Hello,
A customer wants to test Confluence server in Azure... I have found the Microsoft tutorial to enable Azure AD SSO but don't understand how to map Azure AD groups to confluence groups. Can I add a Directory from the users administration page or Should I use Crowd ?
Can someone help me or redirect me to the relevant documentation ?
Regards,
Fred
You can setup AzureAD to send group memberships as parts of the SAML response messages. It is a bit work to get AzureAD to send readable group names but we have created a document describing how to achieve this: https://docs.kantega.no/display/KantegaSSOEnterprise/Managed+and+Default+groups
With managed SAML groups, users are assigned and removed to groups based on the group settings at the identity provider (in your case AzureAD).
Another alternative to get permission updates each time the user logs in is to setup synchronized user directories. With this approach you set up a background job which continuously keeps Confluence up to date on users and group permissions from AzureAD. You can read more about this alternative here: https://kantega-sso.com/provisioning/
Full disclosure: I work for Kantega SSO, and our apps support both managed groups and synchronized AzureAD directories. Our support team is available if you want a demo or have any questions.
Regards,
Jon Espen
Kantega SSO
Hi @Frédéric Grégoire ,
There multiple SSO plugins available for Confluence on the Atlassian Marketplace which allows you to enable SSO into Confluence from Azure AD.
Here is one of the plugins that work on SAML2.0 Protocol.
This plugin also has a feature you are looking for i.e. Group Mapping which allows you to map the Azure AD's group to Confluence local groups, and groups of the users in Confluence will be updated on each SSO(login) based on the group information received in the SAML Response from Azure AD.
Docs to setup SSO: https://plugins.miniorange.com/saml-single-sign-sso-confluence-using-azure-ad-idp
Feel free to reach out to support team through the customer portal in case if you need any assistance to set up the plugin for your use case.
Thanks,
Lokesh
I work for the miniOrange. One of the top SSO vendor in the Atlassian Marketplace,
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
HI Lokesh,
Thank you for the information, I will have a look at miniOrange.
Regards,
Fred
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Frédéric Grégoire ,
Great. Feel free to drop an email at atlassiansupport@xecurify.com or reach out through our customer portal in case if you need any assistance with the plugin setup for your use case(group mapping).
Thanks,
Lokesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
confluence server doesn't really support SSO with Azure unless you are using data center version. Also, crowd doesn't help with SSO redirect. You need SAML plugin for Confluence which should solve your use case.
We use this plugin https://marketplace.atlassian.com/apps/1212129/saml-single-sign-on-sso-confluence?hosting=server&tab=overview
which works great!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Jira Guy,
We already have experience with SAML plugin which indeed works fine.
My issue is more about how to proceed with group mapping.
Thank you for your reply
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Did you try their user sync option? They have Azure AD connector and in the advanced section they have the option to configure groups. Check it out
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.