Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

JIT User provisioning AzureAD

Peter G
Contributor
February 12, 2021

Hello,

today I configured successfully SSO 2.0 on our Jira Server based on SAML with AzureAD.

Users that are still existing can login via AzureAD, works like a charm.

What is not working is that I have a guest account in AzureAD which I´d also like to give access to Jira. 

The guest account does not exist in Jira so far and also not on the remote directory (but of course in the IdP).

I added the guest account in AAD to the Enterprise Application which i configured like the existing users (only difference that existing users are added through a security group).

When i now try to login with the guest account I get the error message "You currently can´t login, Please contact your administrator"

In the Jira log I see following entry:

Received SSO request for user guest_mail.com#EXT#@company.onmicrosoft.com, but the user is not permitted to log in

 

Didn´t found this error message at all while googling for it.

 

Anyone have an idea what could be the problem? 

1 answer

1 accepted

1 vote
Answer accepted
Peter G
Contributor
February 15, 2021

Found the issue:

I had to enable access for the group of the user which it was member of.

Pramodh M
Community Champion
February 15, 2021

In Atlassian Acess or Azure?

Peter G
Contributor
February 15, 2021

In Jira I had to add "Application Access" to the group which is synced from AAD.

Like Pramodh M likes this

Suggest an answer

Log in or Sign up to answer