Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

new users not added to jira-users default group after SAML

Vishal Suri February 8, 2022

Hi,

After we have enabled SAML integration with Jira Software, users are not added to jira-users default group and we need to add those new users to jira-users group so they can view project/ticket they have access to.

 

Any help would be really appreciated. 

 

 

2 answers

0 votes
Lokesh Naktode_miniOrange
Atlassian Partner
February 8, 2022

Hi @Vishal Suri,

It seems you are using JIRA Server not Datacenter which does not have a native SAML feature so I am assuming you are using any SSO plugin from Atlassian Marketplace.

If yes, I suggest you check the configuration and supported features with the developers of that plugin or you can try out the miniOrange SAML which has dedicated options to assign IDP groups as well as default groups to all SSO users(existing and new). 

But if you are using the DC version and built-in SAML then check out the link shared by Pramodh.

Thanks,

Lokesh

PS: I work for miniOrange, one of the top SSO vendors on Atlassian Marketplace. You can reach out to miniOrange at atlassiansupport@xecurify.com

Vishal Suri February 9, 2022

Hi Lokesh,

Thanks for your response. Yes, we are using Jira Server and SSO plugin to enable SAML authentication. Same configuration of SAML works with confluence. Likewise new users get auto added to confluence-users group automatically. But this is not the case with Jira.

If new user logins to jira with his/her username and password instead of SAML, then he/she is added to jira-users group auto.

 

Are there any logs for SAML / SSO to debug this type of issue ?

Lokesh Naktode_miniOrange
Atlassian Partner
February 9, 2022

Hi Vishal,

Can you please let me know which SSO plugin are you using? 

Thanks,

Lokesh

Vishal Suri February 9, 2022
Lokesh Naktode_miniOrange
Atlassian Partner
February 9, 2022

Hi Vishal,

I am not sure if this plugin has a configurable option to select default groups for New Users created through SSO but I think has support for Just in time provisioning where you can send groups (including default groups of JIRA) from IDP in the SAML Response and it will be assigned to SSO users at the time of login.

I think it also has a capacity to assign groups configured in AD/LDAP Configuration, in case, your users are synced from an external user directory.

https://confluence.atlassian.com/adminjiraserver/saml-sso-for-jira-data-center-applications-938847031.html

I suggest you contact Atlassian Support directly for further assistance.

Thanks,

Lokesh

0 votes
Pramodh M
Community Champion
February 8, 2022

Hi @Vishal Suri 

Your SAML Configuration defines the new user's default group 

Check with your SAML Configuration, if there is an option to add the group when a user is added, the user is also added to the group

https://confluence.atlassian.com/adminjiraserver/saml-sso-for-jira-data-center-applications-938847031.html

Thanks,
Pramodh

Vishal Suri February 9, 2022

Hi Pramodh,

Thanks for your response. Yes, we are using Jira Server and SSO plugin to enable SAML authentication. Same configuration of SAML works with confluence. Likewise new users get auto added to confluence-users group automatically. But this is not the case with Jira.

If new user logins to jira with his/her username and password instead of SAML, then he/she is added to jira-users group auto.

 

Are there any logs for SAML / SSO to debug this type of issue ?

Suggest an answer

Log in or Sign up to answer