Is it possible to enforce 2FA for external accounts not managed by our domain who are also agents in JSM?
e.g. Our domain www.nicolas.com can manage accounts with @Nicolas.com but we also have external agents with davids.com and monicas.com that are not managed but we need to enforce 2FA.
How could this be done?
thanks!
You'll need to have Atlassian Guard subscription for this, and then configure additional Identity Providers for each domain (if they aren't in your identity provider). You'll want to keep them as "Claim Manually" rather than auto-sync.
You'll need to work with the IT team of those companies to have this work.
Then assign them to a default access policy that requires 2FA or SSO.
https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-sign-on/
You do not want to enable SCIM as that will create all accounts from those domains.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.