Merging AD users with JIRA users and local groups

nick.rozhdestvensky February 12, 2018

We are currently using JIRA Internal Directory authentication. We plan to move to Microsoft AD authentication with local groups.

I have a local user called "test.ad" in local groups "jira-users" and "test-users", and an AD user with the same login name (i.e. "test.ad").

I configured a new AD user directory with LDAP permissions "Read Only, with Local Groups" and default group membership "jira-users".

After moving to AD auth I got "test.ad" user in group "jira-users" only.

 

Where is my local group "test-users"?  i don't need to rewrite local group membership.

 

Thanks.

1 answer

0 votes
Thomas Deiler
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
February 12, 2018

Dear @nick.rozhdestvensky,

if AD is the first user directory, user directories afterwards get ignored if they keep the same username.

This is the natural overlay effect. Your internal is not gone. If you move Jiras internal DB on top position, the AD account get's hidden.

So long

Thomas

nick.rozhdestvensky February 12, 2018

I expected the result like in Confluence - local groups are merged with AD. Is it possible in JIRA?

Thomas Deiler
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
February 12, 2018

Not that I know. And be aware - even if the usernames are equal, for Jira they are different (internal ID). Otherwise, this would be a security breach.

nick.rozhdestvensky February 12, 2018

 Thanks for this note.

Suggest an answer

Log in or Sign up to answer