Come for the products,
stay for the community

The Atlassian Community can help you and your team get more value out of Atlassian products and practices.

Atlassian Community about banner
4,361,412
Community Members
 
Community Events
168
Community Groups

Provisioning customer accounts from Azure AD

Hi, 

We are currently evaluating the Jira Cloud migration and have the following issue that blocks the migration:

We have 2 Active Directories, one for internal users (@zorgi.be) and one for customer accounts (@zorgi.net).

Both AD's are currently linked to Jira (LDAP) and allow our customers to log on to Jira.

These AD's are also synced with Azure AD, allowing us to give the customer also access to SharePoint Online.

These users have a @zorgi.net account, this account also contains there own mail address from their own domain.
Everything working just fine so far, they can reset their password and log on to both using the same account and password.

Now when migrating to Jira Cloud, we would provision all accounts from Azure AD, no problem for the internal accounts (domain verified, accounts can be managed and SSO is working with Azure).
For the customer accounts there is a problem as in Atlassian Access, the account = mail address, so these users will get an account = their own mail address, so no longer the @zorgi.net account....

This would mean that those users will have 2 separate accounts one @zorgi.net to log on to Sharepoint and one = their own mail address to log on to Jira Cloud.

Also SSO will not be possible...

Is anyone having the same case and how did you solve this (if even possible because I don't see how)?

Thanks for your replies!

1 answer

0 votes
Alex Koxaras Community Leader Aug 26, 2022

Hi @Wim Abts 

SSO is possible only with Atlassian access and a verified domain, in your case @zorgi.net.

You have to find a way to filter out their personal email from your AD and sync only the zorgi email accounts. With these email accounts they will be able to login to your jira instance.

However, although these accounts will NOT count towards your Atlassian Access billing, once you either provide them with product access, or they create with the zorgi email account ANY FREE atlassian product (e.g. trello), then these users will count to your billing.

Hi @Alex Koxaras , 

But the zorgi.net account doesn't have a mail address linked to it (only their own mail address), how is Jira going to sent them updates etc of their Jira tickets?

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Atlassian Access

Atlassian Access Demo Q&A Recap

Hi Community! Thank you to all who joined our ongoing monthly Atlassian Access demo! We have an engaging group of attendees who asked many great questions. I’ll share a recap of frequently ask...

1,515 views 5 5
Read article

Atlassian Community Events