Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Atlassian Cloud so that I can…
In brief
The tutorial received spelling and wording corrections across its SAML attribute mapping, authentication policy, testing, and account discovery sections.
What Entra admins need to know
No administrator action is required.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure Atlassian Cloud for Single sign-on with Microsoft Entra ID
In this article, you learn how to integrate Atlassian Cloud with Microsoft Entra ID. When you integrate Atlassian Cloud with Microsoft Entra ID, you can:
Scenario description
In this article, you configure and test Microsoft Entra SSO in a test environment.
- Atlassian Cloud supports SP and IDP initiated SSO.
- Atlassian Cloud supports Automatic user provisioning and deprovisioning.
On the Select a Single sign-on method page, select SAML.
On the Set up Single Sign-On with SAML page, scroll down to Set up Atlassian Cloud.
a. Select Configuration URLs.
b. Copy Login URL value from Azure portal, paste it in the Identity provider SSO URL textbox in Atlassian.
c. Copy Microsoft Entra Identifier value from Azure portal, paste it in the Identity provider Entity ID textbox in Atlassian.
On the Basic SAML Configuration section, perform the following steps.
a. Copy Service provider entity URL value from Atlassian, paste it in the Identifier (Entity ID) box in Azure and set it as default.
b. Copy Service provider assertion consumer service URL value from Atlassian, paste it in the Reply URL (Assertion Consumer Service URL) box in Azure and set it as default.
c. Select Next.
Your Atlassian Cloud application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. You can edit the attribute mapping by selecting Edit icon.
Attribute mapping for a Microsoft Entra tenant with a Microsoft 365 license.
a. Select the Unique User Identifier (Name ID) claim.
b. Atlassian Cloud expects the nameidentifier (Unique User Identifier) to be mapped to the user's email (user.mail). Edit the Source attribute and change it to user.mail. Save the changes to the claim.
c. The final attribute mappings should look as follows.
Attribute mapping for a Microsoft Entra tenant without a Microsoft 365 license.
a. Select the
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressclaim.
b. While Azure doesn't populate the user.mail attribute for users created in Microsoft Entra tenants without Microsoft 365 licenses and stores the email for such users in userprincipalname attribute. Atlassian Cloud expects the nameidentifier (Unique User Identifier) to be mapped to the user's email (user.userprincipalname). Edit the Source attribute and change it to user.userprincipalname. Save the changes to the claim.
c. The final attribute mappings should look as follows.
Select Stop and save SAML button.
To enforce SAML single sign-on in an authentication policy, perform the following steps.
a. From the Atlassian Admin Portal, select Security tab and select Authentication policies.
b. Select Edit for the policy you want to enforce.
c. In Settings, enable the Enforce single sign-on to their managed users for the successful SAML redirection.
d. Select Update.
Test SSO
In this section, you test your Microsoft Entra single sign-on configuration with following options.
SP initiated:
Select Test this application, this option redirects to Atlassian Cloud Sign-on URL where you can initiate the login flow.
Go to Atlassian Cloud Sign-on URL directly and initiate the login flow from there.
IDP initiated:
- Select Test this application, and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO.
You can also use Microsoft My Apps to test the application in any mode. When you select the Atlassian Cloud tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. For more information about the My Apps, see Introduction to the My Apps.
Discover existing users in Atlassian Cloud
Prior to integration with Microsoft Entra, your Atlassian account may already have one or more users. Using the account discovery functionality, you can generate a report of all the users in Atlassian Cloud, identify which users have matching accounts in Entra, and which users are local to Atlassian Cloud with one click. Learn more about the account discovery functionality here. This enables you to simplify onboarding to Entra, while also pereodicallyperiodically monitoring for unauthorized access.
Related content
@@ -5,7 +5,7 @@ ms.topic: how-to ms.date: 05/26/2026 ms.custom: sfi-image-nochange # Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Atlassian Cloud so that I can control who has access to Atlassian Cloud, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location.---- +--- # Configure Atlassian Cloud for Single sign-on with Microsoft Entra ID In this article, you learn how to integrate Atlassian Cloud with Microsoft Entra ID. When you integrate Atlassian Cloud with Microsoft Entra ID, you can:@@ -28,7 +28,7 @@ The scenario outlined in this article assumes that you already have the followin ## Scenario description -In this article, you configure and test Microsoft Entra SSO in a test environment. +In this article, you configure and test Microsoft Entra SSO in a test environment. * Atlassian Cloud supports **SP and IDP** initiated SSO. * Atlassian Cloud supports [Automatic user provisioning and deprovisioning](atlassian-cloud-provisioning-tutorial.md).@@ -80,11 +80,11 @@ Follow these steps to enable Microsoft Entra SSO. 1. On the **Select a Single sign-on method** page, select **SAML**. 1. On the **Set up Single Sign-On with SAML** page, scroll down to **Set up Atlassian Cloud**.- + a. Select **Configuration URLs**. b. Copy **Login URL** value from Azure portal, paste it in the **Identity provider SSO URL** textbox in Atlassian.- + c. Copy **Microsoft Entra Identifier** value from Azure portal, paste it in the **Identity provider Entity ID** textbox in Atlassian. @@ -100,62 +100,62 @@ Follow these steps to enable Microsoft Entra SSO. 1. On the **Basic SAML Configuration** section, perform the following steps. a. Copy **Service provider entity URL** value from Atlassian, paste it in the **Identifier (Entity ID)** box in Azure and set it as default.- + b. Copy **Service provider assertion consumer service URL** value from Atlassian, paste it in the **Reply URL (Assertion Consumer Service URL)** box in Azure and set it as default. c. Select **Next**.- +  - -1. Your Atlassian Cloud application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. You can edit the attribute mapping by selecting **Edit** icon. ++1. Your Atlassian Cloud application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. You can edit the attribute mapping by selecting **Edit** icon. - + 1. Attribute mapping for a Microsoft Entra tenant with a Microsoft 365 license.- + a. Select the **Unique User Identifier (Name ID)** claim. - + b. Atlassian Cloud expects the **nameidentifier** (**Unique User Identifier**) to be mapped to the user's email (**user.mail**). Edit the **Source attribute** and change it to **user.mail**. Save the changes to the claim. - + c. The final attribute mappings should look as follows. - - 1. Attribute mapping for a Microsoft Entra tenant without a Microsoft 365 license. ++ 1. Attribute mapping for a Microsoft Entra tenant without a Microsoft 365 license. a. Select the `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress` claim. - + b. While Azure doesn't populate the **user.mail** attribute for users created in Microsoft Entra tenants without Microsoft 365 licenses and stores the email for such users in **userprincipalname** attribute. Atlassian Cloud expects the **nameidentifier** (**Unique User Identifier**) to be mapped to the user's email (**user.userprincipalname**). Edit the **Source attribute** and change it to **user.userprincipalname**. Save the changes to the claim. - + c. The final attribute mappings should look as follows.  1. Select **Stop and save SAML** button.- +  1. To enforce SAML single sign-on in an authentication policy, perform the following steps. a. From the **Atlassian Admin** Portal, select **Security** tab and select **Authentication policies**. - b. Select **Edit** for the policy you want to enforce. + b. Select **Edit** for the policy you want to enforce. - c. In **Settings**, enable the **Enforce single sign-on** to their managed users for the successful SAML redirection. + c. In **Settings**, enable the **Enforce single sign-on** to their managed users for the successful SAML redirection. - d. Select **Update**. + d. Select **Update**. -  +  > [!NOTE] > The admins can test the SAML configuration by only enabling enforced SSO for a subset of users first on a separate authentication policy, and then enabling the policy for all users if there are no issues.@@ -178,22 +178,22 @@ To enable Microsoft Entra users sign in to Atlassian Cloud, provision the user a ### Test SSO -In this section, you test your Microsoft Entra single sign-on configuration with following options. +In this section, you test your Microsoft Entra single sign-on configuration with following options. #### SP initiated: -* Select **Test this application**, this option redirects to Atlassian Cloud Sign-on URL where you can initiate the login flow. +* Select **Test this application**, this option redirects to Atlassian Cloud Sign-on URL where you can initiate the login flow. * Go to Atlassian Cloud Sign-on URL directly and initiate the login flow from there. #### IDP initiated: -* Select **Test this application**, and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. +* Select **Test this application**, and you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. You can also use Microsoft My Apps to test the application in any mode. When you select the Atlassian Cloud tile in the My Apps, if configured in SP mode you would be redirected to the application sign-on page for initiating the login flow and if configured in IDP mode, you should be automatically signed in to the Atlassian Cloud for which you set up the SSO. For more information about the My Apps, see [Introduction to the My Apps](https://support.microsoft.com/account-billing/sign-in-and-start-apps-from-the-my-apps-portal-2f3b1bae-0e5a-4a86-a33e-876fbd2a4510). ## Discover existing users in Atlassian Cloud-Prior to integration with Microsoft Entra, your Atlassian account may already have one or more users. Using the account discovery functionality, you can generate a report of all the users in Atlassian Cloud, identify which users have matching accounts in Entra, and which users are local to Atlassian Cloud with one click. Learn more about the account discovery functionality [here](~/identity/app-provisioning/how-to-account-discovery.md). This enables you to simplify onboarding to Entra, while also pereodically monitoring for unauthorized access. +Prior to integration with Microsoft Entra, your Atlassian account may already have one or more users. Using the account discovery functionality, you can generate a report of all the users in Atlassian Cloud, identify which users have matching accounts in Entra, and which users are local to Atlassian Cloud with one click. Learn more about the account discovery functionality [here](~/identity/app-provisioning/how-to-account-discovery.md). This enables you to simplify onboarding to Entra, while also periodically monitoring for unauthorized access. ## Related content 