Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Atlassian Access and Azure AD configuration help with 2 Azure tenants

Rafael Tejero Palma
Contributor
October 1, 2021

Hi all, 

First of all, my experience with Azure AD is very limited and with Atlassian Access I have only been able to check the product general configuration and verify the synchronization of users and groups. Now our customer is asking us for a higher level of configuration with this scenario:

Imagen1.png

  • Initially the configuration was performed on a single domain. That is, a directory was created and domain 1 was claimed. Everything worked correctly
  • Currently domains 2 and 3 that exist in a second Azure AD tenant have been claimed and added to the directory. At this point users and groups have been synchronized in the organization's directory without problems
  • The three domains belong to three companies owned by the same parent company. Some users (like the one with the following error) have accounts on more than one domain.
  • Three domains are on Azure AD
  • After this configuration, one of the users cannot authenticate to Jira with this error:

Imagen2.png

Message (translated): "The selected user account does not exist in tenant "Tenant 1" so the application .... of this tenant cannot be accessed. To do this, it is first necessary to add the account as an external user in the tenant. Use another account."

The login was attempted using an account from domain 2 of tenant 2.

First of all we would need to understand why this error appears (if possible with the data included, and sorry for the limited knowledge of both products) and what would be the proper configuration to avoid this error: federated tenants, creation of a second directory in AA, create a second organization....

Any help will be very appreciated.

Thanks in advanced

Rafa

1 answer

1 accepted

1 vote
Answer accepted
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
December 17, 2022

Hello, @Constantin Lotz 

1) Yes, Atlassian keys everything by email. To be precise – regardless of what is specified in the mapping, i.e. one would think that as per your screenshot the unique identifier is the UPN, but no it's completely ignored, and it's the email that is being used to identify the user.

2) With the configuration in your screenshot the users should be created with emails from the external domains, despite them entering the UPN to trigger the redirect, and logging into Azure with UPN.

Is this not working?

With configuration as per your screenshot, this statement is not correct:

Within Atlassion the User will be created with the upnname and the same value will be the e-mail address value.

3) The triggering to SAML flow happens based on the claimed domains. For you to be able to enter the email with the external domain and be redirected – you need to claim that domain too in Atlassian.

What you then use to actually login into Azure is irrelevant – as soon as you are authenticated the attributes will be sent as per the mapping in your screenshot. If you claim both domains – users will be able to enter either UPN or the email at Atlassian front-door.

Constantin Lotz
Contributor
January 8, 2023

Ok thanks a lot, i guess it was the thing that we have to claim both domains :-)

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events