Hi,
Sorry for long post.
We have Atlassian organization with Azure AD user provisioning enabled (one AD group with 8 users only).
We have more than 250 managed accounts as well (from different organizations).
Provisioned users and managed accounts share the same domain.
Now we want setup SAML SSO with Azure AD for the same domain (for first organization only.
The first step would be to configure SSO in Atlassian Cloud app in Azure AD.
We don't know proper Atlassian SAML ID since SAML configuration is not started at Atlassian yet. So we will put improper values for Identifier: https://auth.atlassian.com/saml/<unique ID>
and Reply URL: https://auth.atlassian.com/login/callback?connection=saml-<unique ID>
In the next step we will initiate SAML setup at Atlassian side.
After this stage SSO will fail for sure since we are used improper values in first step.
How this affect users? Documentation says: "During the time it takes to configure SAML single sign-on, users won't be able to log in to your Atlassian Cloud applications. Consider scheduling a day and time for the changeover to SAML, and alerting your users in advance."
Only provisioned users will be affected? Or managed accounts from diffrent organizations as well?
After next step - fixing Azure AD URLs setup with proper Atlassian IDs - SSO should work for provisioned users but no managed accounts from different organizations?
Thanks in advance for any help.
Regards,
Tomasz