Hi all,
Having some issues with email requests related to Single Sign On (SSO) which I am hopeful the community can assist with.
In our case, the domain which Identity Manager uses for SSO is different than the SMTP domain used for our email addresses. When a valid user sends an email request to the Jira Service Desk support email address, Jira will not associate the sender’s email address with a Jira user account because the addresses will differ, and the email will not be processed.
Context:
User account on AD:
Using SSO, the user account created on Jira Service Desk:
Problems:
Please does anyone have any suggestions on how to fix? This is a very common situation in enterprise networks where email addresses are different than user principal names on Active Directory. There must be a simple solution I am missing?
Thanks,
Marc
Hey Marc,
It sounds like the User Identifier value is mapped to user.userprincipalname rather than user.mail in your IdP.
If you're using Azure AD, the SAML User Identifier is defaulted to the User Principal Name and should be changed to the Email Address (user.mail). If this is the case, take a look at Step 6 in Microsoft's KB, Tutorial: Azure Active Directory integration with Atlassian Cloud, how to change this.
-shawn
Thanks, Shawn. Appreciate the followup.
Unfortunately, it may not be that straight forward since SAML is used for other web services. Making the change on the Azure side for Atlassian will disrupt other configurations or otherwise require they also be changed.
Thanks again for your help!
Marc
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.