SSO: first login and group membership

I have an issue with the user login and group membership and just wanted to post it to see if anyone came across it before.

- I configured our users to be synchronised with ActiveDirectory (in test and production), that works very well.

- With SSO off (that usual Jira login) the users log in with their PC login details and at the first login get added to the group staff-users by default (that group is basically jira-users, you need to be member to use jira).

- If I switch SSO on and let a new user (never logged into Jira before) access it they get logged in, but can’t do anything else because they are not member of any group. From the user management page I can see that the login (with SSO) was not recorded and no group was assigned.

-

- Tried the same on the testsytem (no SSO) and it works fine, the user login is recorded and the group automatically assigned.

I’m thinking that SSO bypasses some of Jira’s usual login procedures and that causes problems? Or maybe I’m missing something here.

2 answers

1 accepted

This widget could not be displayed.

Stefan -

I discussed this internally with AppFusions engineering, and our Kerberos SSO integration does not add users to local groups during first login. We recommend you use LDAP groups instead of local groups if using our SSO.

Our customers of our SSO solution to date are all using LDAP (or AD) groups - so this has not come up before.

We can help you evolve your user directories in this way if needed - or we could add this feature as an enhancement request as well.

Please contact us at info@appfusions.com if you would like to evolve your SSO implementation.

Best,

Ellen

Hi Ellen,

Thank you very much for your answer. We will switch to AD groups now, a requirement that was overdue anyway.

Regards,

Stefan

This widget could not be displayed.

Are you referring to using SSO via Crowd or your tag indicates possibly Kerberos? Depending on the SSO solution, the help will be different

We are using the AppFusions SSO solution with Kerberos (ActiveDirectory), I can give more detail if you require.

FYI... AppFusions main support is now via info@appfusions.com. Both sales and support, honestly. It is the AppFusions front door.

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Aug 22, 2018 in Marketplace Apps

How a Marketplace app tech team is achieving gender diversity

Hello! My name is Genevieve Blanch, and I'm the Marketing Manager at RefinedWiki, creators of apps to give teams the tools to customize Atlassian platforms. Currently, 44% of the tech team at Re...

516 views 3 18
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you