Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Single Sign on for internal and external users

Celerity Atlassian Admin
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
December 21, 2017

I am considering using SAML SSO for Confluence and Jira, but have 2 sets of users: those on my domain, and customers who do not have identities in my domain. If I configure SSO, is there a way to enforce it for users with an @mydomain.com username but allow for usernames NOT using an @mydomain.com username to continue to use their username and password?

 

Thanks in advance

3 answers

0 votes
Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 22, 2022

For most organizations if you had multiple Active Directory or LDAP external directories connected to your Atlassian server products, these directories would be connected to a single cloud identity provider like Azure AD as a universal directory. 

There's some basic architecture diagrams for how this works in Azure AD here (https://docs.microsoft.com/en-us/azure/active-directory/hybrid/choose-ad-authn#architecture-diagrams) but typically if there are people within your company that manage your Azure AD deployment, or manage how you log in to other SaaS applications, then it's best to connect with them and understand your org's identity environment.

0 votes
Dave Mathijs
Community Champion
August 22, 2022

Hi @Dave Meyer , thanks for the quick answer.

I'm aware of the support for multiple identity provider connections, but unfortunately, that is a Cloud Enterprise Plan exclusive feature, so not available for the Standard/Premium Plans.

I have no knowledge whatsoever about Azure AD, so can you confirm that Azure AD can pull in users from different domains/tenants?

0 votes
Dave Meyer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 22, 2022

Hey @Dave Mathijs

We actually launched support for multiple identity provider connections for customers with our Cloud Enterprise plan last week. https://community.atlassian.com/t5/Enterprise-articles/Multiple-identity-provider-support-now-available-in-Cloud/ba-p/2093719

However, for this scenario, it's much more common to have multiple directories of different types connected to a single identity provider, and then Atlassian cloud connects to that one identity provider. Basically every major identity provider can pull in users from various types of external directories (Okta and Azure AD examples attached)

https://docs.microsoft.com/en-us/azure/active-directory/hybrid/whatis-hybrid-identity

https://help.okta.com/en-us/Content/Topics/Directory/ad-agent-get-started.htm

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events