Configure SAML Encrypted Assertions for Microsoft Entra
Who can do this? |
Before you begin
Before you can enable SAML encrypted assertions for Microsoft Entra, make sure you’ve completed the following steps:
Connect to your Atlassian organization with an identity provider
Configure SAML for users to authenticate with single sign-on
Atlassian supports SAML encrypted assertions only for Microsoft Entra identity provider at this time.
What is SAML Encrypted assertions?
SAML encrypted assertions protect the confidentiality of sensitive user data passed during single sign-on (SSO) by ensuring that only the intended service provider, Atlassian, can read the contents.
It protects sensitive information like user IDs, email addresses, and personally identifiable information (PII) from exposure if network traffic is intercepted. It uses public key cryptography so that only the specific service provider, Atlassian, with the matching private key can decode the assertion payload.
Enable SAML Encrypted assertions
Once you’ve connected your Microsoft Entra identity provider to Atlassian and configured SAML for single sign-on, you can enable SAML encrypted assertions.
To enable SAML encrypted assertions:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security > User security > Identity providers.
Select your SAML configuration for Microsoft Entra.
Under Settings > Authentication, click View SAML Configuration.
Under Enable SAML assertion encryption click Enable
When the Enable SAML assertion encryption dialog is presented click Download certificate then Enable
Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption and import the certificate then activate the certificate
After completing these steps, SAML assertions sent to Atlassian will be encrypted.
Disable SAML Encrypted assertions
To disable SAML encrypted assertions:
Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption > Deactivate token
Warning: failure to deactivate token encryption certificate in Entra will result in failed SSO attempts by users with Atlassian cloud
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security > User security > Identity providers.
Select your SAML configuration for Microsoft Entra.
Under Settings > Authentication, click View SAML Configuration.
Using elipsis (…) in upper right corner choose Delete encryption certificate
Confirm deletion in the warning dialog by clicking Delete
After completing these steps, SAML assertions sent to Atlassian will no longer be encrypted.
Refresh SAML Encryption certificate
SAML encryption certificates will be available for refresh 3 months after creation. To refresh your SAML assertions certificate
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security > User security > Identity providers.
Select your SAML configuration for Microsoft Entra.
Under Settings > Authentication, click View SAML Configuration.
Using elipsis (…) in upper right corner choose Refresh encryption certificate
Confirm refresh in the warning dialog by clicking Refresh
Note: If a refresh is attempted less than 3 months after the active certificate was created it will error. Refreshes are only available 3 months after the activate certificate was createdScroll down to SAML encryption certificate section of page and download the new certificate
Go to Microsoft Entra, search for Atlassian Application then Security > Token encryption
Import the new certificate
Deactivate old certificate
Activate new certificate
Warning: failure to deactivate old certificate and activate the refreshed certificate in Entra will result in failed SSO attempts by users with Atlassian cloud
After completing these steps, SAML assertions sent to Atlassian will be encrypted with the refreshed certificate.
Was this helpful?