Step 2. Set up SSO between Atlassian Guard and miniOrange App

After saving the OAuth Configuration, you’ll be required to configure Atlassian Guard and the miniOrange OAuth/OIDC SSO App.

  • A pop-up notification will appear, asking you to complete the Atlassian Guard configuration.
  • Pop-up notification asking to complete the Atlassian Guard configuration
  • Click on Configure Guard, and you will be navigated to the Guard Configurations section.
  • In this section, you will find the Plugin Metadata details.
  • Copy and keep the following values handy. You’ll need them while setting up your Identity Provider in Atlassian Guard:
    • IDP Entity ID
    • IDP SSO URL
    • IDP Public X.509 Certificate
    • Atlassian Guard configurations page where Plugin Metadata details can be found
    1. Open the Atlassian Admin Console and navigate to the Security tab.
    2. Note: In case you manage multiple organizations, you’ll have to select the intended one after accessing the admin console.
    3. Under User Security, click Identity Providers.
    4. Select Other to begin configuring a custom Identity Provider.
    5. Atlassian Guard security page where Identity Providers section can be found
  • Provide an appropriate name, select Set up SAML Single Sign-On, and click Next.
  • Now, paste the IDP Entity ID, IDP SSO URL, and Public X.509 Certificate that you copied from the plugin configuration.
  • Atlassian Guard configurations page where IDP Entity ID, IDP SSO URL, and Public X.509 Certificate can be pasted
  • Click Next and copy the Service Provider Entity ID and Service Provider Assertion Consumer Service URL. Keep these handy as they’re required to complete the plugin configuration.
  • Complete the rest of the Atlassian Guard configuration.
  • Once you’re done, return to the plugin, go to the SP Metadata tab in the Guard Configurations section, and click Next.
  • Enter the SP Entity ID and Assertion Consumer Service (ACS) URL that you copied, and click Save Settings.
  • Atlassian Guard configurations page where SP Metadata tab can be found

Step 3. Configure SSO Authentication Policy

After completing your SSO configuration, you must assign users to the Authentication Policy and enforce Single Sign-On (SSO).

  • Go to your Atlassian Cloud Admin Console.
  • Navigate to SecurityAuthentication Policies.
  • Open the Authentication Policy you configured for SSO.
  • Enable the Enforce Single Sign-On (SSO) option and save the changes.
  • Jira Cloud users in SSO directory
  • Now go to the Members section and add the users or groups who should authenticate using this policy.
  • Save your changes.

Once these steps are complete, return to the app and Mark as Complete to complete the setup.

Jira Cloud complete policy step
Note: Only users added to the Authentication Policy will be able to sign in to Atlassian Cloud using your configured Identity Provider (IdP).