The Atlassian Community can help you and your team get more value out of Atlassian products and practices.
We are running Crowd with Jira, Fisheye and Crucible in our company with about 500-1000 users.
What are the best practices in configuring Crowd directories to control authentication to each application? We are using a delegated authentication directory and will have many users needing access to all applications and many different groups.
Would it be best to create one Crowd directory containing all of the users/groups for each application ex.
~OR
Create a separate Crowd directory for each application ex.
Also we will be using SSO-- is this configurable with both options?
Thanks!
I thik it really boils down to how users will use the various tools. If everyone will use everything and can see everything, I'd keep things simple and use the same group to control similar access on all tools. For example, create a "users" group, dump everyone in there and grant the "users" group permissions to log in and do basic functions on each application. If you have more distinction with your userbase, you might need to break things up as you suggest. I see companies that do this both ways. It just depends on your license and security situation. I'm in favor of not adding complexity for complexity's sake, personally.
If your situation permits, I recommendone Crowd directory as Dave mentioned. If you have multiple Crowd directories, you have to add a user who will use all of Jira, Fishehe and Crucible into each directory. It's a troublesome task.
You can also use multiple Crowd directories in order to use multiple directory types. For example, one direcory is LDAP Delegated Authentication and another is Crowd Internal Directory.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks Shun!
Will all of the groups within that directory show up in each application?
If so, does that count towards the license limit in the application?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Yes all groups will show up in each application.
But only the people who can actually log into your application count towards your license limit.
Best regards,
Peter
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi everyone, We’re always looking at how to improve Confluence and customer feedback plays an important role in making sure we're investing in the areas that will bring the most value to the most c...
Connect with like-minded Atlassian users at free events near you!
Find an eventConnect with like-minded Atlassian users at free events near you!
Unfortunately there are no Community Events near you at the moment.
Host an eventYou're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.