Atlassian Guard protects your employees through SSO and MFA. It does not cover portal-only customer accounts.
However, customers need to access your Jira Service Management (JSM) portal to raise tickets and do so securely. But they often use portal-only accounts, which, in most cases, are protected only by a password.
You’ll have security gaps if they don’t authenticate the same way as your employees. You must understand what the limits of Atlassian Guard are.
You need dedicated 2FA for JSM Cloud portal customers to add the necessary extra layer of security while leaving employee SSO and authentication unchanged. In this blog, we’ll explore how the miniOrange MFA/2FA for JSM Cloud app can help you do just that.
Why Is Securing JSM Portal Customers Different?
Atlassian authentication policies are designed for Atlassian accounts like employees, agents, admins, and other licensed Jira users.
Portal customers work quite differently.
They use portal-only accounts that let them submit and track requests without requiring a licensed Atlassian account. And they manage the account themselves. You can’t enforce MFA using native Atlassian features.
This is why Atlassian Guard portal-only customers remain outside your organization's authentication policies.
What Is a Portal-Only Account?
A portal-only account allows external users to submit and track requests in Jira Service Management without having a licensed Atlassian account. These accounts are generally used by customers, vendors, contractors, and partners.
Unlike licensed users, portal customers manage their own accounts. Because of this, administrators can't require MFA through native Atlassian controls.
Here's how the two account types compare.
| Licensed Users | Portal Customers | |
|---|---|---|
| Account type | Atlassian account | Portal-only account |
| Default protection | Protected by Atlassian Guard or native 2SV | Password only by default |
| MFA enforcement | Admin can enforce MFA | Native enforcement not available |
| Security risk | Lower security risk | Higher risk if left unsecured |
How to Solve Authentication Challenges for Portal-Only JSM Customers
1. Customers Control Their Own Accounts
Portal customers decide whether to enable MFA. But your organization is still responsible for their security. How do you do that without direct control?
The miniOrange app becomes a dedicated security layer. This layer requires two-factor authentication only for your portal customers. It changes nothing for your employees. Your corporate single sign-on stays the same.
You deploy JSM portal 2FA only for the users who need additional authentication.
2. Security vs. Easy Login
Too much friction can discourage customers from using the portal. But compromising on security is not a solution.
The MFA/2FA for JSM Cloud app provides a balance. You allow customers to enroll in 2FA during their very first login. They choose their preferred authentication method. The entire setup is done in minutes.
3. Lost Devices
Customers can lose access to their phones or authenticator apps, preventing them from signing in.
miniOrange keeps the path open by allowing you to provide backup authentication methods. These include backup codes, security questions, and more, which simplify account recovery. Customers can log back in without having to contact you.
4. Different Types of Portal Users
External users arrive from many places and sign in using different methods. This causes inconsistent security across your portal.
miniOrange provides a single standard. You apply the exact same 2FA policy to every external portal customer. It doesn’t matter how they access the portal. You can firmly enforce 2FA for JSM portal customers.
What Does the Customer Experience Look Like?
The miniOrange MFA/2FA for JSM Cloud User Flow
- Customer logs in for the first time.
- Chooses a preferred authentication method.
- Verifies the setup, ensuring the link is strong.
- Saves backup codes or configures a backup method.
- Every future login requires both a password and 2FA.
This approach strengthens MFA for Jira Service Management customers without adding unnecessary complexity during enrollment.
Supported Authentication Methods
Different customers prefer different authentication methods. miniOrange gives them a choice. It supports a broad range of authentication methods.
- Authenticator apps (Google Authenticator, Microsoft Authenticator, Authy, Duo)
- WebAuthn (FIDO2)
- Email OTP
- SMS OTP
- YubiKey and hardware tokens
- Security questions
- Backup codes
Customers can also use backup authentication methods if they can't access their primary method.
How to Enable 2FA for JSM Portal Customers
You can set up 2FA for JSM Cloud portal customers in only a few steps.
- Install the MFA/2FA for JSM Cloud app.
- Open the app settings and enable 2FA for JSM Cloud portal customers.
- Let your customers complete self-enrollment during their first login.
- Test the login flow before rolling it out to all users.
The app also lets you enable 2FA individually for customers based on your requirements.
Who Should Use This?
The miniOrange MFA/2FA for JSM Cloud app helps secure customer access across your organization.
- External Support Portals: Require 2FA for every customer login to keep data safe.
- Vendors and Contractors: Protect users who sit outside your corporate identity provider.
- Regulated Organizations: Secure portals handling financial, healthcare, HR, legal, or other sensitive information.
Why Choose miniOrange MFA/2FA for JSM Cloud
The miniOrange solution is built specifically for JSM Cloud portal customers.
You gain total control over customer authentication. Manage customer 2FA with ease. Enable it. Disable it. Skip it. Or enable it only for specific customers.
We provide 24/7 support and personalized setup assistance.
Whether you're looking to strengthen MFA for Jira Service Management customers or close the authentication gap left by Atlassian Guard portal-only customers, this solution helps secure external portal access without changing how employees sign in.
FAQs
1. Does Atlassian Guard enforce 2FA for JSM portal customers?
No. Atlassian Guard only enforces MFA for Atlassian accounts, such as agents, administrators, and employees. Portal-only customer accounts aren't covered by these authentication policies.
2. Can I require MFA only for portal customers?
Yes. The app protects only portal customers and doesn't affect your existing employee authentication or SSO configuration.
3. Which authentication methods are supported?
The app supports:
- Authenticator apps
- WebAuthn (FIDO2)
- Email OTP
- SMS OTP
- YubiKey and hardware tokens
- Security questions
- Backup codes
4. Do customers configure 2FA themselves?
Yes. Customers complete self-enrollment during their first login and choose their preferred authentication method.
5. What happens if a customer loses their device?
Customers can recover access using backup codes, backup authentication methods, or security questions.
6. Does this work with Jira Service Management Cloud?
Yes. The solution is built specifically for Jira Service Management Cloud portal customers. It uses Atlassian's portal SSO mechanism and requires Atlassian Guard Standard.




Leave a Comment