Uploaded image for project: 'Atlassian Access'
  1. Atlassian Access
  2. ACCESS-1309

Show warning in UI if org admin account is in an enforced SSO policy

    XMLWordPrintable

Details

    • 113
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      Atlassian Update - Nov 27, 2023

      We've rolled out a change in Atlassian Administration to show warnings when organization admins add/edit an authentication policy with single sign-on (SSO) and when they update SAML configuration.

      Please see our support documentation on testing your authentication policy (including SSO) on a smaller subset of users before rolling it out

      Problem Definition

      When an org admin is trying to Configure SAML single sign-on with an identity provider and the org. admin(s) are included in the enforced SSO policy - the org. admin(s) can get locked out of their account if there is an issue with the SAML configuration.

      Suggested Solution

      • There should be a UI warning message when configuring authentication policies to warn admins that they have an "org admin" account in an authentication policy where enforced SSO is enabled
      • The Message can warn the admin about their own org admin account being locked out

      Why this is important

      • If there is a problem with the SAML configuration org. admin(s) will end up being locked out of their own organization and are forced to contact support for assistance
      • This can help reduce contact index and alleviate support load
      • Usually when this happens all on the org. users can't log in either, so admins need to recover access quickly and fix the SAML configuration issue

      Workaround

      • When testing, exclude the org. admin(s) from authentication policies where enforced SSO is enabled. This is to ensure that the org. admin(s) are not locked out if there is an issue with the SAML configuration
      • Add another org admin. who is on a domain that is not claimed by the Atlassian organization

      Attachments

        Issue Links

          Activity

            People

              a09734a47f1d Bhavya Nag
              2215c95d2c26 Hector Menchaca
              Votes:
              2 Vote for this issue
              Watchers:
              10 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: