At the moment when my user base go to my Jira URL they have to select the login button top right to kick off my SAML 2.0 ... But what i really would like is for the users to go to the URL and SSO kicks off automatically ... I know you can set it as Primary Authentication but then that impacts local admin login ...
So is there a way to "protect" the login path to kick off SSO automatically ?
Since this is for Server - everything depends on what app you are using to do SAML SSO
Some of the apps have the feature you are after and some don't, and they can be implemented differently.
Our EasySSO for Jira for example allows a) SAML everywhere but the login/logout pages i.e. if you click logout or navigate directly to the login page - you can login with the local login b) forced SAML everywhere including login/logout, but support for a special parameter to stop it c) forced SAML everywhere, parameter disabled, but ability to disable SAML if needed via special protected "management" endpoint.
Also if you integrate EasySSO with the SecureLogin 2FA app from Syracom you can apply 2FA only to the local logins, leaving those coming via SAML alone (i.e. the assumption is that the IdP has already done 2FA if required).
i still can not logon
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Ninja,
it sounds a bit like you use the original Data-Center in SAML - then this article should help you to have a good workaround for your Admins: https://confluence.atlassian.com/jirakb/bypass-saml-authentication-for-jira-data-center-869009810.html
Alternatively should you use our App: https://marketplace.atlassian.com/apps/1212130/saml-single-sign-on-sso-jira-saml-sso?hosting=datacenter&tab=overview
Then here is an article how to achieve the same - with our plugin. I.e. giving admins a special URL to login: https://wiki.resolution.de/doc/saml-sso/latest/jira/knowledgebase-articles/technical/cannot-access-jira-confluence-bitbucket-bamboo-fisheye-crucible-anymore-bypass-sso
If the Bypass URL is not the Solution you like, then our plugin gives you many options to do "IdP Selection", which includes dealing with local users. Here you find a Video where I Demo the different possibilities: https://youtu.be/DoNir7eN87o
Cheers,
Chris
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.