What is the best way to configure directories in Crowd?

We are running Crowd with Jira, Fisheye and Crucible in our company with about 500-1000 users.

What are the best practices in configuring Crowd directories to control authentication to each application? We are using a delegated authentication directory and will have many users needing access to all applications and many different groups.

Would it be best to create one Crowd directory containing all of the users/groups for each application ex.

  • Company directory
    • jira-users
    • jira-administrators
    • jira-developers
    • fisheye-users
    • fisheye-administrators
    • fisheye-developers
    • crucible-users
    • crucible-administrators
    • crucible-developers

~OR

Create a separate Crowd directory for each application ex.

  • Jira directory
    • jira-users
    • jira-administrators
    • jira-developers
  • Fisheye directory
    • fisheye-users
    • fisheye-administrators
    • fisheye-developers
  • Crucible directory
    • crucible-users
    • crucible-administrators
    • crucible-developers

Also we will be using SSO-- is this configurable with both options?

Thanks!

2 answers

1 accepted

I thik it really boils down to how users will use the various tools. If everyone will use everything and can see everything, I'd keep things simple and use the same group to control similar access on all tools. For example, create a "users" group, dump everyone in there and grant the "users" group permissions to log in and do basic functions on each application. If you have more distinction with your userbase, you might need to break things up as you suggest. I see companies that do this both ways. It just depends on your license and security situation. I'm in favor of not adding complexity for complexity's sake, personally.

If your situation permits, I recommendone Crowd directory as Dave mentioned. If you have multiple Crowd directories, you have to add a user who will use all of Jira, Fishehe and Crucible into each directory. It's a troublesome task.

You can also use multiple Crowd directories in order to use multiple directory types. For example, one direcory is LDAP Delegated Authentication and another is Crowd Internal Directory.

Thanks Shun!

Will all of the groups within that directory show up in each application?

If so, does that count towards the license limit in the application?

Yes all groups will show up in each application.

But only the people who can actually log into your application count towards your license limit.

Best regards,

Peter

Suggest an answer

Log in or Join to answer
Community showcase
Teodora [Botron]
Published Feb 15, 2018 in Marketplace Apps

Jira Inferno: The Nine Circles of Jira Administration Hell

If you spend enough time as a Jira admin - whether you are managing a single, mid-sized instance, a large enterprise one or juggling multiple instances at once - you will eventually find yourself in ...

1,195 views 6 19
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you
Atlassian Team Tour

Join us on the Team Tour

We're bringing product updates and pro tips on teamwork to ten cities around the world.

Save your spot