miniOrange Logo

Products

Services

Plugins

Pricing

Resources

Company

Enable Jira 2FA for Customers and skip for Employees

miniOrangeAuthor
7th July, 20265 Min Read

Credential abuse is the common vector in 13% of data breaches. Cybercriminals can gain access to sensitive organizational data through weak, stolen, or reused passwords belonging to employees or customers.

Single sign-on (SSO) and Multi-Factor Authentication (MFA) are industry-standard solutions for addressing these issues, and they can help to mitigate security threats.

But external Jira Service Management (JSM) customers often authenticate differently.

If Jira's built-in 2FA is enforced for everyone, employees who are already authenticating through an IdP may be prompted for MFA twice.

If it is disabled, customer portals may be left without MFA protection.

This guide will walk you through how to secure the accounts of both your employees (Internal Users) and JSM customers (External Users) in your Data Center instance.

The Authentication Challenge in Jira and Jira Service Management

Most organizations manage two very different user groups inside Jira DC environments.

Internal Users: Employees, Admins, and Agents

These users typically include:

  • Jira administrators
  • Developers
  • Service desk agents
  • Employees
  • Internal stakeholders

Their authentication flow usually looks like this:

Identity Provider → SSO → MFA → Jira

Authentication is commonly managed through:

  • SAML SSO
  • OAuth/OIDC SSO
  • Corporate Identity Providers

Examples include:

  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • OneLogin
  • Ping Identity

Since MFA is already enforced at the IdP level, internal users are already protected.

External Users: JSM Customers

JSM customer portals often serve:

  • Customers
  • Vendors
  • Contractors
  • Partners
  • External support requesters

These users may not authenticate through your corporate IdP.

As a result, admins face a common challenge:

How do you secure customer portal access without forcing employees to complete MFA twice?

How to Secure Your Customers with 2FA?

The miniOrange Two-Factor Authentication app for Jira Data Center allows you to selectively enforce Jira 2FA for external customers. Instead of enabling MFA for everyone, you can target:

  • Specific users
  • User groups
  • Customer-only accounts
  • Service desk users
  • IP-based access conditions

You can enable Jira 2FA for customers while exempting employees.

Supported Authentication Methods

You can choose from 9+ authentication methods:

  • Mobile Authenticator
  • YubiKey Hardware Token
  • Duo Push Notification
  • WebAuthn (FIDO2)
  • OTP Over Email
  • OTP Over SMS
  • Security Questions
  • Out of Band Email
  • Backup Codes

You can also configure primary and backup authentication methods.

Step 1: Install and Configure Jira 2FA

Install the miniOrange Two-Factor Authentication app for Jira Data Center.

After installation:

  • Open basic configuration.
  • Select your preferred 2FA methods.
  • Enable required authentication options.
  • Configure backup methods.

You can choose which methods are available across the organization.

Step 2: Create Customer-Only MFA Policies

The app supports granular enforcement policies.

You can:

  • Enable 2FA for specific customer groups
  • Enforce MFA for portal users
  • Exclude employee groups
  • Manage policies individually or in bulk

Example policy:

Enable 2FA for:
portal-customers

Skip 2FA for:
employees
jira-admins
service-desk-agents

This prevents duplicate verification for internal users already authenticating through SSO.

Step 3: Configure User Experience and Recovery Option{#step-3-configure-user-experience-and-recovery}

You can configure settings that reduce user friction and minimize support overhead:

Remember Device

You can allow trusted devices to bypass repeated verification for a configurable period. This reduces authentication fatigue for returning users.

Backup Authentication Methods

Provide fallback authentication using backup codes or secondary authentication methods. This prevents users from getting locked out.

User Flow Controls

Admins can configure:

  • Primary authentication method enforcement
  • Method selection at login
  • User self-reconfiguration
  • Additional method registration

Step 4: Validate Login Flows

Before production rollout, test authentication across user types.

Validate:

Employee Login Flow

Employee → IdP Login → MFA → SSO → Jira

No additional Jira MFA challenge.

Customer Login Flow

Customer → Jira Login → 2FA Verification → Portal Access

Security remains enforced where it matters most.

Advanced Authentication Policies for Jira

The miniOrange 2FA for Jira app supports advanced policy configurations so you can set different authentication rules for users.

Skip 2FA on SSO

This is one of the most valuable capabilities for mixed environments.

Users who authenticate through SSO, be it SAML or OAuth/OIDC, can bypass 2FA. This avoids duplicate MFA enforcement for employees.

IP-Based Conditional Authentication

You can apply location-aware policies.

For example, admins can whitelist trusted office IP ranges so users logging in from those locations can bypass 2FA.

Group-Based Authentication Rules

You can set different security policies for different user groups.

Group Authentication Method
Employees WebAuthn / IdP MFA
Customers Email OTP
Admins Hardware Token
Contractors TOTP

You can restrict 2FA methods per group.

One-Time Validation Across Atlassian Applications

Encountering 2FA for every Atlassian app can create friction. There's a way to simplify this.

With one-time validation, users who validate once for any app can access connected Atlassian apps without repeated 2FA prompts.

Common Jira 2FA Deployment Use Cases

The miniOrange Jira 2FA solution supports multiple real-world deployment models.

2FA for Customers + SSO for Employees

Employees authenticate through: SSO + IdP MFA

Customers authenticate through: Jira-native 2FA

2FA for All Users

Protect everyone with centralized Jira MFA policies.

Agent-Only MFA

Enforce 2FA specifically for:

  • Service desk agents
  • Support teams
  • Privileged operational users

Remote Access MFA

Require MFA only for users logging in outside trusted environments.

Conclusion

Security doesn't have to be synonymous with friction and inconvenience.

With miniOrange, you can choose both security and a good user experience.

With the right configuration, you can:

  • Secure JSM customers with 2FA
  • Allow employees to continue using SSO + IdP MFA
  • Avoid duplicate authentication prompts
  • Implement flexible, policy-driven authentication controls

What you need is a targeted approach to Jira authentication to secure access without adding complexity.

Try the miniOrange 2FA for Jira app on the Atlassian Marketplace →

Frequently Asked Questions

1. Can I enable Jira 2FA only for Jira Service Management customers?

Yes. The miniOrange Jira 2FA app allows admins to enable 2FA for a specific subset of users, including:

  • Jira Service Management customers
  • Portal-only users
  • External users
  • Selected groups or individual accounts

You can enforce 2FA for customers while excluding employees or service agents.

2. How do I skip Jira 2FA for employees using SSO?

You can use the Skip 2FA on SSO feature.

If employees authenticate through a supported SSO flow, such as SAML or OAuth/OIDC, they can bypass Jira-native 2FA after successful Identity Provider authentication.

This prevents duplicate MFA challenges for internal users already protected by IdP MFA.

3. Can I restrict JSM customer portal access based on groups or organizations?

Yes Admins can configure:

  • Portal Access Mapping
  • Organization Mapping
  • IDP Group Restrictions
  • Email-domain-based mapping

This ensures only authorized users can access specific Jira Service Management portals.

Leave a Comment