Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Azure AD + Crowd + JIRA/Confluence without SSO

Dhruv Khattar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 27, 2019

I'm struggling with the documentation and prior discussions to figure out how these solutions are supposed to work with each other.

 

I have Crowd integrated with Azure AD, and it is successfully reading all the users and groups via the directory configured.

I have JIRA Server and Confluence Server added as applications to Crowd, and I can browse, i.e. "see" our AD users in the respective applications.
I've given the users created by the Azure AD directory application access to JIRA.

 

I'm not yet ready to go the whole way of configuring SSO, but for the moment would just like to give our AD users access to JIRA and Confluence.
However, each time I try setting the password for a user, it tries to sync it back to AD and fails (which isn't my goal to begin with), and if I try using the Forgot Password link, I get an email saying "This user account is managed in an external User Directory and Jira is not able to update your password."

Am I totally misunderstanding the purpose of the Crowd <-> Azure AD sync in all of this? Is it only useful if we're using SSO, or should I be able to set passwords to the users created via the Azure AD directory, and use those to log into JIRA/Confluence?

Appreciate your help!

1 answer

1 accepted

0 votes
Answer accepted
Bruno Vincent
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 12, 2019

Hi @Dhruv Khattar 

Jira/Confluence users that are synced from Azure AD to Jira/Confluence through Crowd do not have a 'local' password in Jira/Confluence. They must use their Azure AD password to log into those apps.

In short, when you reach Jira/Confluence's login form, enter your Azure AD userPrincipalName in the username field (e.g. firstname.lastname@company.com) and your Azure AD password in the password field.

You won't be able to change the Azure AD password from Jira/Confluence as the connection between Crowd and Azure AD is read-only.

Dhruv Khattar
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 12, 2019

Thanks Bruno... My issue was that the default login form just wasn't accepting my Azure AD username/password. I installed the AD SSO app, and that allows me to log in with my AD credentials.

Suggest an answer

Log in or Sign up to answer