Provisioning customer accounts from Azure AD

Wim Abts August 26, 2022

Hi, 

We are currently evaluating the Jira Cloud migration and have the following issue that blocks the migration:

We have 2 Active Directories, one for internal users (@zorgi.be) and one for customer accounts (@zorgi.net).

Both AD's are currently linked to Jira (LDAP) and allow our customers to log on to Jira.

These AD's are also synced with Azure AD, allowing us to give the customer also access to SharePoint Online.

These users have a @zorgi.net account, this account also contains there own mail address from their own domain.
Everything working just fine so far, they can reset their password and log on to both using the same account and password.

Now when migrating to Jira Cloud, we would provision all accounts from Azure AD, no problem for the internal accounts (domain verified, accounts can be managed and SSO is working with Azure).
For the customer accounts there is a problem as in Atlassian Access, the account = mail address, so these users will get an account = their own mail address, so no longer the @zorgi.net account....

This would mean that those users will have 2 separate accounts one @zorgi.net to log on to Sharepoint and one = their own mail address to log on to Jira Cloud.

Also SSO will not be possible...

Is anyone having the same case and how did you solve this (if even possible because I don't see how)?

Thanks for your replies!

1 answer

0 votes
Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 26, 2022

Hi @Wim Abts 

SSO is possible only with Atlassian access and a verified domain, in your case @zorgi.net.

You have to find a way to filter out their personal email from your AD and sync only the zorgi email accounts. With these email accounts they will be able to login to your jira instance.

However, although these accounts will NOT count towards your Atlassian Access billing, once you either provide them with product access, or they create with the zorgi email account ANY FREE atlassian product (e.g. trello), then these users will count to your billing.

Wim Abts August 28, 2022

Hi @Alex Koxaras _Relational_ , 

But the zorgi.net account doesn't have a mail address linked to it (only their own mail address), how is Jira going to sent them updates etc of their Jira tickets?

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events