Skip to content

Commit 5d751a6

Browse files
authored
Merge pull request #164159 from bhavana-129/attlasian-update
Product Backlog Item 1449827: SaaS App Tutorial: Atlassian Cloud Update
2 parents 40f63bc + 2b92caf commit 5d751a6

20 files changed

+57
-69
lines changed

articles/active-directory/saas-apps/atlassian-cloud-tutorial.md

Lines changed: 57 additions & 69 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ ms.service: active-directory
99
ms.subservice: saas-app-tutorial
1010
ms.workload: identity
1111
ms.topic: tutorial
12-
ms.date: 05/17/2021
12+
ms.date: 06/30/2021
1313
ms.author: jeedes
1414
---
1515
# Tutorial: Integrate Atlassian Cloud with Azure Active Directory
@@ -24,7 +24,7 @@ In this tutorial, you'll learn how to integrate Atlassian Cloud with Azure Activ
2424

2525
To get started, you need the following items:
2626

27-
* An Azure AD subscription. If you don't have a subscription, you can get one-month free trial [here](https://azure.microsoft.com/pricing/free-trial/).
27+
* An Azure AD subscription. If you don't have a subscription, you can get a [free account](https://azure.microsoft.com/free/).
2828
* Atlassian Cloud single sign-on (SSO) enabled subscription.
2929
* To enable Security Assertion Markup Language (SAML) single sign-on for Atlassian Cloud products, you need to set up Atlassian Access. Learn more about [Atlassian Access]( https://www.atlassian.com/enterprise/cloud/identity-manager).
3030

@@ -38,7 +38,7 @@ In this tutorial, you configure and test Azure AD SSO in a test environment.
3838
* Atlassian Cloud supports **SP and IDP** initiated SSO.
3939
* Atlassian Cloud supports [Automatic user provisioning and deprovisioning](atlassian-cloud-provisioning-tutorial.md).
4040

41-
## Adding Atlassian Cloud from the gallery
41+
## Add Atlassian Cloud from the gallery
4242

4343
To configure the integration of Atlassian Cloud into Azure AD, you need to add Atlassian Cloud from the gallery to your list of managed SaaS apps.
4444

@@ -55,13 +55,13 @@ Configure and test Azure AD SSO with Atlassian Cloud using a test user called **
5555

5656
To configure and test Azure AD SSO with Atlassian Cloud, perform the following steps:
5757

58-
1. **[Configure Azure AD with Atlassian Cloud SSO](#configure-azure-ad-sso)** - to enable your users to use Azure AD based SAML SSO with Atlassian Cloud.
58+
1. **[Configure Azure AD with Atlassian Cloud SSO](#configure-azure-ad-with-atlassian-cloud-sso)** - to enable your users to use Azure AD based SAML SSO with Atlassian Cloud.
5959
1. **[Create an Azure AD test user](#create-an-azure-ad-test-user)** - to test Azure AD single sign-on with B.Simon.
6060
1. **[Assign the Azure AD test user](#assign-the-azure-ad-test-user)** - to enable B.Simon to use Azure AD single sign-on.
6161
1. **[Create Atlassian Cloud test user](#create-atlassian-cloud-test-user)** - to have a counterpart of B.Simon in Atlassian Cloud that is linked to the Azure AD representation of user.
6262
1. **[Test SSO](#test-sso)** - to verify whether the configuration works.
6363

64-
### Configure Azure AD SSO
64+
## Configure Azure AD with Atlassian Cloud SSO
6565

6666
Follow these steps to enable Azure AD SSO in the Azure portal.
6767

@@ -75,88 +75,77 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
7575

7676
1. If you want to setup Atlassian Cloud manually, log in to your Atlassian Cloud company site as an administrator and perform the following steps.
7777

78-
1. Before you start go to your Atlassian product instance and copy/save the Instance URL
78+
1. Before you start go to your Atlassian product instance and copy/save the Instance URL.
7979
> [!NOTE]
80-
> url should fit `https://<instancename>.atlassian.net` pattern
80+
> url should fit `https://<INSTANCE>.atlassian.com` pattern.
8181
82-
![instance name](./media/atlassian-cloud-tutorial/get-atlassian-instance-name.png)
82+
![Instance Name](./media/atlassian-cloud-tutorial/instance.png)
8383

84-
1. Open the [Atlassian Admin Portal](https://admin.atlassian.com/) and click on your organization name
84+
1. Open the [Atlassian Admin Portal](https://admin.atlassian.com/) and click on your organization name.
8585

86-
![organization](./media/atlassian-cloud-tutorial/click-on-organization-in-atlassian-access.png)
86+
![Admin Portal](./media/atlassian-cloud-tutorial/organization.png)
8787

8888
1. You need to verify your domain before going to configure single sign-on. For more information, see [Atlassian domain verification](https://confluence.atlassian.com/cloud/domain-verification-873871234.html) document.
89-
1. From the Atlassian Admin Portal Screen select **Security** from the left drawer
9089

91-
![security](./media/atlassian-cloud-tutorial/click-on-security-in-atlassian-access.png)
90+
1. In the **ATLASSIAN Admin** portal, navigate to **Security** tab, select **SAML single sign-on** and click **Add SAML configuration**.
9291

93-
1. From the Atlassian Admin Portal Security Screen select **SAML single sign** on from the left drawer
92+
![Security](./media/atlassian-cloud-tutorial/admin.png)
9493

95-
![saml sso](./media/atlassian-cloud-tutorial/click-on-saml-sso-in-atlassian-access-security.png)
94+
1. In the **Add SAML configuration** section, fill the required fields which you have copied from the Azure portal and click **Save configuration**.
9695

97-
1. Click on **Add SAML Configuration** and keep the page open
98-
99-
![Add SAML Configuration](./media/atlassian-cloud-tutorial/saml-configuration-in-atlassian-access-security-saml-sso.png)
100-
101-
![Add SAML Configuration 2](./media/atlassian-cloud-tutorial/add-saml-configuration.png)
96+
![Add SAML Configuration](./media/atlassian-cloud-tutorial/configuration.png)
10297

10398
1. In the Azure portal, on the **Atlassian Cloud** application integration page, find the **Manage** section and select **Set up single sign-on**.
10499

105-
![set up sso](./media/atlassian-cloud-tutorial/set-up-sso.png)
100+
![Set up sso](./media/atlassian-cloud-tutorial/set-up.png)
106101

107102
1. On the **Select a Single sign-on method** page, select **SAML**.
108103

109-
![saml in azure](./media/atlassian-cloud-tutorial/saml-in-azure.png)
104+
![SAML in azure](./media/atlassian-cloud-tutorial/azure.png)
110105

111-
1. On the **Set up Single Sign-On with SAML** page, scroll down to **Set Up Atlassian Cloud**
106+
1. On the **Set up Single Sign-On with SAML** page, scroll down to **Set Up Atlassian Cloud**.
112107

113-
a. Click on **Configuration URLs**
108+
a. Click on **Configuration URLs**.
114109

115-
![urls](./media/atlassian-cloud-tutorial/configuration-urls.png)
110+
![Single Sign-On](./media/atlassian-cloud-tutorial/configure.png)
116111

117-
b. Copy **Azure AD Identifier** value from Azure portal, paste it in the **Identity Provider Entity ID** textbox in Atlassian
112+
b. Copy **Azure AD Identifier** value from Azure portal, paste it in the **Identity Provider Entity ID** textbox in Atlassian.
118113

119-
c. Copy **Login URL** value from Azure portal, paste it in the **Identity Provider SSO URL** textbox in Atlassian
114+
c. Copy **Login URL** value from Azure portal, paste it in the **Identity Provider SSO URL** textbox in Atlassian.
120115

121-
![Identity Provider SSO URL](./media/atlassian-cloud-tutorial/configuration-urls-azure.png)
116+
![Identity Provider SSO URL](./media/atlassian-cloud-tutorial/configuration-azure.png)
122117

123-
![entity id and ss](./media/atlassian-cloud-tutorial/entity-id-and-ss.png)
118+
![Entity id](./media/atlassian-cloud-tutorial/login.png)
124119

125120
1. On the **Set up Single Sign-On with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate and save it on your computer.
126121

127122
![signing Certificate](./media/atlassian-cloud-tutorial/certificate.png)
128123

129-
![Certificate 1](./media/atlassian-cloud-tutorial/certificate-1.png)
124+
![Certificate 1](./media/atlassian-cloud-tutorial/certificate-download.png)
130125

131-
1. **Add/Save** the SAML Configuration in Atlassian
126+
1. **Add** and **Save** the SAML Configuration in Atlassian.
132127

133-
1. If you wish to configure the application in **IDP** initiated mode, edit the **Basic SAML Configuration** section of the **Set up Single Sign-On with SAML** page in Azure and open the **SAML single sign-on page** on the Atlassian Admin Portal
128+
1. On the **Basic SAML Configuration** section, perform the following steps.
134129

135-
a. Copy **SP Entity ID** value from Atlassian, paste it in the **Identifier (Entity ID)** box in Azure and set it as default
130+
a. Copy **SP Entity ID** value from Atlassian, paste it in the **Identifier (Entity ID)** box in Azure and set it as default.
136131

137-
b. Copy **SP Assertion Consumer Service URL** value from Atlassian, paste it in the **Reply URL (Assertion Consumer Service URL)** box in Azure and set it as default
132+
b. Copy **SP Assertion Consumer Service URL** value from Atlassian, paste it in the **Reply URL (Assertion Consumer Service URL)** box in Azure and set it as default.
138133

139-
c. Copy your **Instance URL** value, which you copied at step 1 and paste it in the **Relay State** box in Azure
140-
141-
![copy urls](./media/atlassian-cloud-tutorial/copy-urls.png)
134+
c. Copy your **Instance URL** value, which you copied at step 4 and paste it in the **Relay State** box in Azure.
142135

143-
![edit button](./media/atlassian-cloud-tutorial/edit-button.png)
144-
145-
![urls image](./media/atlassian-cloud-tutorial/urls.png)
146-
147-
1. If you wish to configure the application in **SP** initiated mode, edit the **Basic SAML Configuration** section of the **Set up Single Sign-On with SAML** page in Azure. Copy your **Instance URL** (from step 1) and paste it in the **Sign On URL** box in Azure
136+
![Copy URLs](./media/atlassian-cloud-tutorial/values.png)
148137

149-
![edit button in urls](./media/atlassian-cloud-tutorial/edit-button.png)
138+
![Button](./media/atlassian-cloud-tutorial/edit-button.png)
150139

151-
![sign-on url](./media/atlassian-cloud-tutorial/sign-on-URL.png)
140+
![URLs image](./media/atlassian-cloud-tutorial/image.png)
152141

153142
1. Your Atlassian Cloud application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. You can edit the attribute mapping by clicking on **Edit** icon.
154143

155144
![attributes](./media/atlassian-cloud-tutorial/edit-attribute.png)
156145

157-
1. Attribute mapping for an Azure AD tenant with a Microsoft 365 license
146+
1. Attribute mapping for an Azure AD tenant with a Microsoft 365 license.
158147

159-
a. Click on the **Unique User Identifier (Name ID)** claim
148+
a. Click on the **Unique User Identifier (Name ID)** claim.
160149

161150
![attributes and claims](./media/atlassian-cloud-tutorial/user-attributes-and-claims.png)
162151

@@ -166,25 +155,34 @@ Follow these steps to enable Azure AD SSO in the Azure portal.
166155

167156
c. The final attribute mappings should look as follows.
168157

169-
![image 2](./media/atlassian-cloud-tutorial/default-attributes-1.png)
158+
![image 2](./media/atlassian-cloud-tutorial/attributes.png)
170159

171-
1. Attribute mapping for an Azure AD tenant without a Microsoft 365 license
160+
1. Attribute mapping for an Azure AD tenant without a Microsoft 365 license.
172161

173162
a. Click on the `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress` claim.
174163

175-
![image 3](./media/atlassian-cloud-tutorial/email-address.png)
164+
![image 3](./media/atlassian-cloud-tutorial/claims.png)
176165

177166
b. While Azure does not populate the **user.mail** attribute for users created in Azure AD tenants without Microsoft 365 licenses and stores the email for such users in **userprincipalname** attribute. Atlassian Cloud expects the **nameidentifier** (**Unique User Identifier**) to be mapped to the user's email (**user.userprincipalname**). Edit the **Source attribute** and change it to **user.userprincipalname**. Save the changes to the claim.
178167

179-
![set email](./media/atlassian-cloud-tutorial/set-email.png)
168+
![Set email](./media/atlassian-cloud-tutorial/save-claims.png)
180169

181170
c. The final attribute mappings should look as follows.
182171

183-
![image 4](./media/atlassian-cloud-tutorial/default-attributes-2.png)
172+
![image 4](./media/atlassian-cloud-tutorial/final-attributes.png)
173+
174+
1. To enforce SAML single sign-on in an authentication policy, perform the following steps.
175+
176+
a. From the **Atlassian Admin** Portal, select **Security** tab and click **Authentication policies**.
177+
178+
b. Select **Edit** for the policy you want to enforce.
179+
180+
c. In **Settings**, enable the **Enforce single sign-on** to their managed users for the successful SAML redirection.
181+
182+
d. Click **Update**.
183+
184+
![Authentication policies](./media/atlassian-cloud-tutorial/policy.png)
184185

185-
> [!NOTE]
186-
> You can set multiple security policies by selecting **Authentication policies** option from the left drawer. An authentication policy allows you to specify authentication settings for different sets of users and configurations in your organization. It verifies that users who access the Atlassian organization are genuine. For more information, please refer [Authentication policies](https://support.atlassian.com/security-and-access-policies/docs/understand-authentication-policies/).
187-
188186
### Create an Azure AD test user
189187

190188
In this section, you'll create a test user in the Azure portal called B.Simon.
@@ -211,24 +209,15 @@ In this section, you'll enable B.Simon to use Azure single sign-on by granting a
211209

212210
### Create Atlassian Cloud test user
213211

214-
To enable Azure AD users to sign in to Atlassian Cloud, provision the user accounts manually in Atlassian Cloud by doing the following:
215-
216-
1. In the **Administration** pane, select **Users**.
217-
218-
![The Atlassian Cloud Users link](./media/atlassian-cloud-tutorial/tutorial-atlassiancloud-14.png)
212+
To enable Azure AD users sign in to Atlassian Cloud, provision the user accounts manually in Atlassian Cloud by doing the following steps:
219213

220-
1. To create a user in Atlassian Cloud, select **Invite user**.
214+
1. Go to **Products** tab, select **Users** and click **Invite users**.
221215

222-
![Create an Atlassian Cloud user](./media/atlassian-cloud-tutorial/tutorial-atlassiancloud-15.png)
216+
![The Atlassian Cloud Users link](./media/atlassian-cloud-tutorial/users.png)
223217

224-
1. In the **Email address** box, enter the user's email address, and then assign the application access.
218+
1. In the **Email address** textbox, enter the user's email address, and then click **Invite user**.
225219

226-
![Atlassian Cloud user](./media/atlassian-cloud-tutorial/tutorial-atlassiancloud-16.png)
227-
228-
1. To send an email invitation to the user, select **Invite users**. An email invitation is sent to the user and, after accepting the invitation, the user is active in the system.
229-
230-
> [!NOTE]
231-
> You can also bulk-create users by selecting the **Bulk Create** button in the **Users** section.
220+
![Create an Atlassian Cloud user](./media/atlassian-cloud-tutorial/invite-users.png)
232221

233222
### Test SSO
234223

@@ -242,11 +231,10 @@ In this section, you test your Azure AD single sign-on configuration with follow
242231

243232
#### IDP initiated:
244233

245-
* Click on **Test this application** in Azure portal and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO
234+
* Click on **Test this application** in Azure portal and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO.
246235

247236
You can also use Microsoft My Apps to test the application in any mode. When you click the Atlassian Cloud tile in the My Apps, if configured in SP mode you would be redirected to the application sign on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](../user-help/my-apps-portal-end-user-access.md).
248237

249-
250238
## Next steps
251239

252240
Once you configure Atlassian Cloud you can enforce session control, which protects exfiltration and infiltration of your organization's sensitive data in real time. Session control extends from Conditional Access. [Learn how to enforce session control with Microsoft Cloud App Security](/cloud-app-security/proxy-deployment-any-app).
93.6 KB
Loading
11 KB
Loading
76.4 KB
Loading
36.8 KB
Loading
38.6 KB
Loading
32.8 KB
Loading
59.5 KB
Loading
23.3 KB
Loading
8.66 KB
Loading

0 commit comments

Comments
 (0)