Hi,
After we have enabled SAML integration with Jira Software, users are not added to jira-users default group and we need to add those new users to jira-users group so they can view project/ticket they have access to.
Any help would be really appreciated.
Hi @Vishal Suri,
It seems you are using JIRA Server not Datacenter which does not have a native SAML feature so I am assuming you are using any SSO plugin from Atlassian Marketplace.
If yes, I suggest you check the configuration and supported features with the developers of that plugin or you can try out the miniOrange SAML which has dedicated options to assign IDP groups as well as default groups to all SSO users(existing and new).
But if you are using the DC version and built-in SAML then check out the link shared by Pramodh.
Thanks,
Lokesh
PS: I work for miniOrange, one of the top SSO vendors on Atlassian Marketplace. You can reach out to miniOrange at atlassiansupport@xecurify.com
Hi Lokesh,
Thanks for your response. Yes, we are using Jira Server and SSO plugin to enable SAML authentication. Same configuration of SAML works with confluence. Likewise new users get auto added to confluence-users group automatically. But this is not the case with Jira.
If new user logins to jira with his/her username and password instead of SAML, then he/she is added to jira-users group auto.
Are there any logs for SAML / SSO to debug this type of issue ?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Vishal,
Can you please let me know which SSO plugin are you using?
Thanks,
Lokesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Lokesh,
We use this plugin for SSO auth to login to jira.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Vishal,
I am not sure if this plugin has a configurable option to select default groups for New Users created through SSO but I think has support for Just in time provisioning where you can send groups (including default groups of JIRA) from IDP in the SAML Response and it will be assigned to SSO users at the time of login.
I think it also has a capacity to assign groups configured in AD/LDAP Configuration, in case, your users are synced from an external user directory.
I suggest you contact Atlassian Support directly for further assistance.
Thanks,
Lokesh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Vishal Suri
Your SAML Configuration defines the new user's default group
Check with your SAML Configuration, if there is an option to add the group when a user is added, the user is also added to the group
Thanks,
Pramodh
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Pramodh,
Thanks for your response. Yes, we are using Jira Server and SSO plugin to enable SAML authentication. Same configuration of SAML works with confluence. Likewise new users get auto added to confluence-users group automatically. But this is not the case with Jira.
If new user logins to jira with his/her username and password instead of SAML, then he/she is added to jira-users group auto.
Are there any logs for SAML / SSO to debug this type of issue ?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.