Uploaded image for project: 'SAML for Atlassian Data Center'
  1. SAML for Atlassian Data Center
  2. SAMLDC-73

Jira Application Access respect "default group" when using JIT provisioning

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • Icon: Low Low
    • None
    • None
    • None
    • None

      For a customer using AD with JIT provisioning, the "Default Groups" settings under "Application Access" page is currently ignored.

      Expected behavior is when JIT users, are created in internal directory, like manually created users, respect this setting to apply default groups to the user's membership when inserted to internal directory.

       

      App Access page says:

      When you create a user for a Jira application, that user is automatically added to the application's default group.

      But users created via JIT do not respect this setting.

            [SAMLDC-73] Jira Application Access respect "default group" when using JIT provisioning

            Owen made changes -
            Workflow Original: SAMLDC Workflow v2 [ 4056682 ] New: JAC Suggestion Workflow 3 [ 4271315 ]
            Status Original: Verified [ 10005 ] New: Reviewing [ 11773 ]
            Pedro Souza made changes -
            Link New: This issue relates to JRASERVER-72388 [ JRASERVER-72388 ]
            Mareusz (Inactive) made changes -
            Link New: This issue duplicates SAMLDC-69 [ SAMLDC-69 ]
            Thiago Masutti made changes -
            Link New: This issue is related to CONFSERVER-60578 [ CONFSERVER-60578 ]
            Thiago Masutti made changes -
            Remote Link New: This issue links to "Page (Confluence)" [ 535107 ]
            Deyves (Inactive) made changes -
            Link New: This issue is related to JRASERVER-72066 [ JRASERVER-72066 ]
            Deyves (Inactive) made changes -
            Link Original: This issue is related to JRASERVER-72066 [ JRASERVER-72066 ]
            Alexander (Inactive) made changes -
            Link New: This issue is related to JRASERVER-72066 [ JRASERVER-72066 ]
            Eddie Webbinaro (Inactive) made changes -
            Description Original: For a customer using AD with JIT provisioning, the "Default Groups" settings under "Application Access" page is currently ignored.

            Expected behavior is when JIT users, are created in internal directory, like manually created users, respect this setting to apply default groups on first login.



             
            New: For a customer using AD with JIT provisioning, the "Default Groups" settings under "Application Access" page is currently ignored.

            *Expected behavior* is when JIT users, are created in internal directory, like manually created users, respect this setting to apply default groups to the user's membership when inserted to internal directory.

             

            App Access page says:
            {quote}When you create a user for a Jira application, that user is automatically added to the application's default group.
            {quote}
            But users created via JIT do not respect this setting.
            Eddie Webbinaro (Inactive) made changes -
            Description Original: For a customer using Azure AD with JIT provisioning, with a large AD footprint, passing all group memberships via SAML is problematic, hitting the 150 group limit.

            Customer requests: adding an option to consume a SAML Token, which will work around the user login issue when hitting the 150 group limitation. Once user has required groups when the login JIT automatically maps the user group with Application Access group and add user to it automatically.

            Also consider the possibility of local AD user directory (not Azure AD) to handle the possible scenario in which the user logs on with JIT but Application Access default groups are not yet setup.
            New: For a customer using AD with JIT provisioning, the "Default Groups" settings under "Application Access" page is currently ignored.

            Expected behavior is when JIT users, are created in internal directory, like manually created users, respect this setting to apply default groups on first login.



             

              Unassigned Unassigned
              abeltz Alexander (Inactive)
              Votes:
              12 Vote for this issue
              Watchers:
              21 Start watching this issue

                Created:
                Updated: