I'm struggling with the documentation and prior discussions to figure out how these solutions are supposed to work with each other.
I have Crowd integrated with Azure AD, and it is successfully reading all the users and groups via the directory configured.
I have JIRA Server and Confluence Server added as applications to Crowd, and I can browse, i.e. "see" our AD users in the respective applications.
I've given the users created by the Azure AD directory application access to JIRA.
I'm not yet ready to go the whole way of configuring SSO, but for the moment would just like to give our AD users access to JIRA and Confluence.
However, each time I try setting the password for a user, it tries to sync it back to AD and fails (which isn't my goal to begin with), and if I try using the Forgot Password link, I get an email saying "This user account is managed in an external User Directory and Jira is not able to update your password."
Am I totally misunderstanding the purpose of the Crowd <-> Azure AD sync in all of this? Is it only useful if we're using SSO, or should I be able to set passwords to the users created via the Azure AD directory, and use those to log into JIRA/Confluence?
Appreciate your help!
Jira/Confluence users that are synced from Azure AD to Jira/Confluence through Crowd do not have a 'local' password in Jira/Confluence. They must use their Azure AD password to log into those apps.
In short, when you reach Jira/Confluence's login form, enter your Azure AD userPrincipalName in the username field (e.g. firstname.lastname@company.com) and your Azure AD password in the password field.
You won't be able to change the Azure AD password from Jira/Confluence as the connection between Crowd and Azure AD is read-only.
Thanks Bruno... My issue was that the default login form just wasn't accepting my Azure AD username/password. I installed the AD SSO app, and that allows me to log in with my AD credentials.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.