Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Provisioning groups from custom IdP

Jeffrey Anderson
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
November 23, 2020

We use Atlassian Access with a custom IdP proxy running simplesamlphp, which proxies through to a federated login.

Since this is an IdP proxy, I don't think we can just sync the users and groups over, as a valid user has to authenticate against a federation.

But we do provide group information in the SAML assertions sent by our IdP.  

What do I have to do to integrate that group information with Confluence?  We provide a list of groups under the 'groups' attribute.  Is it sufficient to match the names of these groups with Atlassian groups?  Or do I need to modify the group attribute name in some way?

1 answer

1 accepted

1 vote
Answer accepted
Jimmy Seddon
Community Champion
April 30, 2020

Hi @Rohini Kumar,

From my understanding yes.  Verifying your domain to gain control of all Atlassian accounts that have been created with your domain does not.  However, if you are looking for the automatic sync of adding new users, and automatically disabling accounts that have been disabled in your Active Directory as well as the possibility of SSO authentication, you would require Atlassian Access to unlock those features.

I hope that helps!

-Jimmy

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events