Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1379

AAid gets unlinked while changing an email from Managed to UnManaged vis SCIM

      Issue Summary

      Email change from Managed to Unmanaged is prohibited in Atlassian Cloud.
      However, when this change is triggered via SCIM, the AAid- SCIM link gets broken.

      This is reproducible on Data Center: (yes) / (no)

      Steps to Reproduce

      1. Push an update for an account to change the email from Managed to Unmanaged via SCIM
      2. The email gets updated on IDEA however the AAid of the old user is removed from SCIM

      Expected Results

      The update fails on SCIM and an error is shown

      Actual Results

      IDP-Atlassian SCIM link breaks for the user.
      Org Admins get confused so as to what exactly happened.

      1. We see the following error in the Provisioning logs:
      Email update to unmanaged user with ID ********, primary email user@domain.com, unlinked any associated Atlassian account.
      

      Workaround

      Relink the AAid with SCIM by the help of maintenance API however, even this will end up with the user having 2 Atlassian Accounts

          Form Name

            [ACCESS-1379] AAid gets unlinked while changing an email from Managed to UnManaged vis SCIM

            Ramon M made changes -
            Link New: This issue is related to ACCESS-1396 [ ACCESS-1396 ]
            Yang Li made changes -
            Resolution New: Answered [ 9 ]
            Status Original: Needs Triage [ 10030 ] New: Closed [ 6 ]
            SET Analytics Bot made changes -
            Support reference count Original: 10 New: 11
            SET Analytics Bot made changes -
            Support reference count Original: 9 New: 10

            We are looking on changing this behavior but before we can plan for this on the roadmap we are waiting on security for approval

            https://asecurityteam.atlassian.net/servicedesk/customer/portal/19/PSHELP-25711?atlOrigin=eyJpIjoiYjQ5Y2Q2MWIwMTYzNDgyYzg2NzJlOTYwMTQ1YzFiYmIiLCJwIjoiamlyYS1zbGFjay1pbnQifQ

            FellowJitster added a comment - We are looking on changing this behavior but before we can plan for this on the roadmap we are waiting on security for approval https://asecurityteam.atlassian.net/servicedesk/customer/portal/19/PSHELP-25711?atlOrigin=eyJpIjoiYjQ5Y2Q2MWIwMTYzNDgyYzg2NzJlOTYwMTQ1YzFiYmIiLCJwIjoiamlyYS1zbGFjay1pbnQifQ
            Yang Li made changes -
            Status Original: In Progress [ 3 ] New: Needs Triage [ 10030 ]
            Yang Li made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 778069 ]
            SET Analytics Bot made changes -
            Support reference count Original: 7 New: 9
            Bugfix Automation Bot made changes -
            Priority Original: Medium [ 3 ] New: High [ 2 ]
            SET Analytics Bot made changes -
            Support reference count Original: 6 New: 7

              yli2@atlassian.com Yang Li
              umasih@atlassian.com Ulka
              Affected customers:
              2 This affects my team
              Watchers:
              13 Start watching this issue

                Created:
                Updated:
                Resolved: