Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Enforce MFA and Password complexity for Customers

Matthew Crocco May 18, 2020

I am setting up an internal JSD and looking to have Jira Access for SSO and enforce MFA for the agents. Is there a way to make the same requirements for our customers as well?

It seems the current setting the customer can use anything for a password.

Thanks

1 answer

1 accepted

0 votes
Answer accepted
Angélica Luz
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
May 19, 2020

Hello Matthew,

Thank you for reaching out to Atlassian Community!

When using Atlassian access, currently, SSO, password policy, and 2FA are only applicable to internal users and not customers.

Customers use a different URL to login and also their accounts are local, it's not an Atlassian account, that's why it's not possible to use Atlassian access for their accounts.

There are some feature requests suggesting the implementation of such ability:

Please, click on vote and watch to receive updates about the features.

Regards,
Angélica

Matthew Crocco May 21, 2020

Thanks Angelica,

Does this apply as well if I have a verified domain and the customers email addresses are claimed and managed?

Thank you

Angélica Luz
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
May 22, 2020

That's actually a workaround, Matthew.

You can migrate the customers to Atlassian account, so you can manage their accounts. 

When migrating their accounts, they will be listed as internal users, and for them to use only the portal, you need to make sure that they are not added to any default groups.

Before migrating, go to Cog Icon > User management > Product access and disable all the products, so new users won't receive a license, therefore, customers migrated won't be part of any groups.

Screen Shot 2020-05-22 at 10.30.08.png

Once their accounts are managed, they will log in using the same URL as any other user (xxxxxxx.atlassian.net) and not the portal, but since they won't be part of any default groups, they will be redirected to the customer portal.

Like Matthew Crocco likes this

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
TAGS
AUG Leaders

Atlassian Community Events