Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Azure AD sync options

Kamil Sochacki
July 26, 2022

Hi,

Is Azure AD sync options available for all Atlassian plan or only in enterprise?

Set up user syncing | Atlassian Support | Atlassian Documentation

Best regars,

KS

1 answer

0 votes
Ramon M
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
November 12, 2019

Hi Priska, 

Thanks for using Atlassian Community. 

To start off with Atlassian Access which provides the SSO solution in Atlassian cloud is done via SAML. Unfortunately, it's not possible to directly use the session token generated by third party AD into accessing a Jira Service Desk portal in cloud. 

With Atlassian Access, the SSO login flow is always via our centralized identity service in https://id.atlassian.com. Our ID service will communicate with your AD via SAML during end user's authentication. On a successful authentication, the browser session token is generated for Atlassian cloud and that will be used when accessing the service in Atlassian cloud (ie. Jira service desk cloud portal). 

The solution also requires the following :

  • The end user has an Atlassian Account in cloud. This is the online identity of your end user in Atlassian and it is identified by a unique email address. This account can be granted access to a Jira service desk portal which makes the user a customer to your service desk.
  • The Atlassian Accounts are under a domain owned by your company. SSO can only be enforced in Atlassian Cloud to all Atlassian accounts that has an email address under your domain. 

The mapping on the KB Page you mentioned refers to how the Atlassian Account is connected to the account on AD side via SAML. Technically, you can have an Atlassian Account under a shared email address under your domain and you can enforce the SSO to that with your AD. On Atlassian side though, the end users' identity will be lost under one shared Atlassian Account, so I would not recommend it. 

On the other hand, Atlassian Access SSO is free to use for unlicensed domain users which makes it free for service desk portal customers. 

May I ask what is your identity service provider and does it support SAML?

Regards,
Ramon

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events