Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

AAD SSO and Guest Users

Peter Bance December 31, 2020

I have a peculiar issue with Jira Cloud + Atlassian Access. We use SSO (to Azure AD) with automated provisioning for regular users, which works fine. Now, though, we are trying to add a few external partners to our Jira instance. They have Guest accounts in AAD, the provisioning works fine (AAD reports users are successfully created with the correct attributes), but they are not appearing in the "Users" list in Jira, and are unable to log in via our SSO.

I'm sure I'm missing something in the configuration, I just can't work out what/where!

Any pointers on where I should look? Is it more likely to be in Atlassian Access config, or Jira Core/Software?

Follow-up: could it be because I can't add the external partners email domain to "Verified Domains"? I really, really don't want to go creating accounts in our domain for these partners.

3 answers

1 accepted

0 votes
Answer accepted
Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 31, 2020

Hi Peter,

I remember there has been a discussion around that topic lately which was referred to as a Suggestion in https://jira.atlassian.com/browse/ACCESS-648

Could you please kindly check if this corresponds to your scenario also?
The former request was slightly diverge, but only for some details.

If this matches the current status was that this Suggestion is ongoing and it should not take so long until this is implemented.

Regards,
Daniel

Peter Bance December 31, 2020

Thank you - that's exactly it. I will go comment on the Issue (didn't think to search there).

Daniel Ebers
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 31, 2020

No worries! Here are so many information stored -- which is pretty good -- but sometimes it is hard to find all of them quickly.

Glad this helped!

0 votes
Wim Abts
Contributor
February 23, 2022

@Christopher Mahoski 

Hi Christopher, 
Did you get this to work? We have the same requirement and are preparing for Cloud migration.

Christopher Mahoski February 23, 2022

No, unfortunately, we've had to stay on-prem for now as well as use other products.  Atlassian is tracking improvements for Q2-Q3 of this year as referenced in this issue.

[ACCESS-102] Enforce security policies for users not on verified domains - Create and track feature requests for Atlassian products.

Like Wim Abts likes this
Wim Abts
Contributor
June 3, 2022

Hi,
But that's only in regard to setting security policies, I don't think that single sign-on will be included in that (only stuff like password strength and 2FA).
We have guest accounts in Azure AD which log on to SharePoint Online, they will have a different password in Atlassian if there's no SSO....

0 votes
Christopher Mahoski August 4, 2021

Peter, did you ever find a way to have your unmanaged guests login via SSO with AAD?  We're up against the same situation and provisioning isn't the problem.

Peter Bance August 4, 2021

Yes, it's all working since an Atlassian update a while back. I had to tweak the SAML attributes in the Azure AD enterprise app, as the defaults use UPN as UID (which can be "peculiar" for Guest accounts):

image.png

Like Steve Guyer likes this
Christopher Mahoski August 5, 2021

Thanks for the quick reply Peter!  We tried provisioning a Guest (different domain than our verified domain) into our Atlassian cloud directory and it imports as a user of the products, but never shows in our directory of managed accounts.  We still seem to not have the ability to scope an authentication policy to anything other than managed accounts, so the guest logging in with an email address and domain different than our verified managed domain still doesn't work.  Are we missing something by chance?

Peter Bance August 6, 2021

Hmm, not a problem I've come across, I'm afraid - I have a single default Authentication Policy set up (applies to "All Users"), with "Enforce SSO" set, as we don't need to support non-SSO users, so it may be I'd have a similar problem if I had to support that. Sadly, it sounds like this needs to be an Atlassian support ticket 😒

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events