Missed Team ’24? Catch up on announcements here.

×
Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Question around enabling Single Sign On

pasharc December 27, 2018

Hello Atlassian Community!

I am very new to the Atlassian suite and am not a software engineer, but have been tasked with understand the potential ramifications/impact of turning on Single Sign On (AzureAD) for out Bitbucket, Confluence, Jira users. I'm not too worried about the impact on Jira and Confluence, but I do worry about the folks using Bitbucket as they may have CI/CD, build pipeline configuration etc. that could break when we enable SSO. Are there any best practices or anything specific to communicate to our end users?

Also what impacts could multi-factor authentication have on this? Once we enable SSO, MFA will also be enabled by default. Any help, guidance or insight is greatly appreciated.

 

1 answer

1 accepted

1 vote
Answer accepted
Stephen Sifers
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 31, 2018

Hello Pasharc and welcome to the Community!

The Atlassian suite will work with Azure AD SSO and MFA. Something things to be aware of with Azure AD MFA is the portal for the applications is controlled by MFA, authentication to the applications themselves are not controlled by MFA since you can only access them from the Azure “myapps” portal. As long as a user has accessed the “myapps” portal, they should not be required to re-authenticate MFA. So MFA should not be an issue with Bitbucket access.

As far as users who are running CI/CD with Bitbucket pipelines, you should review having them use SSH keys for their automation tasks instead of using stored/cached credentials. You may find more at Use SSH keys in Bitbucket Pipelines.

Previously I have used Jira, Confluence and Bitbucket with Azure AD with SSO and MFA without issue. You do have to understand a bit more about how the authentication works, but with SSO enabled it made accessing the products much easier.

When Deploying Azure AD with SSO and MFA, I would highly suggest you do a controlled deployed with a few select users to ensure everything is working as expected. From this test deployment, ensure you include non-technical users to have them review your documentation for the roll out. This will help to ensure your documentation and communication is targeted at all users and not just developers or IT staff.

I hope this helps and provides some guidance.

Regards,
Stephen Sifers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events