Good morning folks!
At my company we would like to configure the G Suite to sync our users automatically.
At the same time, we would like to set up Single Sign-On (SSO) via SAML for the Atlassian Cloud Application.
Here the documentation on Google that I found:
https://support.google.com/a/answer/7553615?hl=en&ref_topic=6304947
Will the SAML integration also sync the Google users onto the JIRA platform?
Are those two features compatible? Which approach is the most appropriate for us?
Thanks in advance!
Kevin
Hi @Kevin Delord,
Unfortunately it's not possible to combine G Suite provisioning with SAML SSO. If you configure G Suite syncing, your users will also need to sign in with their Google account. To achieve both user syncing and SSO, there are two options:
1. Configure SAML SSO and use SCIM to sync users from your identity provider. We currently support user syncing for Okta – Azure AD and Onelogin are coming soon.
2. The G Suite integration supports both SSO and user syncing, so as mentioned above, if you are syncing users from G Suite, they will also be redirected to log in with their Google account to Atlassian Cloud.
Hope this helps!
Dave
Hi @Dave Meyer,
Thank you for your quick reply.
Your answer cleared out the confusion, the integration of SAML SSO and the G Suite syncing are not compatible.
Do I still understand correctly that SAML SSO is possible with Google as Identity Provider when using Atlassian Access and configure an "unsupported identity provider" ?
It also appears that SSO + G Suite sync makes everything easier and faster, but what kind of SSO is it? My guess is OAuth and not SAML, could you confirm ?
Thanks!!
Kevin
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Kevin Delord,
Do I still understand correctly that SAML SSO is possible with Google as Identity Provider when using Atlassian Access and configure an "unsupported identity provider" ?
Yes I believe this should be possible.
It also appears that SSO + G Suite sync makes everything easier and faster, but what kind of SSO is it? My guess is OAuth and not SAML, could you confirm ?
This uses Google's OpenID Connect endpoint.
Cheers,
Dave
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.