SSO: first login and group membership

I have an issue with the user login and group membership and just wanted to post it to see if anyone came across it before.

- I configured our users to be synchronised with ActiveDirectory (in test and production), that works very well.

- With SSO off (that usual Jira login) the users log in with their PC login details and at the first login get added to the group staff-users by default (that group is basically jira-users, you need to be member to use jira).

- If I switch SSO on and let a new user (never logged into Jira before) access it they get logged in, but can’t do anything else because they are not member of any group. From the user management page I can see that the login (with SSO) was not recorded and no group was assigned.

-

- Tried the same on the testsytem (no SSO) and it works fine, the user login is recorded and the group automatically assigned.

I’m thinking that SSO bypasses some of Jira’s usual login procedures and that causes problems? Or maybe I’m missing something here.

2 answers

1 accepted

Stefan -

I discussed this internally with AppFusions engineering, and our Kerberos SSO integration does not add users to local groups during first login. We recommend you use LDAP groups instead of local groups if using our SSO.

Our customers of our SSO solution to date are all using LDAP (or AD) groups - so this has not come up before.

We can help you evolve your user directories in this way if needed - or we could add this feature as an enhancement request as well.

Please contact us at info@appfusions.com if you would like to evolve your SSO implementation.

Best,

Ellen

Hi Ellen,

Thank you very much for your answer. We will switch to AD groups now, a requirement that was overdue anyway.

Regards,

Stefan

Are you referring to using SSO via Crowd or your tag indicates possibly Kerberos? Depending on the SSO solution, the help will be different

We are using the AppFusions SSO solution with Kerberos (ActiveDirectory), I can give more detail if you require.

FYI... AppFusions main support is now via info@appfusions.com. Both sales and support, honestly. It is the AppFusions front door.

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Nov 29, 2018 in Marketplace Apps

How to set up an incident workflow from the VP of Engineering at Sentry

Hey Atlassian community, I help lead engineering at Sentry, an open-source error-tracking and monitoring tool that integrates with Jira. We started using Jira Software Cloud internally last year, a...

1,373 views 0 8
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you