Hi,
We are looking for a 2FA solution for Jira, Confluence, BitBucket and Bamboo.
All the addons we've trialed so far work, *but* you have to go through 2FA each time you switch between applications.
Is there a 2FA plug in that will allow users to go through the 2FA check once and then switch between aplkications without having to 2FA a second time?
Hope that makes sense.
Tim
Hi @Tim Finch
As all the application have their own session management you need to verify your credential including 2FA every time when you switch between the applications(in case if you are not logged in to that application)
The best way to achieve your use case will be connecting all the applications to Identity Provider(IDP) Application for Single Sign-on and enable IDP's 2FA on the top of SSO.
You can use SAML plugin for JIRA, Confluence, Bitbucket, and Bamboo to enable SAML SSO into these applications from your IDP and in case if you don't have any IDP, you can take a look into the miniOrange IDP. It supports several 2FA methods like OTP over Email and SMS, Google Authenticator, Push Notification, Hardware tokens, etc.
In this case, If a user is logged in to one of application (for e.g. JIRA ) via SSO and if he switches between application, he doesn't need to reauthenticate himself, he will be logged in directly.
Thanks,
Lokesh
P.S. I work for the miniOrange and if you need any help with the setup, you can contact us at atlassiansupport@miniorange.com or through our customer portal.
A few days ago we released a new security app to Atlassian Marketplace called Polar SSO.
In addition to SAML and Kerberos, you get to define policies that encourages or enforces users to add a second factor based on users network location, group membership, login method (password, saml, kerberos) etc.
A benefit from adding extra verification is that you can log in directly without password using Windows Hello, MacOS Touch ID, Apple watch, Android fingerprint, USB security keys with PIN or fingerprint. In addition you can use the same device to re-verify your identity on WebSudo protected pages (which can be a pain to do every 10 minutes).
You may also further protect your application by defining policies that denies regular password login, while allowing SAML login from untrusted sones.
Disclaimer, I work for Polarnight, the vendor behind this app.
-Lars
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
it is possible to solve this using the Crowd server?
I mean, for our company we are using the crowd server SSO and we need at the same time use to 2FA.
Actually, we're using Secure Login for JIRA and Confluence but when switch application we must enter PIN separately like @Tim Finch mentions above.
Thanks for any solutions
Regards
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
There are no add-ons like that on Atlassian Marketplace.
Your only option is to delegate this check to an external party, usually a SAML IdP via SAML SSO app/add-on like our EasySSO or any other SAML app - from re:solution, Kantega or others...
I have to point out that from security point of view there is nothing bad about having to do 2FA the second time. You should also configure your 2FA to not challenge internal users, or in the case of EasySSO, you can integrate SecureLogin 2FA so when users are coming in via SSO (from the office via NTLM or Kerberos with no credentials being asked, or from outside via SAML IdP that may have already done the 2FA) - there is no local 2FA.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi,
what addons did you try? Did you get a solution for both: 2FA & SSO?
Best
JP
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.