Configure provisioning for Atlassian with Zoho Directory
User provisioning with Atlassian enables you to provision and deprovision users in Atlassian from the Zoho Directory Admin Panel, enabling you to use Zoho Directory as a single source of truth. To get the most out of this integration, you can also set up single sign-on (SSO). SSO allows your organization's users to easily access Atlassian without having to sign in to it separately.
Prerequisite
-
Roles required to perform this action:
- Organization Owner
- Organization Admin
- Permissions required to perform this action:
- View apps
- Assign apps
- Import users
- Other prerequisites
- A verified domain in Atlassian
- An Atlassian Access subscription
- Admin role in at least one Jira or Confluence site
In Atlassian: Enable SCIM and generate token
-
Sign in to your Atlassian admin console. If you have more than one organization, select one.
-
Go to Security, then click Identity providers.
-
Click Add identity provider.
-
Select "Other Provider" under Identity Provider, and enter "Zoho Directory" in the Directory Name field, then click Add.
-
Click Set up user provisioning, then click Next.
-
Copy the SCIM base URL and the API Key. They will be used in Zoho Directory to set up provisioning.
-
Click Next.
-
Click Stop and save SCIM configuration.
-
Go to Settings, then click Domains.
-
Add and verify a domain that has also been verified in Zoho Directory.
-
Go back to the Identity Providers screen, and click on the identity provider you just added.
-
Click View domains, then click Link domain.
-
Select the domain you just added, then click Next.
-
Click Move domains.
In Zoho Directory: Set up provisioning
-
Sign in to Zoho Directory
, then click Admin Panel.
-
Go to Applications, then click on Atlassian.
-
Go to Provisioning, then click Configure.
-
Enter the SCIM base URL and the API Key you copied from Atlassian in the Sync endpoint and SCIM Token fields.
-
Click Authorize.
-
Select the fields that have to be synced with Atlassian, and map a relevant Zoho Directory field with them. If you'd like to have a constant value to be set in Atlassian for any field, click Edit next to the field, enter the value in the Hardcoded value field, then click OK.
Note: By default, all Atlassian fields will be mapped to a relevant Zoho Directory field. To change this mapping, you should have the Standard or Professional plans in Zoho Directory.
-
Click Save and Next.
- Choose which of the changes made in Zoho Directory have to be synced with Atlassian:
- Create users: Assigning a user to Atlassian in Zoho Directory automatically creates a new user account in Atlassian.
- Update User profile: If a user account already exists in Atlassian for a user, any changes made to the mapped fields in the user's profile in ZD will be synced with Atlassian.
- Delete Users: Unassigning Atlassian for the user from ZD will delete the user's account in Atlassian.
- Activate and deactivate Users: If a user account already exists in Atlassian for a user, assigning them to Atlassian in ZD or unassigning them will activate or deactivate the user in Atlassian. Additionally, activating or deactivating a user in ZD will also activate or deactivate them in Atlassian.
- Click Save.
- If you'd like to have the users currently in Atlassian to be imported to ZD, click Import. It is advisable to import users to ZD during initial setup or when activating the app after a while. A list of users that can be imported will be displayed.
- The following filters can be used to select users to import:
- All Users: All the users that can be imported from Atlassian to ZD.
- New Users: Users that are present in Atlassian, but not in ZD. These users will be created in ZD, and Atlassian will be assigned to them.
- Update User: Users already present in ZD. Any changes in the user profile for these users will not be synced, and the field values from Atlassian will be used to overwrite the values in ZD.
- Users to Activate: Users in ZD, but not assigned to Atlassian in ZD. These users will be assigned to Atlassian.
- Users to Deactivate: Users that are either not present or present as inactive users in Atlassian. These users will be unassigned from Atlassian in ZD.
- Click Confirm Assignment.
- Click Done.