In Jira Align, can the user/group/role management be offloaded to an external Active Directory?
Summary
The Jira Align Support Team are sometimes asked questions similar to one of the following:
"Is it possible to synchronize user/group/role data from/to external directories ( Active Directory etc.) with Jira Align?"
“Is there is a way to assign System or Team roles to people in Jira Align by adding them to specific Active Directory groups?”
“We have to ensure that we manage our users using Active Directory or SiteMinder etc. We do not want to manage users via JIRA Align but automate in some way similar to how we are using the other Atlassian tools (JIRA, confluence, etc..). Isd there any way to support this in Jira Align?”
Environment
Jira Align
Solution
Jira Align's integration with SSO providers, such as Active Directory (AD), only integrates the Authentication (credential verification), as per the Jira Align User-authentication workflow. Authorization and Auditing, which are the remaining two concepts for managing software access (security) in distributed environments, are handled solely within Jira Align and are not integrated to AD in any way.
Due to no integration for Authorization, there is no ability to manage the permissions within Jira Align via groups configured inside Active Directory and administrators will need to create users and apply roles to them within Jira Align itself