Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Does Atlassian Access support nested groups?

Philip Colmer
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 5, 2020

I'm trying to write a script that will sync groups from our LDAP system to Atlassian Access because the Google connector only syncs users. The script uses the documented APIs.

According to the schema, it *looks* like the reference can point at users and groups. Unfortunately, the documentation only references users:

The User provisioning REST API REST API (atlassian.com)

If I try to patch the membership of a group with the id of a group, I get this error:

{"schemas":["urn:ietf:params:scim:api:messages:2.0:Error"],"status":"400","scimType":"invalidValue","detail":"Resource [USER] Missing user: REDACTED"}

The payload only seems to require "value" and "display". I've tried explicitly specifying $ref so that it is clear that a group is being referenced but I'm still getting the same error.

 

1 answer

1 accepted

0 votes
Answer accepted
Prince Nyeche
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 5, 2020

Hi @Philip Colmer 

Welcome to community! Atlassian access or rather Atlassian Cloud doesn't have group nesting for users. the failure for 400 error is because payload is invalid. Please can you share the payload you're using.

Philip Colmer
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 5, 2020

OK - if there isn't support for group nesting, I'll just sync flattened lists of members instead.

Thanks for the confirmation.

Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 8, 2020

Just for context, the primary reason that Atlassian does not support nested groups for user provisioning is that this feature is not supported by major cloud identity providers like Microsoft Azure AD and Okta, which account for the vast majority of our user provisioning API usage. 

https://help.okta.com/en/prod/Content/Topics/users-groups-profiles/usgp-groups-main.htm

https://docs.microsoft.com/en-us/azure/active-directory/app-provisioning/how-provisioning-works#scoping

We're tracking customer demand for nested groups support here: https://jira.atlassian.com/browse/ACCESS-654

Shane Emerson
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 24, 2023

This seems confusing, I have a group setup to sync in Atlassian cloud, and the group does sync to the cloud, but the users in the group are not added to the access policy.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events