Are you in the loop? Keep up with the latest by making sure you're subscribed to Community Announcements. Just click Watch and select Articles.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

migrate local users to Azure+scim

Hi all,

currently about 2,000 of our members (of our domain) have existing accounts with Atlassian. The domain has been claimed, those accounts are visible as "local", I can manage them locally (e.g. disble and delete former members).

I connected Access to Azure for SAML and SCIM. My domain has been connected to the identity povider.

I can successfully create NEW users and groups using Azure+SCIM.

However, I would like to manage existing accounts using SCIM, which fails. The username could be easily linked to Azure, but using SCIM manually I can verify that only 10 of my 2,000 users are visible via SCIM. Those are the accounts that have been created usind SCIM in the first place.

How can I transfer accounts from local to Azure-management? I expect Azure to automatically link them, once they are visible using SCIM.

 

Best regards
Patrick

 

1 answer

0 votes
Craig Castle-Mead
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
Feb 06, 2023

Hi @of7085 

Based on your description, I assume you have the below in Access:

  • A local authentication policy that contains all of the users who you claimed/added before you setup your AzureAD connection in Access
  • An SSO authentication policy that contains all of the users you’ve provisioned in AzureAD since the connection was established

 

If that’s the case, and all users in the local policy have the same usernames as would come from AzureAD, I’d expect the below to work (validate with a small sample of low impact users first):

  • Ensure users in the local policy are added to AzureAD in the way you’d add them if they were net new users
  • In Access, move the users from the local authentication policy to the AzureAD auth policy. This should then create a SCIM connection between the user and AzureAD object.

 

CCM

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events