Uploaded image for project: 'Jira Data Center'
  1. Jira Data Center
  2. JRASERVER-72388

Local group membership is removed when JIT is enabled.

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Medium
    • None
    • 8.15.1
    • Documentation - All
    • None

    Description

      Summary

      Currently, when using JIT provided by SSO for Atlassian Server and Data Center, users are updated every time they log in.

      This can cause group membership from being lost if the groups are being managed directly in Jira's internal directory.

      Environment

      • Jira DC 8.15.x
      • SAML SSO 4.1.5
      • OIDC for SSO
      • JIT enabled

      Steps to Reproduce

      1. Login with a user for the first time in Jira, that is provided by the IDP;
      2. JIT will create the user in the internal directory as expected;
      3. Add Jira internal groups to the newly created user;
      4. Log out;
      5. Upon the next log-in, the Internal groups are removed and only the groups provided by the IDP with JIT will be kept.

      Expected Results

      Just like the Delegated LDAP directory, internal groups should be kept and new groups provided by the IDP

      Actual Results

      Users are removed from internal groups as they log in.

      Workaround

      Manage the groups on the IDP side, by creating groups with the same name as Jira's internal groups in the IDP, or disable JIT.

      Attachments

        Issue Links

          Activity

            People

              bc878d9874ad Oksana Levchuk (Inactive)
              psouza Pedro Souza
              Votes:
              20 Vote for this issue
              Watchers:
              28 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: