Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Domain verification with Atlassian Access and GSuites

David Hawn
November 23, 2020

We use GSuites and our domain is verified with Google.  It is not an option for us to disconnect our domain from Google.  We are interested in using an identity provider for SSO and SCIM.  I have read through help pages and some of the community support, and it seems like my options are limited.

I think the following apply to this situation:

  • You're using G Suite

    Your users authenticate with Google. Because you verify your domain as part of your integration with Google, you can't verify your domain from your site. If you want to verify your domain, you'll need to disconnect the G Suite integration.

    If your users for another domain aren't connected through G Suite, you can still verify that domain and subscribe to Atlassian Access security policies for that domain.

  • When you connect to G Suite, you’re unable to provision users via SCIM or use SAML single sign-on because we’ll provision users from G Suite and they’ll be able to authenticate through Google. (from here)

In summary:

  1. I can't disconnect our domain from Google to associate it with Atlassian Access.
  2. I want to use a 3rd party identity provider to provision users and provide SSO.
  3. I specifically don't want Atlassian to automatically provision users based on GSuites users. 

I can't imagine that we are the only company that uses GSuites and wants to use Atlassian Access in this way. Here is a related post.  Are there other options that I am missing?

Thank you for the help in advance.

David

1 answer

0 votes
JimmyVanAU
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
May 1, 2020

Hi,

I can't find the documentation at the moment, but I'm reasonably sure that Atlassian periodically checks the domain verification record (~24-72 hours from memory), so any set up will break. You should leave it in there.

Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
May 3, 2020

That's correct. It's mentioned here but a little bit buried https://confluence.atlassian.com/cloud/verify-a-domain-for-your-organization-873871234.html

We maintain the ongoing check of your text record as a security measure against cases where an attacker may have temporarily gained illicit control of a domain.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events