Uploaded image for project: 'Admin Experience'
  1. Admin Experience
  2. AX-346

Multiple Selective user claim for same domain by different Organizations

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Issue Summary

      There are situations where a company/organization has different departments with each their own Atlassian Organization and Cloud Sites. The departments all share the same domain but manage different users.

      In the light of the Selective user claim feature release (https://jira.atlassian.com/browse/ACCESS-764), it would be useful that the same domain can be claimed multiple times by different Organizations, each claiming their set of users.

      Currently, a domain can only belong to one Organization at a time, even if not all accounts have been claimed.

      Workaround

      Currently there is no known workaround for this behavior. A workaround will be added here when available

       

      2024/05/23 Update

      Hi everyone,

      Just a quick update to let you know that this new feature has now been released to all customers.

      If you experience any issues or have any new suggestions with this, please raise a new ticket so that we can investigate further.

      Thanks,

      Chantelle Liu
      Atlassian Access Associate Product Manager

       

        1. acme.jpeg
          acme.jpeg
          78 kB
        2. acme 1.png
          acme 1.png
          25 kB

            [AX-346] Multiple Selective user claim for same domain by different Organizations

            Rodrigo B. made changes -
            Component/s Original: Domain Claim - Maintenance [ 66394 ]
            Component/s Original: Domain Claim - Initial Setup [ 53302 ]
            Component/s New: Domain Verification - Maintenance [ 80146 ]
            Component/s New: Domain Verification - Initial Setup [ 80145 ]
            Key Original: ACCESS-1450 New: AX-346
            Support reference count Original: 161
            Project Original: Atlassian Guard [ 18910 ] New: Admin Experience [ 24210 ]
            Aneita made changes -
            Description Original: h3. Issue Summary

            There are situations where a company/organization has different departments with each their own Atlassian Organization and Cloud Sites. The departments all share the same domain but manage different users.

            In the light of the Selective user claim feature release (https://jira.atlassian.com/browse/ACCESS-764), it would be useful that the same domain can be claimed multiple times by different Organizations, each claiming their set of users.

            Currently, a domain can only belong to one Organization at a time, even if not all accounts have been claimed.
            h3. Workaround

            Currently there is no known workaround for this behavior. A workaround will be added here when available

             
            {panel:title=2024/01/11 Update|borderStyle=dashed|borderColor=#4dabf7|titleBGColor=#4dabf7|bgColor=#d0ebff}
            Good news - the ability to verify a domain in multiple orgs, and claim unique users from that domain, is now available in early access!

            If your organization is interested in trying this feature in early access, please send me an email at *ayang@atlassian.com* along with your org ID and the domain that you’d like to verify so that we can evaluate your eligibility.

            {+}This feature is expected to be available in early access until the GA release in Q2 2024{+}. You can follow our [public roadmap|https://www.atlassian.com/wac/roadmap/cloud/multi-org-domain-claims?search=multi%20org&p=34230be2-ab] item for updates on the GA release.

            Cheers,
            Aneita
            {panel}
             
            New: h3. Issue Summary

            There are situations where a company/organization has different departments with each their own Atlassian Organization and Cloud Sites. The departments all share the same domain but manage different users.

            In the light of the Selective user claim feature release ([https://jira.atlassian.com/browse/ACCESS-764]), it would be useful that the same domain can be claimed multiple times by different Organizations, each claiming their set of users.

            Currently, a domain can only belong to one Organization at a time, even if not all accounts have been claimed.
            h3. Workaround

            Currently there is no known workaround for this behavior. A workaround will be added here when available

             
            {panel:title=2024/05/23 Update|borderStyle=dashed|borderColor=#4dabf7|titleBGColor=#4dabf7|bgColor=#d0ebff}
            Hi everyone,

            Just a quick update to let you know that this new feature has now been released to all customers.

            If you experience any issues or have any new suggestions with this, please raise a new ticket so that we can investigate further.

            Thanks,

            Chantelle Liu
            Atlassian Access Associate Product Manager
            {panel}
             
            Adrienne Jackson made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 926423 ]
            trossiter made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 916374 ]
            Jared Winter made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 915169 ]

            David Cowley added a comment - - edited

            f88495f47be4 I'm not sure if you can. I've used the feature now on domains that I knew were previously claimed by other Orgs (I know who they are and such already as well). But the only real indication that it was claimed by another Org that I recall seeing in the process is that there's a discrepancy between the All accounts column and the Available to claim column. There might have been something in the wizard that said it was already claimed, but didn't register for me because I knew they were already claimed. 

            admin.atlassian.com -> Settings -> Domains (can't include a screenshot unfortunately it seems)

            David Cowley added a comment - - edited f88495f47be4 I'm not sure if you can. I've used the feature now on domains that I knew were previously claimed by other Orgs (I know who they are and such already as well). But the only real indication that it was claimed by another Org that I recall seeing in the process is that there's a discrepancy between the All accounts column and the Available to claim column. There might have been something in the wizard that said it was already claimed, but didn't register for me because I knew they were already claimed.  admin.atlassian.com -> Settings -> Domains (can't include a screenshot unfortunately it seems)

            How can I tell if a domain has been claimed by another organization? 

            Catherine McCaffrey added a comment - How can I tell if a domain has been claimed by another organization? 
            Chantelle Liu made changes -
            Resolution New: Fixed [ 1 ]
            Status Original: In Progress [ 3 ] New: Closed [ 6 ]

            Aneita added a comment -

            Hey 6ffdcfc4150d - users will always have the authentication policy assigned to them by the org that manages their account. In your example above, you're right in that user@org1domain.com will authenticate based on the auth policy that Org 2 has assigned to the user as Org 2 manages the account. Even if the user is accessing a site outside of Org 2, Org 2's auth policy will apply. Other orgs will not be able to apply an auth policy to this user as they do not manage the account. 

            External user security is a feature that enables orgs to require an extra step of security at the point of content access (not login).

            Aneita added a comment - Hey 6ffdcfc4150d - users will always have the authentication policy assigned to them by the org that manages their account. In your example above, you're right in that user@org1domain.com will authenticate based on the auth policy that Org 2 has assigned to the user as Org 2 manages the account. Even if the user is accessing a site outside of Org 2, Org 2's auth policy will apply. Other orgs will not be able to apply an auth policy to this user as they do not manage the account.  External user security is a feature that enables orgs to require an extra step of security at the point of content access (not login).
            SET Analytics Bot made changes -
            Support reference count Original: 160 New: 161

              ayang@atlassian.com Aneita
              ea8de7b38038 Kenneth De Coster
              Votes:
              77 Vote for this issue
              Watchers:
              102 Start watching this issue

                Created:
                Updated:
                Resolved: