SSO MS AD & Crowd

Deleted user January 12, 2014

Is it possible to have transparent SSO for Atlassian Tools Jira, Confluence, Crucible and Stash using Microsoft Active Directory for authentication and Crowd out of the box configured without any

additional third party plugin or software? Means: Log on to your workstation/PC and do not see any additional login screens accessing the Atlassian tools if not explicitly wanted.

6 answers

1 accepted

0 votes
Answer accepted
Caspar Krieger
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
January 13, 2014

Crowd will provide you with SSO such that once you've entered in your login details (username and password) into one of the Atlassian applications (JIRA, Stash, Fisheye/Crucible, Confluence, or Crowd), then you will be automatically logged into other Atlassian applications.

Currently, Crowd does not provide functionality like "once you've logged onto your desktop, you're automatically logged into all Atlassian applications".

Sujit Kumar January 21, 2016

@Caspar Krieger : Is the functionality "once you've logged onto your desktop, you're automatically logged into all Atlassian applications"  now available with Crowd ? . So is it on the roadmap in the future release of Crowd ? using the MS AD integrated with Crowd...

Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
January 21, 2016

@sujit kumar, it is not available in Crowd out of the box, you will need the IWAAC plugin for this:

https://marketplace.atlassian.com/plugins/com.cleito.iwaac/server/overview

Like Sujit Kumar likes this
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
January 21, 2016

@sujit kumar It is not available out of the box - as per Bruno's comment you will need an add-on. Some, like IWAAC will still talk to Crowd on the authentication step, while there are other SSO plugins that do "true" SSO only talking to your Domain Controller at this stage.

If your application is configured to do something special in the context of authorization, group management etc. Crowd may still be used there, but for the purpose of SSO authentication becomes irrelevant. If SSO fails/not possible in the first place - the regular Crowd-backed login process will occur.

There is our marketplace reincarnation of NTLM Authenticator - EasySSO for all apps, that now also supports Kerberos, or others including IWAAC, there also vendors/experts who don't list theirs on marketplace, it is also possibly to "roll your own" with front-end webserver or I think CAS.

In other words extra costs any way.

Like Sujit Kumar likes this
Caspar Krieger
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
February 8, 2016

My statement from 2 years ago is still correct. Please look into third party solutions if you need this functionality. (Apologies for the delay in replying; I was on leave.)

1 vote
Mateusz Miara
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
March 14, 2019

Hello ,

Crowd 3.4 has just came out and it comes with a functionality that might be of help to you - Crowd SSO 2.0 - Crowd’s single point of access for Jira, Jira Service Desk, Bitbucket, and Confluence across different domains with one common login page. For more information, see our documentation

Hope this helps,

Mateusz

1 vote
Ed Letifov _TechTime - New Zealand_
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
January 13, 2014

This is not possible. 3rd party plugins is what you will need.

Our NTLM Authenticators for Jira and Confluence support the latest versions of both applications.

TechTime Initiative Group, an Atlassian Expert in New Zealand has been providing a solution to do NTLM authentication (a.k.a auto-login or SSO in Windows environment) with Confluence and Jira for over 6 years.

We have over 60 customers successfully using this solution in New Zealand, Australia, Switzerland, Finland, Norway, Sweeden, France, Germany, Netherlands, Slovenia, Czech Republic, Turkey, Russia, Latvia, the UK and the USA both in NTLMv2 and NTLMv1 environments with and without Crowd in the backend.

The NTLM Authenticator is delivered as a jar file and instructions how to deploy it to Atlassian Jira and/or Confluence to work in conjunction with IOPlex Jespa to perform NLTM authentication in Windows environment.

The cost is one-off NZ$150 (plus fees for Jespa license payable to IOPlex). We do sell bundles that include IOPlex Jespa license.

If you need it, the trial version is available from our TurningRight website.

We are currently working on moving it to Marketplace (Jan/Feb 2014) and as byproduct eventually making it support the rest of Atlassian tools (planned for 2nd quarter of 2014)

0 votes
Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
November 22, 2015

Hi Harald,

You might want to have a look at the Integrated Windows Authentication for Apps using Crowd (IWAAC) plugin: https://marketplace.atlassian.com/plugins/com.cleito.iwaac/server/overview

IWAAC provides your Windows domain users with automatic logon on any application using Atlassian Crowd as its user management system, including Jira, Confluence, Bitbucket Server (previously known as Stash), Bamboo, FishEye, Crucible, Jenkins and G Suite (formerly Google Apps).

IWAAC is a generic plugin that works on all applications that are compatible with Crowd. Once you have purchased a proper license, you can deploy the plugin on as many applications (Confluence, Jira, Bamboo etc.) and server instances as you want since an IWAAC license is an Enterprise license that is valid for your entire organisation.

You can download IWAAC and test it for free at: https://www.cleito.com/products/iwaac/

Regards,

Bruno

0 votes
Deleted user January 13, 2014

Conclusion on these answers for me is:

Why paying that money for Crowd if we have a directory server that does the authentication and can do real SSO using a cheaper Third Party Plugin? Just for having additional Administration Level outside the directory server?

We'll have to think of dropping Crowd!

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
January 12, 2014

I've got close to that on one site. We weren't using MS AD, just LDAP hooked into Crowd. We got SSO for Jira, Confluence and Fisheye/Crucible working with that fine. Stash wasn't around at the time, but I suspect it's just as easy as the others. So I'd give you a tentative "yes" because if you can do this with LDAP and Crowd, you should be able to get there with MS AD as well.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events