Provision and sync users from an identity provider
Make changes in your identity provider to users and groups and sync them to your Atlassian organization.
When you want to disconnect Microsoft Azure AD from your Atlassian organization, you need to complete two steps:
Disconnect your Microsoft Account
Disconnect your identity provider
When you disconnect your Microsoft account from your Atlassian organization, users can log in with a third-party account or log in with Atlassian credentials after they reset their password. However, their details won't sync when you change their Microsoft accounts.
Before you can disconnect your Microsoft account, you need to stop enforcing users from logging in with single sign-on.
To stop enforcing single sign-on:
Go to admin.atlassian.com. Select your organization if you have more than one.
Navigate to Security > Identity provider > View policies.
Select Edit for the authentication policy you’d like to update.
Deselect enforce single sign-on.
Learn more about editing authentication policies
To disconnect your Microsoft account:
Navigate to Security > Identity providers and select your Identity provider directory.
Select View SAML configuration
Select Delete configuration.
Navigate to User provisioning, and select Edit.
Navigate to Disconnect Microsoft account, and select Disconnect account.
After you disconnect, we don't save any of your sync settings. You can start syncing your users again by setting up another connection to the same or a different Microsoft account.
After you disconnect, your previously synced users and groups maintain product access but lose the sync settings you applied.
When you delete an identity provider: we:
Delete its directory
Move the users from the directory to the default authentication policy in the local directory
Move any linked domains to the local directory
Before you can delete your identity provider, you need to:
Delete SAML configuration
Delete user provisioning configuration
Learn how to disconnect an identity provider
Was this helpful?