Configure SAML Encrypted Assertions for Microsoft Entra

Who can do this?
Role: Organization admin
Atlassian Cloud: Atlassian Guard Standard
Atlassian Government Cloud: Available

はじめる前に

Before you can enable SAML encrypted assertions for Microsoft Entra, make sure you’ve completed the following steps:

Connect to your Atlassian organization with an identity provider

Configure SAML for users to authenticate with single sign-on

Atlassian supports SAML encrypted assertions only for Microsoft Entra identity provider at this time.

What is SAML Encrypted assertions?

SAML encrypted assertions protect the confidentiality of sensitive user data passed during single sign-on (SSO) by ensuring that only the intended service provider, Atlassian, can read the contents.

It protects sensitive information like user IDs, email addresses, and personally identifiable information (PII) from exposure if network traffic is intercepted. It uses public key cryptography so that only the specific service provider, Atlassian, with the matching private key can decode the assertion payload.

Enable SAML Encrypted assertions

Once you’ve connected your Microsoft Entra identity provider to Atlassian and configured SAML for single sign-on, you can enable SAML encrypted assertions.

To enable SAML encrypted assertions:

  1. アトラシアンの管理に移動します。複数の組織がある場合は、対象の組織を選択します。

  2. Select Security > User security > Identity providers.

  3. Select your SAML configuration for Microsoft Entra.

  4. Under Settings > Authentication, click View SAML Configuration.

  5. Under Enable SAML assertion encryption click Enable

  6. When the Enable SAML assertion encryption dialog is presented click Download certificate then Enable

  7. Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption and import the certificate then activate the certificate

After completing these steps, SAML assertions sent to Atlassian will be encrypted.

Disable SAML Encrypted assertions

To disable SAML encrypted assertions:

  1. Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption > Deactivate token

    1. Warning: failure to deactivate token encryption certificate in Entra will result in failed SSO attempts by users with Atlassian cloud

  2. アトラシアンの管理に移動します。複数の組織がある場合は、対象の組織を選択します。

  3. Select Security > User security > Identity providers.

  4. Select your SAML configuration for Microsoft Entra.

  5. Under Settings > Authentication, click View SAML Configuration.

  6. Using elipsis (…) in upper right corner choose Delete encryption certificate

  7. Confirm deletion in the warning dialog by clicking Delete

After completing these steps, SAML assertions sent to Atlassian will no longer be encrypted.

Refresh SAML Encryption certificate

SAML encryption certificates will be available for refresh 3 months after creation. To refresh your SAML assertions certificate

  1. アトラシアンの管理に移動します。複数の組織がある場合は、対象の組織を選択します。

  2. Select Security > User security > Identity providers.

  3. Select your SAML configuration for Microsoft Entra.

  4. Under Settings > Authentication, click View SAML Configuration.

  5. Using elipsis (…) in upper right corner choose Refresh encryption certificate

  6. Confirm refresh in the warning dialog by clicking Refresh
    Note: If a refresh is attempted less than 3 months after the active certificate was created it will error. Refreshes are only available 3 months after the activate certificate was created

  7. Scroll down to SAML encryption certificate section of page and download the new certificate

  8. Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption

    1. Import the new certificate

    2. Deactivate old certificate

    3. Activate new certificate

    4. Warning: failure to deactivate old certificate and activate the refreshed certificate in Entra will result in failed SSO attempts by users with Atlassian cloud

After completing these steps, SAML assertions sent to Atlassian will be encrypted with the refreshed certificate.

 

さらにヘルプが必要ですか?

アトラシアン コミュニティをご利用ください。