Hi
We use both Confluence and JIRA and have connected them to our AD for authentication and user management purposes. We are not using Crowd, nor do we plan to or want to use the service.
We have configured the LDAP for both Confluence and JIRA, and have been able to successfully import users. But what we have found over time is that when users leave, their accounts are disabled in AD and are flagged as such, but do not get marked as disabled in the Atlassian apps.
Is this not supported without Crowd? Surely the LDAP must be able to recognise and sync when an account is marked as inactive. If this continues it will begin to impact our licence count.
Please note we have disabled incremental synchronisation (although have tested with this on, too), and are using the LDAP as read-only with local groups.
Hi,
what is the setting of "Manage user status locally" in the Advanced Setting section of the LDAP/AD configuration? Also check "Filter our expired users".
Anyway, removing users from the confluence-users, jira-core, jira-software, jira-servicedesk groups also frees the license use, if you use the standard settings.
Best
JP
Hi JP
Thanks for responding.
I have it set to Read Only, with Local Groups.
Filter Out Expired Users was unticked, but I have ticked it and restested and find the same.
When setting up the LDAP, we encountered problems with using the default confluence-users/jira-users groups (ie there was no way to add this to people who had prior been added to that group via Crowd), so have proxy AD groups that perform that functionality.
Best wishes
Adam
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.