Hi all,
First of all, my experience with Azure AD is very limited and with Atlassian Access I have only been able to check the product general configuration and verify the synchronization of users and groups. Now our customer is asking us for a higher level of configuration with this scenario:
Message (translated): "The selected user account does not exist in tenant "Tenant 1" so the application .... of this tenant cannot be accessed. To do this, it is first necessary to add the account as an external user in the tenant. Use another account."
The login was attempted using an account from domain 2 of tenant 2.
First of all we would need to understand why this error appears (if possible with the data included, and sorry for the limited knowledge of both products) and what would be the proper configuration to avoid this error: federated tenants, creation of a second directory in AA, create a second organization....
Any help will be very appreciated.
Thanks in advanced
Rafa
Hello, @Constantin Lotz
1) Yes, Atlassian keys everything by email. To be precise – regardless of what is specified in the mapping, i.e. one would think that as per your screenshot the unique identifier is the UPN, but no it's completely ignored, and it's the email that is being used to identify the user.
2) With the configuration in your screenshot the users should be created with emails from the external domains, despite them entering the UPN to trigger the redirect, and logging into Azure with UPN.
Is this not working?
With configuration as per your screenshot, this statement is not correct:
Within Atlassion the User will be created with the upnname and the same value will be the e-mail address value.
3) The triggering to SAML flow happens based on the claimed domains. For you to be able to enter the email with the external domain and be redirected – you need to claim that domain too in Atlassian.
What you then use to actually login into Azure is irrelevant – as soon as you are authenticated the attributes will be sent as per the mapping in your screenshot. If you claim both domains – users will be able to enter either UPN or the email at Atlassian front-door.
Ok thanks a lot, i guess it was the thing that we have to claim both domains :-)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.