Log inSkip to main contentSkip to sidebar
Something went wrong, please try again.
Create and track feature requests for Atlassian products.
  • More
    DashboardsProjectsIssues
  • Give feedback to Atlassian
  • Help
    • Jira Core help
    • Keyboard Shortcuts
    • About Jira
    • Jira Credits
  • Log In
IMPORTANT: JAC is a Public system and anyone on the internet will be able to view the data in the created JAC tickets. Please don’t include Customer or Sensitive data in the JAC ticket.

Open issues

  • All issues
  • Open issues
  • Done issues
  • Viewed recently
  • Created recently
  • Resolved recently
  • Updated recently
View all issues and filters
Order by Priority
  1. Suggestion
    ACCESS-1952Allow Multiple External User Security Policies
  2. Suggestion
    ACCESS-1534Allow org admins to disable Bitbucket Cloud 2FA
  3. Suggestion
    ACCESS-2403Comprehensive Auditing Solution for Group Management in Guard, Confluence, and AAD.
  4. Suggestion
    ACCESS-822Support more synced attributes for SCIM User Provisioning
  5. Suggestion
    ACCESS-1396Ability to check and re-sync provisioned external account after an email address change
  6. Suggestion
    ACCESS-604Grant users synced from identity providers via SCIM application access by default
  7. Suggestion
    ACCESS-800Ability to rename groups after they've synced to the organization from an identity provider.
  8. Suggestion
    ACCESS-1559Ability to export groups from Atlassian Admin
  9. Suggestion
    ACCESS-1583Allow certain users to be excluded from IP Allowlisting so that the can log in from any network
  10. Suggestion
    ACCESS-1703Ability to know in which group without being Admin
  11. Suggestion
    ACCESS-1834Automatically move users from local policy to IDP linked policy once they are provisioned
  12. Suggestion
    ACCESS-1919Improve UI messaging for anomaly group deletion detected by Google Workspace sync
  13. Suggestion
    ACCESS-1979Provide SSO authentication with Microsoft Azure Automatic Integration
  14. Suggestion
    ACCESS-2202Customization for Guard Premium's Data Classification Field in Jira
  15. Suggestion
    ACCESS-2223Option to disable External users policy
  16. Suggestion
    ACCESS-2398Authorization header instruction for the audit log webhook configuration
  17. Suggestion
    ACCESS-1654Include audit logs for JWM/Business type projects
  18. Suggestion
    ACCESS-2135Feature to turn off new product pop ups
  19. Suggestion
    ACCESS-2308Disable the "Remove user" button on the Users page UI for SCIM synced users.
  20. Suggestion
    ACCESS-621Ability to provision users to Bitbucket Cloud repositories with SCIM
  21. Suggestion
    ACCESS-625Provide support for OpenID Connect (besides SAML) for SSO
  22. Suggestion
    ACCESS-940Add support for "Linked" Push groups in the Okta integration
  23. Suggestion
    ACCESS-1021Provide ability to remove synced accounts and groups from the Directory through the UI
  24. Suggestion
    ACCESS-1048IP allowlist on organization administration (admin.atlassian.com)
  25. Suggestion
    ACCESS-1458Ability to exclude or differentiate deactivated users in authentication policies
  26. Suggestion
    ACCESS-1533Allow for org and site admin permissions to be assigned via groups (local or provisioned)
  27. Suggestion
    ACCESS-1575Allow admins to unlock a provisioned managed account temporarily and later on relink with the Provisioned data (API and UI option)
  28. Suggestion
    ACCESS-1612Ability to selectively enable external user security for subset of external users
  29. Suggestion
    ACCESS-1832Unlink SCIM synced groups instead of deleting them when the group is removed/unassigned in the IDP
  30. Suggestion
    ACCESS-1959IP allowlist feature for standard editions
  31. Suggestion
    ACCESS-2048Increase the limit of users in external user security test policy
  32. Suggestion
    ACCESS-2124Support External user security for Bitbucket workspaces that are added or linked to Atlassian organization
  33. Suggestion
    ACCESS-2212Ability to have more granular control of the "data export block" for Jira and Confluence
  34. Suggestion
    ACCESS-2366Managed Teams when connected with a Group should not take the name of the connected group
  35. Suggestion
    ACCESS-2074Unlink the Okta group left in the target app
  36. Suggestion
    ACCESS-2392Expand BBC activities tracked in Atlassian Guard audit log
  37. Suggestion
    ACCESS-1002Enabling allow listing policies automatically blocks Atlassian's own IPs
  38. Suggestion
    ACCESS-1040IP allow list: Allow specific policies to only apply to specific products/pages/Spaces/Projects
  39. Suggestion
    ACCESS-2388Ability to add groups to authentication policies.
  40. Suggestion
    ACCESS-720Deactivation policies for managed accounts
  41. Suggestion
    ACCESS-814Implement user and group provisioning with Trello
  42. Suggestion
    ACCESS-832Enable organization admins to view the authentication policy and method each user utilized when logging into Atlassian.
  43. Suggestion
    ACCESS-905Provide a web UI to change the managed accounts' public name for organization admins
  44. Suggestion
    ACCESS-1009Ability to control site/organization access for accounts via user provisioning
  45. Suggestion
    ACCESS-1481Removing the User from Atlassian Cloud App on IDP should unlink its SCIM ID
  46. Suggestion
    ACCESS-1670Allow Custom Admin Roles
  47. Suggestion
    ACCESS-1978Delete the synced user's Atlassian account once the user is deleted from the IDP
  48. Suggestion
    ACCESS-2153Support additional filters (eq) for the user provisioning REST API
  49. Suggestion
    ACCESS-2332Summary: Add audit log entries for app additions (e.g., JSM trial) to existing sites
  50. Suggestion
    ACCESS-2401Multiple Mobile App Policies for the same app
Refresh results
1 2 3 4 5Next >>
4 of 502
Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-822

Support more synced attributes for SCIM User Provisioning

Log In
In Progress
Export
undefinedView workflow
XMLWordPrintable

    • Icon: Suggestion Suggestion
    • Resolution: Unresolved
    • User Sync - Managed Accounts
      • ACE-5310
      • RIBS-SHORT
      • guard-s8
      • sam-request
    • 579
    • Hide

      5th November
      Thank you all for your feedback and to those who answered our survey.

      We have added a Location attribute to SCIM User Provisioning. To add Location, you will need to sync to the following attribute: 

      • Full Attribute: urn:scim:schemas:extension:atlassian-custom:1.0:Attributes:basedIn
        • Namespace: urn:scim:schemas:extension:atlassian-custom:1.0:Attributes
        • Attribute Name: basedIn

      We are continuing to work on adding the following attributes and will provide dates for them shortly:

      • Profile picture
      • Employee ID

      We will also be enabling automations for approval workflows for the Manager attribute.

      We understand the importance of this feature, and we will update this ticket with more information on specific dates as we have them.

      Our support documentation will be updated as new attributes are added:

      • https://support.atlassian.com/provisioning-users/docs/understand-user-provisioning/
      • https://support.atlassian.com/provisioning-users/docs/sync-user-attributes-to-your-organization/

       

      Thanks,
      Holly

      Show
      5th November Thank you all for your feedback and to those who answered our survey. We have added a Location attribute to SCIM User Provisioning. To add Location, you will need to sync to the following attribute:  Full Attribute : urn:scim:schemas:extension:atlassian-custom:1.0:Attributes:basedIn Namespace : urn:scim:schemas:extension:atlassian-custom:1.0:Attributes Attribute Name : basedIn We are continuing to work on adding the following attributes and will provide dates for them shortly: Profile picture Employee ID We will also be enabling automations for approval workflows for the Manager attribute. We understand the importance of this feature, and we will update this ticket with more information on specific dates as we have them. Our support documentation will be updated as new attributes are added: https://support.atlassian.com/provisioning-users/docs/understand-user-provisioning/ https://support.atlassian.com/provisioning-users/docs/sync-user-attributes-to-your-organization/   Thanks, Holly
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      As per the user-provisioning documentation the feature currently supports the sync of:

      • Display name
      • Email address
      • Organization
      • Job title
      • Timezone
      • Department
      • Preferred language

      From provisioning perspective, it would be a good feature to allow custom attributes from third party IDPs to be synced into the Atlassian accounts. Sample use cases:

      • Profile photos
      • Location/Office/Based in
      • Manager (JSD approvals automatically set to the user's Manager)
      • Employee ID
      • Student ID's
      • Cost center

            • Sort By Name
            • Sort By Date
            • Ascending
            • Descending
            • Thumbnails
            • List
        1. image-2024-12-05-15-38-25-789.png
          image-2024-12-05-15-38-25-789.png
          71 kB
          05/Dec/2024 2:38 PM
        2. image-2024-12-05-15-38-34-790.png
          image-2024-12-05-15-38-34-790.png
          100 kB
          05/Dec/2024 2:38 PM
        3. Screen Shot 2022-09-30 at 16.16.55.png
          Screen Shot 2022-09-30 at 16.16.55.png
          1.44 MB
          30/Sep/2022 7:18 AM

        is duplicated by

        Bug - A problem which impairs or prevents the functions of the product. ACCESS-766 Based in (location) cannot be updated via user provisioning

        • Medium - Medium priority issues
        • Closed

        Suggestion - ACCESS-785 Support Syncing User's Profile Photo with SCIM User Provisioning

        • Closed

        Suggestion - ACCESS-883 Allow to sync profile photos from external identity providers

        • Closed

        Suggestion - ACCESS-886 Include profile picture in azure user provisioning

        • Closed

        Suggestion - ACCESS-1417 Sync additional information to Atlassian Account using GSuite

        • Closed

        Suggestion - ACCESS-1626 Allow for the ability to take profile information from external sources

        • Closed

        Suggestion - CLOUD-11126 Allow Customized Attribute Mapping from Identity Provider

        • Closed

        Suggestion - ID-7724 Active Directory profile picture sync

        • Closed

        Suggestion - ACCESS-657 Support more attributes for user-provisioning

        • Closed

        Suggestion - ACCESS-1487 Push Other Attributes from an IDP to Atlassian Cloud Managed Profiles

        • Gathering Interest
        relates to

        Suggestion - ACCESS-1240 Sync Atlassian teams from identity provider via SCIM

        • Closed

        ACE-5271 Loading...

        ACE-5310 Loading...

        blocks

        LINK-4558 Loading...

        is addressed by

        ENT-406 Loading...

        links to

        Web Link How to sync more user attributes from Azure AD - Atlassian Community

        mentioned in

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        Page Loading...

        (5 is duplicated by, 3 relates to, 1 blocks, 1 is addressed by, 1 links to, 36 mentioned in)

              • All
              • Comments
              • Work Log
              • History
              • Activity
              Pinned comments

              Pinned by Cole Norman

              Holly Makris (Inactive) added a comment - 20/Sep/2024 12:35 AM

              For those of you asking about UPN sync for Entra, that is also in progress, scheduled to launch by the end of 2024. You can track progress here: https://jira.atlassian.com/browse/ACCESS-1560

              We have heard your feedback related to the Manager attribute. When Manager becomes available, you will also be able to use it for automating approvals, which is why it will take a bit longer to release than the other attributes.

              We will make sure the product teams are aware of the additional attributes and your feedback related to attribute automation.

              Thank you for your feedback!

              Holly Makris (Inactive) added a comment - 20/Sep/2024 12:35 AM For those of you asking about UPN sync for Entra, that is also in progress, scheduled to launch by the end of 2024. You can track progress here: https://jira.atlassian.com/browse/ACCESS-1560 We have heard your feedback related to the Manager attribute. When Manager becomes available, you will also be able to use it for automating approvals, which is why it will take a bit longer to release than the other attributes. We will make sure the product teams are aware of the additional attributes and your feedback related to attribute automation. Thank you for your feedback!

              Pinned by Holly Makris (Inactive)

              Holly Makris (Inactive) added a comment - 06/Nov/2024 10:46 PM

              Thank your for your feedback on how to add the Location attribute. We have updated our documentation here: https://support.atlassian.com/provisioning-users/docs/sync-user-attributes-to-your-organization/

              Please do continue to post your questions and feedback, we are reviewing daily and will update the documentation to address any confusion.

              We will update this ticket with more information about the Employee ID and Profile picture attributes as well as Manager automations as soon as we have them. Please watch the Current Status section of this ticket for updates.

              Holly Makris (Inactive) added a comment - 06/Nov/2024 10:46 PM Thank your for your feedback on how to add the Location attribute. We have updated our documentation here: https://support.atlassian.com/provisioning-users/docs/sync-user-attributes-to-your-organization/ Please do continue to post your questions and feedback, we are reviewing daily and will update the documentation to address any confusion. We will update this ticket with more information about the Employee ID and Profile picture attributes as well as Manager automations as soon as we have them. Please watch the Current Status section of this ticket for updates.

              All comments

              Nathan Kulmann added a comment - Yesterday

              How about being able to provision in a user's phone number? I would think this is pretty basic

              Nathan Kulmann added a comment - Yesterday How about being able to provision in a user's phone number? I would think this is pretty basic

              Stefaan added a comment - 2 days ago

              Hosting those profile pictures somewhere public is an absolute security no-go.

              Stefaan added a comment - 2 days ago Hosting those profile pictures somewhere public is an absolute security no-go.

              s.weber added a comment - 2 days ago

              Hi 7778d37f2763 , 

              we are currently not allowed to execute the approach. I don't see why its so hard to re-use what's there.. The images from the profiles from our local AD are already in Entra ID and in the O365 Profile.

              s.weber added a comment - 2 days ago Hi 7778d37f2763 ,  we are currently not allowed to execute the approach. I don't see why its so hard to re-use what's there.. The images from the profiles from our local AD are already in Entra ID and in the O365 Profile.

              Rune Rasmussen added a comment - 3 days ago

              7778d37f2763 On the topic of using the manager in approval flows:

              I've been poking around with Smart Values and all the "GET User" looking API endpoints I can find, but I can't find the manager attribute or value.

              If you find something that works I'm very interested in hearing about it.

              Maybe e902c0832f88 can tell us if the Manager is possible to get with a Smart Value or API endpoint, or if it currently only shows in the UI and nowhere else?

              Rune Rasmussen added a comment - 3 days ago 7778d37f2763 On the topic of using the manager in approval flows: I've been poking around with Smart Values and all the "GET User" looking API endpoints I can find, but I can't find the manager attribute or value. If you find something that works I'm very interested in hearing about it. Maybe e902c0832f88 can tell us if the Manager is possible to get with a Smart Value or API endpoint, or if it currently only shows in the UI and nowhere else?

              Brian Foley added a comment - 6 days ago - edited

              ce97ef160c39 121b87ce6f8e Did either of you get profile photo sync working satisfactorily?

              Is there more complete instructions than what is linked to below?

              We wont be allowed to do this part: "The pictures must be stored in a publicly accessible location" with personal data such as images.  Does anybody know if they really need to be fully public?  Our Atlassian instances are IP whitelisted to our corporate IPs – do the photos need to be available to atlassian's IP range, or just our corporate IP range?

              Brian Foley added a comment - 6 days ago - edited ce97ef160c39 121b87ce6f8e Did either of you get profile photo sync working satisfactorily? Is there more complete instructions than what is linked to below? We wont be allowed to do this part: "The pictures must be stored in a publicly accessible location" with personal data such as images.  Does anybody know if they really need to be fully public?  Our Atlassian instances are IP whitelisted to our corporate IPs – do the photos need to be available to atlassian's IP range, or just our corporate IP range?

              Brian Foley added a comment - 6 days ago

              fb7f7643e44d FYI, we found that manager sync works fine from Entra to Guard, and does show up under user profile under both "Manager" and "Direct reports" fields.  There is also a "Reporting line" widget under home.atlassian.com that shows an org chart of sorts.  We have not yet tested using manager in approval flow.

              Have you setup attribute mapping as per: https://support.atlassian.com/platform-experiences/docs/how-to-sync-the-manager-attribute-into-atlassian-home-with-azure-ad/

              Brian Foley added a comment - 6 days ago fb7f7643e44d FYI, we found that manager sync works fine from Entra to Guard, and does show up under user profile under both "Manager" and "Direct reports" fields.  There is also a "Reporting line" widget under home.atlassian.com that shows an org chart of sorts.  We have not yet tested using manager in approval flow. Have you setup attribute mapping as per: https://support.atlassian.com/platform-experiences/docs/how-to-sync-the-manager-attribute-into-atlassian-home-with-azure-ad/

              Patrícia Francezi added a comment - 1 week ago

              Manager is currently possible to sync based on Platform Experiences, but it does not show correctly in User profile,  because the id guard receives is a external user in entra id - its the user id.

              User profile does not know how to read the external id for it, so is not showing. 

              Is there any timeline to have this 

              From this comment https://jira.atlassian.com/browse/ACCESS-822?focusedId=3504561&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-3504561
              Its being 1 year now 

              When Manager becomes available, you will also be able to use it for automating approvals, which is why it will take a bit longer to release than the other attributes.

              e902c0832f88 please update us!

              Patrícia Francezi added a comment - 1 week ago Manager is currently possible to sync based on Platform Experiences, but it does not show correctly in User profile,  because the id guard receives is a external user in entra id - its the user id. User profile does not know how to read the external id for it, so is not showing.  Is there any timeline to have this  From this comment https://jira.atlassian.com/browse/ACCESS-822?focusedId=3504561&page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#comment-3504561 Its being 1 year now  When Manager becomes available, you will also be able to use it for automating approvals, which is why it will take a bit longer to release than the other attributes. e902c0832f88 please update us!

              Christian Humer added a comment - 06/Aug/2025 1:04 PM

              Hello Guys

              Is the profile picture sync with Entra ID now working or not? The pictures must be stored in a publicly accessible location. According to the documentation (https://support.atlassian.com/provisioning-users/docs/sync-user-profile-photos-to-your-organization), I guess "yes".

              Christian Humer added a comment - 06/Aug/2025 1:04 PM Hello Guys Is the profile picture sync with Entra ID now working or not? The pictures must be stored in a publicly accessible location. According to the documentation ( https://support.atlassian.com/provisioning-users/docs/sync-user-profile-photos-to-your-organization ), I guess "yes".

              Samuel Segaud added a comment - 06/Aug/2025 9:43 AM

              Hi e902c0832f88 

              Would it be possible to have visibility over the availability of the manager field in the synchronization, thus enabling automatic approval workflows?

               

              Automatically at last.... By developing a system to retrieve the manager from Assets. But perhaps you have an idea of when Atlassian will be able to take the manager into account automatically in approvals with something like issue.reporter.manager. That would be great, but maybe just a dream.

               

              Samuel Segaud added a comment - 06/Aug/2025 9:43 AM Hi e902c0832f88   Would it be possible to have visibility over the availability of the manager field in the synchronization, thus enabling automatic approval workflows?   Automatically at last.... By developing a system to retrieve the manager from Assets. But perhaps you have an idea of when Atlassian will be able to take the manager into account automatically in approvals with something like issue.reporter.manager. That would be great, but maybe just a dream.  

              Kim Walton added a comment - 22/Jul/2025 6:56 PM - edited

              Hopefully they include some details as to what specifically is going to be included in this progress.   There are so many attributes that have been added in the comments and every one of them would be useful to most, if not everyone.  

              Kim Walton added a comment - 22/Jul/2025 6:56 PM - edited Hopefully they include some details as to what specifically is going to be included in this progress.   There are so many attributes that have been added in the comments and every one of them would be useful to most, if not everyone.  

                e902c0832f88 Sudesh Peram
                rmacalinao Ramon M
                Votes:
                1090 Vote for this issue
                Watchers:
                643 Start watching this issue

                  Created:
                  26/Feb/2020 3:01 PM
                  Updated:
                  Yesterday 3:01 PM
                  • Atlassian Jira Project Management Software
                  • About Jira
                  • Report a problem
                  • Privacy policy
                  • Notice at Collection

                  Atlassian