Application Links from Jira can fail to connect when using Microsoft Entra application proxy Pre-Authentication

XMLWordPrintable

    • Type: Suggestion
    • Resolution: Unresolved
    • None
    • Component/s: Application Links
    • None
    • 4

      Problem Statement:

      As an administrator, I want to setup my environment with Microsoft Entra application proxy's Pre-Authentication option to add an additional security layer. When this feature is enabled, application links from Jira fail to connect to other Atlassian Products.

      Summary:

      Microsoft Entra Application Proxy has a feature called "Pre-Authentication" which, when enabled, will block a significant number of anonymous attacks because only authenticated identities can access the back-end application.

      When you try to setup an application link from Jira, however, the "Pre-Authentication" feature interrupts the Oauth Dance and, as the application link isn't able to obtain an authentication token, the application url for the other Atlassian product returned is actually the Azure Login URL.

      Impact:

      Administrators will generally see "Network Error" from the application link page and users will not be able to utilize typical application link functionality between Atlassian Products. 

      Idea:

      Please update the Application Link Oauth Dance to Support Microsoft Entra application proxy Pre-Authentication feature.

      Work Around

      When deploying Jira behind Microsoft Entra Application Proxy choose the "Passthrough" option for your pre-authentication method.

              Assignee:
              Unassigned
              Reporter:
              Patrick Turbett
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: