Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Will Atlassian Access work for B2B Guest users in our Azure AD tenant?

Koen Bins
Contributor
December 30, 2021

Current situation:

We are using the following cloud products: Confluence, Jira Software and Bitbucket. We distinguish two types of users in these products: 1) workers from our own company (registered with a company email addresses) and 2) external users, such as business partners/suppliers (who are registered with their external business email address).

What we hope to achieve:

We would like to use AA to enable SSO, automated user (de)provisioning, and more advanced security policies. We want this two work for all our current users (internal and external).

Questions:

  • Will user provisioning and SSO authentication also work for the B2B Guest users in our IDP? Since:
    • The UPN of a B2B Guest users does not contain our company domain. Instead the UPN will end on "@<companydomain>.onmicrosoft.com", which is a domain we obviously cannot verify.
    • The B2B Guest user can still be identified based on their external business email address, since it is registered as the email address in their Azure AD record. However, we cannot verify the company domain of our business partners/suppliers on which their email address is based.
  • If yes, will AA recognise the existing external users in our cloud products based on their external email address?
  • Any other recommendations or considerations from community members who have set this up successfully?
  • Slightly off-topic: Is it possible to have a subset of users login with SSO, while another group of users still uses their local user credentials (application-side).

Thanks for your help.

 

3 answers

0 votes
Tim van den Heuvel
October 25, 2019

[Double post]

0 votes
Tim van den Heuvel
October 25, 2019

[Double post]

0 votes
Ravya
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Champions.
October 25, 2019

Hey,

May be referring to this link will help you :

Server

https://confluence.atlassian.com/adminjiraserver/assign-users-to-groups-project-roles-and-applications-938847026.html

Add a user to a group
Select  > User Management to view the user list.
Find the user in the user list using the filter form at the top of the page.
Click Groups in the Operations column.
Use the search box to find the group that you want to add the user to. You can add more than one group at a time in that search field if you need to add the user to multiple groups.
Click Join selected groups and the user will be added.

Cloud:

https://confluence.atlassian.com/adminjiracloud/managing-groups-794199009.html

 

--Ravya

Tim van den Heuvel
October 25, 2019

Hi Ravya, thank you for the quick reply. However, when clicking on "User Management" I cannot see the user list? The only options I have is to invite new users or go into the specific settings of either JIRA or Confluence (see screenshot below).

Going to admin.atlassian.com asks me to add "Atlassian Access" to my products? I hope this does not mean that I need to buy another product in order to manage the user access for JIRA and Confluence?

 

Screenshot 2019-10-25 at 15.14.34.png

Jimmy Seddon
Community Champion
October 25, 2019

Hi @Tim van den Heuvel,

Based on the screenshot you provided I "think" you might be in the "Trusted" role not a full  "Site Administrator".  The "Trusted" role gives you access to the administration panel to invite new users with the "Basic" role, but that looks like you are missing a number of options that should be presented to a full "Site Administrator". 

You should speak with one of your other Admins to see if this was configured incorrectly.

I hope that helps!

-Jimmy

Tim van den Heuvel
October 28, 2019

Hi Jimmy, thanks for your reply. Do you know where I can find who is a full site administrator?

Jimmy Seddon
Community Champion
October 28, 2019

Hi Tim,

I don't think there is a good way for you to discover this from the product.  Do you know who setup your Jira instance and gave you access to it?  I would start by talking to that person first.

-Jimmy

Tim van den Heuvel
October 28, 2019

Hi Jimmy, I think I do know who initially setup the instance but that person is longer reachable (email is also inactivated). Is there a way to get around this? Or at least know for sure that his account is the one with whom the JIRA/Confluence instance was setup?

Jimmy Seddon
Community Champion
October 28, 2019

You are going to need to talk to support about trying to correct this one.  You can start that conversation with them here: https://support.atlassian.com/contact/

Sorry I can't offer more help on this one.

-Jimmy

Tim van den Heuvel
October 31, 2019

Thanks anyway Jimmy, I will try to figure it out by contacting them directly.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events