Uploaded image for project: 'Identity'
  1. Identity
  2. ID-7396

Some fields are still editable at https://id.atlassian.com/manage-profile even with SCIM integration enabled

    XMLWordPrintable

Details

    Description

      Issue Summary

      Users still can edit Full name, Job title, Department, Timezone and Organization fields on their Atlassian Accounts details at https://id.atlassian.com/manage-profile even when user provisioning is enabled. This should not happen and might be disruptive to the company since the information may not reflect the information that is on their internal directory.

      Steps to Reproduce

      1. Enable User provisioning
      2. Sync a user
      3. Ask the user to access https://id.atlassian.com/manage-profile and change one of those fields

      When the user does this manual change it overwrites the field. Unless the IdP sends a PATCH to update that information the field won't reflect the IdP information.

      Expected Results

      When User provisioning enables the users should not be able to edit those fields. The Org admins which should have that ability for edge cases don't have.

      Actual Results

      The users can edit them.

      Workaround

      To get the information reflecting the IdP side you should trigger a change on the users' profile there. Each IdP implemented the User provisioning REST API differently so it is recommended that you engage their support team gets more details on how they trigger those updates.

      Attachments

        Issue Links

          Activity

            People

              ef0fd77f42fd Freddie Xavier
              jnunes@atlassian.com João Nunes
              Votes:
              19 Vote for this issue
              Watchers:
              47 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: