Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Azure Active Directory SAML 2.0 Setup for Jira Align

Azure Active Directory is a popular SAML 2.0 service. The following is an example of how we have tested and configured Azure with Jira Align. Please review the following example and adjust as needed for your organization's security policies and practices. 

 

Azure

1. Sign into Azure and click on Azure Active Directory.

1.png

2. Select Enterprise Applications from Manage in the left column. 

2.png

3. Click on New application.

3.png

4. Select Non-gallery application.

4.png

5. Name the application something relevant to your organization and/or the application itself and click Add. In this case, we've named it JiraAlign.

Note: Any spaces in the name will cause issues with the Login URL later so it's best to just avoid them.

 

6. Under the Getting Started section, click on 1. Assign users and groups.

6.png

7. Click Add user and add Users and/or Groups as needed. You need at least one User to test SSO and you can go back and add more later if you want.

 

8. On the Add Assignment screen, you can select the users you want, click Select and Assign.

 

9. The user(s)/group(s) should show up on the Users and groups pane now.

9.png

10. Click on Single sign-on and SAML.

AzureAD_Step10.png

11. In Section 1: Basic SAML Configuration, edit the Identifier (Entity ID) and  Reply URL (Assertion Consumer Service URL) to both be the Jira Align instance:

https://instance.agilecraft.com or https://instance.jiraalign.com 

Click Save.

Alternatively, you can upload the metadata file by copying the Show Jira Align Saml 2.0 Service Provider metadata from Jira Align (Administrator > Platform > Security) and save as an XML file. 

12. In Section 3: SAML Signing Certificate, edit and change the Signing Option to Sign SAML response and assertion. Click Save.

12.png

13. Also, in Section 3: SAML Signing Certificate, click Download next to Federation Metadata XML to use in a later step.

14. In Section 4: Set up <name>, copy the Logout URL and save it for use in a later step. Logout URL will look something like this: https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0

15. In the left hand menu under Manage, click Properties and copy the User Access URL for use in a later step. User Access URL will start with https://myapps.microsoft.com/signin. 

15.png

 

Jira Align

16. Sign into Jira Align and click Administration > Platform > Security.

16.png

17. Click Add SAML Provider. 

17.png

18. Paste in the SAML 2.0 Metadata from Azure (Step 13 from earlier).

19. Click Save & Close.

20. Set Enable SSO to Yes.

21. Click Save Settings.

 

Testing

22. Open up an incognito window in your browser and navigate to the User Access URL from Azure (Step 15 from earlier).

 

Additional Notes

  • The user account you are testing from Azure SAML 2.0 must be also configured on the Jira Align side.
  • User accounts on the Jira Align side can be created using the following methods:
    • API 1.0
    • Excel Import
    • Manually created
    • Users automatically integrated from Jira (the user must be assigned to an integrated issue)

Disable Manual Sign In

AzureAD_Step23.png

  • Once you are confident that there are no known issues with SSO, you can go back to Platform Settings from earlier and set Disable Manual Sign In to Yes. 

You'll need to open a ticket with Jira Align to regain access if you get locked out while Disable Manual Sign In is turned on. 

  • After you have set Disable Manual Sign In, you'll be able to fill out the following fields:
    • Sign In URL (use the URL from step 15)
    • Sign Out URL (use the URL from step 14)

If for some reason your Sign In or Sign Out URL contain encoded characters (Example: %20 for space), you'll need to replace that with the non-encoded equivalent.

8 comments

Tim Keyes Atlassian Team Aug 06, 2020

Awesome article @James McCulley!

Great work!

Like James McCulley likes this

Hi, why have the image stores gone to imgur? Enterprise customers are going to have a problem going forward with community.atlassian.com if this is preferred image as enterprises (like mine) block imgur. Many thx

Tim Keyes Atlassian Team Aug 09, 2020

Hi Karalee,

Do you know of any image hosting sites that your network does not block?  

Thank you!
Tim

Hi Tim, I emailed you directly to chat further. 

Karalee,

I have made a change to where the images are hosted.  Can you confirm you can see them now?

Thanks!

James

I can @James McCulley, thanks! Are the other being pages updated as well or will they be updated on an ad-hoc basis? e.g. https://community.atlassian.com/t5/Jira-Align-articles/Domain-Migration-agilecraft-com-to-jiraalign-com-Impacts-on/ba-p/1451258 still has imgur. I can @ mention you/Tim if/when I find another?

Like # people like this
Tim Keyes Atlassian Team Aug 10, 2020

Hi Karalee,

I probably have about 12 articles with images hosted in Imigur.  I will move them over to hosting on the community's site over the next week or two.

Cheers!
Tim

Like # people like this

Hi @James McCulley a quick note to let you know that this article was so helpful for us today! Your note about the User Access URL was spot on - it didn't work so I piped up with your tip about no spaces when setting up... and it fixed it

Like James McCulley likes this

Comment

Log in or Sign up to comment
TAGS
Community showcase
Published in Jira Align

Lean Portfolio Management with Jira Align

Lean Portfolio Management (LPM) is a relatively newer management methodology which draws from lean and systems thinking approaches to drive value-based outcomes, as opposed to more traditional techni...

240 views 0 22
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you