Microsoft Entra ID
General

Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Atlassian Cloud so that I can…

In brief

The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.

What Entra admins need to know

No administrator action is required.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


Configure Atlassian Cloud for Single sign-on with Microsoft Entra ID

In this article, you learn how to integrate Atlassian Cloud with Microsoft Entra ID. When you integrate Atlassian Cloud with Microsoft Entra ID, you can:

Scenario description

In this article, you configure and test Microsoft Entra SSO in a test environment.

  1. On the Select a Single sign-on method page, select SAML.

  2. On the Set up Single Sign-On with SAML page, scroll down to Set up Atlassian Cloud.

    a. Select Configuration URLs.

    b. Copy Login URL value from Azure portal, paste it in the Identity provider SSO URL textbox in Atlassian.

    c. Copy Microsoft Entra Identifier value from Azure portal, paste it in the Identity provider Entity ID textbox in Atlassian.

    Screenshot shows the Configuration values.

  3. On the Basic SAML Configuration section, perform the following steps.

    a. Copy Service provider entity URL value from Atlassian, paste it in the Identifier (Entity ID) box in Azure and set it as default.

    b. Copy Service provider assertion consumer service URL value from Atlassian, paste it in the Reply URL (Assertion Consumer Service URL) box in Azure and set it as default.

    c. Select Next.

    Screenshot shows the Service provider images.

    Screenshot shows the Service provider Values.

  4. Your Atlassian Cloud application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. You can edit the attribute mapping by selecting Edit icon.

    attributes

    1. Attribute mapping for a Microsoft Entra tenant with a Microsoft 365 license.

      a. Select the Unique User Identifier (Name ID) claim.

      attributes and claims

      b. Atlassian Cloud expects the nameidentifier (Unique User Identifier) to be mapped to the user's email (user.mail). Edit the Source attribute and change it to user.mail. Save the changes to the claim.

      unique user ID

      c. The final attribute mappings should look as follows.

      image 2

    2. Attribute mapping for a Microsoft Entra tenant without a Microsoft 365 license.

      a. Select the http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress claim.

      image 3

      b. While Azure doesn't populate the user.mail attribute for users created in Microsoft Entra tenants without Microsoft 365 licenses and stores the email for such users in userprincipalname attribute. Atlassian Cloud expects the nameidentifier (Unique User Identifier) to be mapped to the user's email (user.userprincipalname). Edit the Source attribute and change it to user.userprincipalname. Save the changes to the claim.

      Set email

      c. The final attribute mappings should look as follows.

      image 4

  5. Select Stop and save SAML button.

    Screenshot shows the image of saving configuration.

  6. To enforce SAML single sign-on in an authentication policy, perform the following steps.

    a. From the Atlassian Admin Portal, select Security tab and select Authentication policies.

    b. Select Edit for the policy you want to enforce.

    c. In Settings, enable the Enforce single sign-on to their managed users for the successful SAML redirection.

    d. Select Update.

    Screenshot showing Authentication policies.

Test SSO

In this section, you test your Microsoft Entra single sign-on configuration with following options.

SP initiated:

  • Select Test this application, this option redirects to Atlassian Cloud Sign-on URL where you can initiate the login flow.

  • Go to Atlassian Cloud Sign-on URL directly and initiate the login flow from there.

IDP initiated:

  • Select Test this application, and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO.

You can also use Microsoft My Apps to test the application in any mode. When you select the Atlassian Cloud tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. For more information about the My Apps, see Introduction to the My Apps.

Discover existing users in Atlassian Cloud

Prior to integration with Microsoft Entra, your Atlassian account may already have one or more users. Using the account discovery functionality, you can generate a report of all the users in Atlassian Cloud, identify which users have matching accounts in Entra, and which users are local to Atlassian Cloud with one click. Learn more about the account discovery functionality here. This enables you to simplify onboarding to Entra, while also pereodicallyperiodically monitoring for unauthorized access.

Related content

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…