SAML Single Sign On Setup Guides for SAML SSO Current: Azure AD B2C Azure AD B2C Below, you find information to set up Azure AD B2C and our apps. If you need help or have questions, you can contact us via our helpdesk or book a free screen share session at https://resolution.de/go/calendly.Step-By-Step GuidesBased on your user provisioning model, pick one of the following step-by-step guides.In most cases, we recommend using Azure AD B2C with User Sync.Azure AD B2C with User SyncSetting up User synchronization with Azure AD B2C, as well as authentication via SAMLAzure AD B2C with Just-in-Time ProvisioningSetting up authentication via SAML with Azure AD B2C and using Just-in-Time Provisioning to create/update user accounts during login.Azure AD B2C with Manual ProvisioningSetting up authentication via SAML with Azure AD B2C for users that already exist in the Atlassian product.Some important notes:User Sync functionality is currently only available for Jira, Confluence, Bitbucket & Bamboo.Fisheye only supports Manual User Management. Which Step-By-Step Guide You Should Pick?Depending on your Atlassian product, you can choose from different user provisioning models. We recommend using User Sync, since it is easy to set up and maintain. In general, with Azure AD B2C we support the following ways for user provisioning:User Sync allows to sync users periodically from Azure AD B2C, but also when they log in for the first time into your Atlassian product. See our detailed article for User Sync.Just in Time Provisioning allows to create and update users on-the-fly when they log in. A drawback for syncing groups from Azure is, that only group ids and no group names are sent. See our detailed article for JIT.LDAP synchronization from Active Directory. If your instance is still synchronized to your Active Directory via LDAP, you can continue to do so. Please follow the "Manual User Management" guide in this scenario.For Manual User Management, the administrator has to create and update users on Azure and your Atlassian product by hand. We do not recommend it. See our article for Manual User Management.Model/FunctionAdmin EffortPro's and Con'sUser SyncLowUses Azure API to perform regular syncUsers and Groups are created & updated shortly after done in Azure AD B2CUsers can be disabledAdditional attributes can be written to Jira User PropertiesJust in Time ProvisioningLow, if no groupsHigh, with Groups from Azure(Needs setting up group transformation rules).Creates & updates users based on information in the SAML Response during LoginUsers are only created on their first Login.Users & Groups are updated only during SAML authentication.Users cannot be marked disabled (as Azure will not complete the Authentication for a deleted/disabled User)Azure AD B2C only sends group IDs in SAML messages, not friendly names. This requires the setup of group transformation rules or acceptance of cryptic group names in the Atlassian application.Manual User ManagementHigh Here no sync happensNeeds manual maintenance of two user bases (or is done via custom developments) SAML Single Sign-On is available for Atlassian Server & Atlassian Data Center products. Our Jira Data Center, Confluence Data Center, Bitbucket Data Center, Jira Server, Confluence Server, Bitbucket Server and other apps are all available on the Atlassian Marketplace.