos (beta program)

Kudos logo

You've been invited into the Kudos (beta program) private group. Chat with others in the program, or give feedback to Atlassian.

View group

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Does Atlassian Access support nested groups?

I'm trying to write a script that will sync groups from our LDAP system to Atlassian Access because the Google connector only syncs users. The script uses the documented APIs.

According to the schema, it *looks* like the reference can point at users and groups. Unfortunately, the documentation only references users:

The User provisioning REST API REST API (atlassian.com)

If I try to patch the membership of a group with the id of a group, I get this error:

{"schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"status":"400","scimType":"invalidValue","detail":"Resource [USER] Missing user: REDACTED"}

The payload only seems to require "value" and "display". I've tried explicitly specifying $ref so that it is clear that a group is being referenced but I'm still getting the same error.

 

1 answer

1 accepted

0 votes
Answer accepted
Prince Nyeche Community Leader Nov 05, 2020

Hi @Philip Colmer 

Welcome to community! Atlassian access or rather Atlassian Cloud doesn't have group nesting for users. the failure for 400 error is because payload is invalid. Please can you share the payload you're using.

OK - if there isn't support for group nesting, I'll just sync flattened lists of members instead.

Thanks for the confirmation.

Dave Meyer Atlassian Team Nov 08, 2020

Just for context, the primary reason that Atlassian does not support nested groups for user provisioning is that this feature is not supported by major cloud identity providers like Microsoft Azure AD and Okta, which account for the vast majority of our user provisioning API usage. 

https://help.okta.com/en/prod/Content/Topics/users-groups-profiles/usgp-groups-main.htm

https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/how-provisioning-works#scoping

We're tracking customer demand for nested groups support here: https://jira.atlassian.com/browse/ACCESS-654

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
Community showcase
Published in Atlassian Access

We're launching improved navigation for admins

Hi Atlassian Community, My name is Avni Barman and I am a Product Manager on the Atlassian Access team! One of my top priorities is to help make the administrator's life easier through improved pro...

923 views 1 10
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you