Provision and sync users from an identity provider
Make changes in your identity provider to users and groups and sync them to your Atlassian organization.
When you switch from Azure AD for nested groups to SCIM, you replace one identity provider option with another. You need to do this because you’re unable to use both options at the same time.
When you switch from Azure AD for nested groups to SCIM user provisioning, you retain product access for users and groups. We remove domains you synced or accounts you claimed from the domain. The amount of time it takes to complete the switch depends on the number of groups in your organization.
These are the steps you take to make the switch:
Delete SAML (if you set it up)
Disconnect your Microsoft account
Disconnect identity provider Azure AD for nested groups
You’re not required to verify domains and claim accounts when you switch to the SCIM option for Microsoft Azure. We recommend you verify at least one domain for the users you’d like to manage. When your users become managed accounts, you can apply single sign-on.
To remove Azure AD for nested groups:
Go to admin.atlassian.com. Select your organization if you have more than one.
Select Security > Identity providers.
Select your Identity provider Directory.
Select Delete SAML.
Select Disconnect Microsoft account.
Select Disconnect identity provider.
To see instructions for steps 4-6, go to:
After you’re done with steps 1-3, you can switch to the SCIM option for Microsoft Azure AD.
Delete SAML (if you set it up)
Disconnect your Microsoft account
Disconnect identity provider Azure AD for nested groups
These are the steps you take to connect Microsoft Azure AD SCIM:
Verify domains and claim accounts to set up SAML
Add and name your Microsoft Azure AD directory
Connect Microsoft Azure AD for SCIM to your Atlassian organization
To configure SCIM user provisioning:
Regenerate the API key for your directory.
Go to admin.atlassian.com. Select your organization if you have more than one.
Select Security > Identity providers.
Select your Identity provider Directory.
Select Set up user provisioning.
Copy the values for SCIM base URL and API key.
Save your SCIM configuration.
Update the API key in Azure AD and restart user provisioning:
In the Microsoft Azure platform that you used for SCIM user provisioning.
Update the API key.
Select Restart provisioning.
Learn more about how to configure user provisioning for Azure AD
Was this helpful?