I am integrating Jira with Okta for SAML SSO. I am currently syncing the users from Okta into Jira and SAML is working great from that standpoint. However, I would like to implement JIT user provisiong. I have followed the documentation on both sides and nothing working. Are there any gotchas anyone is aware of?
Hi Matthew.
JIT provisioning should be quite straight forward. Are no user records created at all? Or are user records created but the SAML authentication fails?
The configuration and feature completeness of JIT depends on the SSO app you are using.
Full disclosure: I work for Kantega SSO, one of the top SSO app vendors. In our app K-SSO SAML Kerberos OAuth for Jira, you setup JIT to both create and update user records as users authenticate with SSO (SAML or OpenID Connect). The only requirement needed is a writable user directory. Most commonly, JIT is used together with the standard Jira internal directory.
Regards,
Jon Espen
Kantega SSO
SAML works perfectly if there is an existing user in Jira that matches the NameID value in the SAML assertion. If not, it says user does not exist - Jira doesn't seem to be creating the user. I'm using Okta for SSO
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Are you using the "Okta Jira Authenticator" app to integrate Jira and Okta? I am not an expert on this app, but I cannot find any documentation regarding JIT support this their guide: https://saml-doc.okta.com/Provisioning_Docs/Okta_Jira_Authenticator_Configuration_Guide.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
 
 
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.