Uploaded image for project: 'Identity'
  1. Identity
  2. ID-167

Support Nested Groups in Atlassian Cloud platform

    • Icon: Suggestion Suggestion
    • Resolution: Won't Do
    • None
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Problem Definition

      "Enable Nested Group" is turned off in Atlassian Cloud platform. Atlassian Cloud customers would like to get this feature enabled as since Jira 4.3 release, the new user management has the ability to use nested groups.

      It seems that the reason behind disabling this is that: there is a potential risk that Atlassian Cloud licence will not work properly with nested groups.

      Suggested Solution

      Implement nested group feature as implemented in Jira Server.

      Workaround

      Nested groups flattening via Cloud IdP - nested groups aren’t supported in Atlassian Cloud, but you can keep the nested structure in your external user directory and use the flattened one in Cloud. A flattener keeps proper group memberships by automatically recreating memberships from your nested structure in the flat structure, and then adding users to all the required groups.

      Consider syncing groups via IdP that supports the feature - here’s a summary of how identity providers supported in Atlassian Cloud handle nested groups:

      https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/ 

      For example, Azure AD supports nested groups:

      If you'd like to use flattened nested groups with AzureAD, please can check Early Access Program for Nested groups flattening between Atlassian cloud and Azure AD 

            [ID-167] Support Nested Groups in Atlassian Cloud platform

            Should be a basic feature.
            Really need this, please consider implementing it!

            Dominique Dames added a comment - Should be a basic feature. Really need this, please consider implementing it!
            Diego Berrueta made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 845321 ]

            Another request for nested groups in Atlassian cloud. 

            Matt Bailey added a comment - Another request for nested groups in Atlassian cloud. 

            Doron Gill added a comment -

            must have feature

            Doron Gill added a comment - must have feature

            We really need this

            Jonas Runningen added a comment - We really need this

            Milad S. added a comment - - edited

            I hope our votes/comments make you reconsider the decision regarding this feature.

            Milad S. added a comment - - edited I hope our votes/comments make you reconsider the decision regarding this feature.

            Count me as another puzzled person as to why you won't do this.

            The whole architecture for how groups are managed in the cloud doesn't seem sustainable for large organizations as there is no way for anyone but an ORG ADMIN to make group changes. And now you can't even leverage nested groups. Are you trying to make user management a nightmare?

            Krista Stellar added a comment - Count me as another puzzled person as to why you won't do this. The whole architecture for how groups are managed in the cloud doesn't seem sustainable for large organizations as there is no way for anyone but an ORG ADMIN to make group changes. And now you can't even leverage nested groups. Are you trying to make user management a nightmare?
            Ben Borecki (Inactive) made changes -
            Description Original: h3. Problem Definition

            "Enable Nested Group" is turned off in Atlassian Cloud platform. Atlassian Cloud customers would like to get this feature enabled as since Jira 4.3 release, the new user management has the ability to use nested groups.

            It seems that the reason behind disabling this is that: there is a potential risk that Atlassian Cloud licence will not work properly with nested groups.
            h3. Suggested Solution

            Implement nested group feature as implemented in Jira Server.
            h3. Workaround

            [Nested groups flattening via Cloud IdP|[https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/]] - nested groups aren’t supported in Atlassian Cloud, but you can keep the nested structure in your external user directory and use the _flattened_ one in Cloud. A flattener keeps proper group memberships by automatically recreating memberships from your nested structure in the flat structure, and then adding users to all the required groups.

            Consider [syncing groups via IdP|https://support.atlassian.com/provisioning-users/docs/configure-user-provisioning-with-an-identity-provider/] that supports the feature - here’s a summary of how identity providers supported in Atlassian Cloud handle nested groups:

            [https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/

            For example, Azure AD supports nested groups:
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]

            If you'd like to use flattened nested groups with AzureAD, please can check [Early Access Program for Nested groups flattening between Atlassian cloud and Azure AD|https://community.atlassian.com/t5/Enterprise-articles/Nested-groups-flattening-with-Azure-AD-sync-Early-Access-Program/ba-p/2075553#M416
            New: h3. Problem Definition

            "Enable Nested Group" is turned off in Atlassian Cloud platform. Atlassian Cloud customers would like to get this feature enabled as since Jira 4.3 release, the new user management has the ability to use nested groups.

            It seems that the reason behind disabling this is that: there is a potential risk that Atlassian Cloud licence will not work properly with nested groups.
            h3. Suggested Solution

            Implement nested group feature as implemented in Jira Server.
            h3. Workaround

            [Nested groups flattening via Cloud IdP|https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/] - nested groups aren’t supported in Atlassian Cloud, but you can keep the nested structure in your external user directory and use the _flattened_ one in Cloud. A flattener keeps proper group memberships by automatically recreating memberships from your nested structure in the flat structure, and then adding users to all the required groups.

            Consider [syncing groups via IdP|https://support.atlassian.com/provisioning-users/docs/configure-user-provisioning-with-an-identity-provider/] that supports the feature - here’s a summary of how identity providers supported in Atlassian Cloud handle nested groups:

            [https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/

            For example, Azure AD supports nested groups:
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]

            If you'd like to use flattened nested groups with AzureAD, please can check [Early Access Program for Nested groups flattening between Atlassian cloud and Azure AD|https://community.atlassian.com/t5/Enterprise-articles/Nested-groups-flattening-with-Azure-AD-sync-Early-Access-Program/ba-p/2075553#M416
            Ben Borecki (Inactive) made changes -
            Description Original: h3. Problem Definition
            "Enable Nested Group" is turned off in Atlassian Cloud platform. Atlassian Cloud customers would like to get this feature enabled as since Jira 4.3 release, the new user management has the ability to use nested groups.

            It seems that the reason behind disabling this is that: there is a potential risk that Atlassian Cloud licence will not work properly with nested groups.

            h3. Suggested Solution
            Implement nested group feature as implemented in Jira Server.

            h3. Workaround
            None at the moment.
            Consider [syncing groups via IdP|https://support.atlassian.com/provisioning-users/docs/configure-user-provisioning-with-an-identity-provider/] that supports the feature. For example, Azure AD supports nested groups:
            * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]
            * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]
            New: h3. Problem Definition

            "Enable Nested Group" is turned off in Atlassian Cloud platform. Atlassian Cloud customers would like to get this feature enabled as since Jira 4.3 release, the new user management has the ability to use nested groups.

            It seems that the reason behind disabling this is that: there is a potential risk that Atlassian Cloud licence will not work properly with nested groups.
            h3. Suggested Solution

            Implement nested group feature as implemented in Jira Server.
            h3. Workaround

            [Nested groups flattening via Cloud IdP|[https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/]] - nested groups aren’t supported in Atlassian Cloud, but you can keep the nested structure in your external user directory and use the _flattened_ one in Cloud. A flattener keeps proper group memberships by automatically recreating memberships from your nested structure in the flat structure, and then adding users to all the required groups.

            Consider [syncing groups via IdP|https://support.atlassian.com/provisioning-users/docs/configure-user-provisioning-with-an-identity-provider/] that supports the feature - here’s a summary of how identity providers supported in Atlassian Cloud handle nested groups:

            [https://support.atlassian.com/migration/docs/prepare-nested-groups-for-cloud-migration/

            For example, Azure AD supports nested groups:
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]
             * [learn.microsoft.com|https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/directory-service-limits-restrictions]

            If you'd like to use flattened nested groups with AzureAD, please can check [Early Access Program for Nested groups flattening between Atlassian cloud and Azure AD|https://community.atlassian.com/t5/Enterprise-articles/Nested-groups-flattening-with-Azure-AD-sync-Early-Access-Program/ba-p/2075553#M416

              Unassigned Unassigned
              adiallo Abdoulaye Kindy Diallo (Inactive)
              Votes:
              65 Vote for this issue
              Watchers:
              108 Start watching this issue

                Created:
                Updated:
                Resolved: