Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Atlassian Access and Azure AD configuration help with 2 Azure tenants

Rafael Tejero Palma
Contributor
October 1, 2021

Hi all, 

First of all, my experience with Azure AD is very limited and with Atlassian Access I have only been able to check the product general configuration and verify the synchronization of users and groups. Now our customer is asking us for a higher level of configuration with this scenario:

Imagen1.png

  • Initially the configuration was performed on a single domain. That is, a directory was created and domain 1 was claimed. Everything worked correctly
  • Currently domains 2 and 3 that exist in a second Azure AD tenant have been claimed and added to the directory. At this point users and groups have been synchronized in the organization's directory without problems
  • The three domains belong to three companies owned by the same parent company. Some users (like the one with the following error) have accounts on more than one domain.
  • Three domains are on Azure AD
  • After this configuration, one of the users cannot authenticate to Jira with this error:

Imagen2.png

Message (translated): "The selected user account does not exist in tenant "Tenant 1" so the application .... of this tenant cannot be accessed. To do this, it is first necessary to add the account as an external user in the tenant. Use another account."

The login was attempted using an account from domain 2 of tenant 2.

First of all we would need to understand why this error appears (if possible with the data included, and sorry for the limited knowledge of both products) and what would be the proper configuration to avoid this error: federated tenants, creation of a second directory in AA, create a second organization....

Any help will be very appreciated.

Thanks in advanced

Rafa

2 answers

2 votes
Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 5, 2020

Hi @Balaji Shinde , did you follow the instructions here to generate your API token? https://confluence.atlassian.com/cloud/create-an-admin-api-key-969537932.html

It's important to understand that the organization API key is not the same as a personal API key.

0 votes
Edwin Kyalangalilwa
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
February 5, 2020

Hi @Balaji Shinde ,

This is the API you're looking for api-group-Users , although there isn't a way of deactivating users in cloud at the moment.

Authenticating to this you'll use your username and api token as the password.

Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 5, 2020

Hi @Edwin Kyalangalilwa I think @Balaji Shinde has the correct API, this is indeed a new API that we provide to organization administrators for deactivating accounts across all Atlassian products. Deactivating accounts for users that have left the company is the type of scenario it's designed for.

Like Edwin Kyalangalilwa likes this
Edwin Kyalangalilwa
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
February 5, 2020

Gotcha, thanks for the clarification @Dave Meyer !

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events