Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Logout binding ?

ADyPo
Contributor
October 16, 2020

Hello everyone,

Do you know if there's a logout binding please ?

I only have 2 URLs in Atlassian Access :
- 1 for the entity id SP
- 1 for the assertions SP.
None of them seem to do the trick.

Here's what's happening :

1) Atlassian side : When I logout from Jira and try to connect back with another account, I'm reconnected with the first one (as I'm still logged-in in the identity provider). I was quite shocked when it happened.

2) Identity Provider side : If I activate the "front channel logout" option in my identity provider (to force a redirection to the Atlassian site when I logout from the identity provider) and enter one of the URL, I get a "not found" message or a "can't connect" one (obviously as it's the login callback). So, I can't logout anymore.

There's no logout binding from any side.

All I can do to really logout is to logout from both the Atlassian side and the Identity Provider side (without a redirection / Front Channel Logout option), so that a new connection to the Atlassian site would redirect me to the Identity Provider, where I'm not authentified.

Security-wise, I don't know what to think about that, as there will be thousands of users on this Jira site.

Am I maybe missing something here ?

Thanks a lot in advance for any kind of help, I know it's not an easy topic but you might be a real life saver =).

Kind regards,

Dylan

1 answer

0 votes
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
July 8, 2020

It's a pyramid (top to bottom): A single org admin user in Atlassian Access may create and have access to multiple organisations. I do believe billing will be per organisation (as it is based on the number of managed users). An organisation in Access may have multiple domains "claimed". A user is attributed to an organisation (as a managed user) based on their email domain. 

When the user shows up at Atlassian's login page, everyone has to enter their email – this is when the decision is taken to proceed with asking for a password or redirect to the IdP (Okta).Your connection to Okta will be set up per organisation.

If your subsidiaries have the same email domain – you can only have a single organisation in Access, and thus only one Access bill/subscription and by extension a single Okta application.

If your subsidiaries have different email domains – you can have different organisations (and thus different bills/subscriptions/Okta applications).

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events