Prevent users from Crowd to be users in JIRA or Confluence

Hi

We use Crowd with a single user directory to control user access to JIRA and Confluence. The problem is that all users in the directory, even if the do not have access to the corresponding application, are visible in JIRA and Confluence and do count against the license limit.

How can we define access to Confluence or JIRA within Crowd for certain groups and not for others? Is the only way to do that having different directories?

 

Best regards

Andy

1 answer

This widget could not be displayed.
Ann Worley Atlassian Team Sep 25, 2017

You can definitely limit which groups can access Jira and Confluence from Crowd. Click on the Application in Crowd, click the Directories tab and choose False under Allow all to authenticate. Then go to the Groups tab and limit access to the groups you want.

Here are more details on how this works: Specifying which Groups can access an Application and Mapping a Directory to an Application

I understand how to enable a group for a specific application, and I have set "allow all" to false for any application (except Crowd).
My problem is that all users are visible in all applications: it seems that all groups defined within Crowd are propagated to all applications, even though they are not allowed to authenticate.

We are using version 2.10 of Crowd and have connected 2 JIRA instances, 1 Confluence and 1 Bitbucket instance.

Ann Worley Atlassian Team Sep 25, 2017

I misunderstood the question.It sounds like there are two issues, one is that the users are visible in the applications that they don't use and the second issue of them taking up licenses.

To keep the users from showing up in the wrong applications you could set up different Directories for each application in Crowd. However, if you want to use Single Sign-on at some point you will need to use the same directory for all the applications. It seems like if the users don't take up a license it will be ok that they are listed in the user management consoles.

The license counts in Jira, Bitbucket and Confluence depend on Global permissions, so you can control which users take up a license by setting permissions:

Jira

Users with any of the following Global Permissions and is an Active status will count towards the license:
JIRA applications System Administrators
JIRA applications Administrators
JIRA applications Users

Confluence

Global Permission
Description
Can Use
This is the most basic permission that allows users to access the site.
Users with this permission count towards the number of users allowed by your license.

Bitbucket

User accounts that have not been assigned "Bitbucket Server User" permission or higher, either directly or through group membership, will not be able to log in to Bitbucket Server. These users are considered unlicensed and do not count towards your Bitbucket Server license limit.

Thank you for your quick answer. I set up a separate directory for all external people, so I can to some extent limit access and license count.

However, I do not understand why all groups in a directory are propagated to all connected applications. In my opinion propagation should be limited to those groups assigned to an application.

Ann Worley Atlassian Team Sep 25, 2017

I am happy to hear you found a workaround for your setup.

Judging by the comments on Improvement for Crowd to have selectable group sync it looks like the reason all groups from the directory are synchronized to the applications is:

...keeping memberships common across the applications is simpler and allows for groups like developers that have common cross-application behaviour.

Lukasz Pater Atlassian Team Sep 26, 2017

For context there is an open feature request for limiting the users visible to the application to only those that can authenticate here: https://jira.atlassian.com/browse/CWD-432.

Currently a workaround is to configure directories with the right users, and then attach them to the correct applications (which sounds pretty close to what you ended up with).

Suggest an answer

Log in or Sign up to answer
Atlassian Summit 2018

Meet the community IRL

Atlassian Summit is an excellent opportunity for in-person support, training, and networking.

Learn more
Community showcase
Published Feb 27, 2018 in Crowd

The Crowd team is looking for feedback on Server & Data Center customers' identity strategies!

Do you own more than one Server or Data Center product? Do you have challenges provisioning users across your Atlassian products? Are you spending a lot of time integrating each Atlassian product wit...

1,392 views 6 14
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you