I think I may have gotten the cart before the horse (proverbially speaking). My goal is to sync to EntraID with JIT and SSO. I setup a sync from Atlassian JSM to Azure EntraID, Then I setup SSO and enabled JIT. Maybe I don't need both? This is for my end users/ requestors to submit tickets without requiring a license or to login (portal only users). Should I break down the Azure EntraID sync and start again? When I test users, they get the sign in screen for Atlassian instead of SSO through. Any help is appreciated.
Hi @Kevin O_Brien ,
Welcome to Atlassian community.
I'm not sure to understand what you need to do.
The portal-only customers don't require a JSM license for submitting request.
If your customers are external, the license for Atlassian guard is not applied, as indicated here https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-sign-on-for-portal-only-customers/
For customers that are internal, probably it is required a license of Atlassian guard, if so policy is required.
I suggest to try to follow this procedure in order to configure SSL and provisioning with Entra ID: https://learn.microsoft.com/en-us/entra/identity/saas-apps/atlassian-cloud-tutorial
Kind regards
Sorry it it's not clear. Let me try to explain. what i want to achieve is portal only customers for all my end users, with SSO and JIT. What I DID was sync my users to EntraID, THEN i setup SSO and JIT. I believe I didn't need to sync the users and i should just get rid of that and allow the users to be created with JIT as they access my JSM.
Does that sound right?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Understood your point; I'm not sure, but I think JIT as you expect doesn't work in Atlassian Guard.
There is a thread about this: https://community.atlassian.com/forums/Questions/JIT-Provisioning/qaq-p/2780526
Regards
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for the reply.
I only configured Atlassian Guard because it would not let me configure SSO without it. I was prompted to configure Guard with something along the lines of "must use Atlassian Guard to configure SSO". (not those exat words). If I don't need Guard, that's fine with me. I simply want users to be able to submit tickets as portal users without a license and I don't want them to have to manage separate Atlassian accounts with passwords.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.