Authentication, simplified: OpenID Connect for Data Center

Authentication, simplified: OpenID Connect for Data Center

Enable single sign-on for your self-hosted Atlassian products and manage your users seamlessly and securely.

It’s the stuff of nightmares: the dreaded “Forgot your password?” odyssey after guessing the umpteenth variation of your workhorse password. New services, all requiring identity confirmation, are introduced every day, so it’s no wonder single sign-on (SSO) solutions have become critical for enterprise organizations.

But the need for SSO goes well beyond a seamless user experience. In fact, its most important function, perhaps, is ensuring security and compliance for enterprises that have to manage user access to the myriad apps deployed across the company.

Cue OpenID Connect (OIDC), a hyper-focused authentication layer on top of the OAuth 2.0 authorization framework and an emerging standard for SSO and identity provision. While still a relatively young technology, OIDC is rapidly growing in popularity, primarily because of its flexibility and usability. And now our Data Center editions of Jira Software, Jira Service Management, Confluence, and Bitbucket will include support for OIDC.

Supporting OIDC not only makes it easier to comply with security standards and requirements set by your organization, but provides an interoperable way, similar to REST, to incorporate secure identity management in a frictionless environment.

How OpenID Connect works, and why it matters

Teams are deploying more mission-critical software than ever before; they’re relying on chat tools for internal communications, and constantly context switching between dev tools and project management tools. As a result, the number of applications with access to sensitive information increases by the day. So ensuring a secure environment is at the top of any organization’s priority list. The matter is compounded for enterprise organizations overseeing a decentralized business, with a range of teams and tools spanning function, region, and even subsidiary. This commonly results in enterprises needing support for multiple authentication standards.

We have a lot of disparate services in our company that use different authentication sources, and I’d like to bring all of this together into a single source for ease of onboarding/offboarding […] If we had OIDC as an option in our Atlassian products, it would give us more flexibility in our spaghetti pile of services. – Financial Services customer

With an extended range of supported authentication options, enterprise customers have more flexibility to achieve single sign-on for users across the entire organization. As for OIDC in particular, it’s easy to integrate, and offers the features and security options to match and adapt to increasingly demanding enterprise requirements. And while there have been third-party plugins that provide workarounds to support OIDC in Atlassian products, their setup logistics and additional cost are not ideal. With support for OIDC, customers can simplify billing and streamline integration.

All of this is not to say that OIDC is the only authentication option out there, or the right one for your organization. There are a few other alternatives we see customers use, such as Crowd, which offers single sign-on/authentication for Atlassian products in addition to several other user management features (offered for both Server and Data Center deployments), and SAML, which we currently bundle with our Data Center products via plugin on the Marketplace. While nuanced, it’s important to understand the differences and similarities between SAML and OIDC.

Differences between the most common identity standards

As it stands today, there are three leading open standards for identity online: OIDC, OAuth 2.0, and SAML. While some may be well versed on what OIDC is and how it works, many still struggle to understand how it compares to other identity standards such as OAuth 2.0 or SAML, and understanding each is an important step towards protecting your organization’s data from the ground up.

How to get started with OpenID Connect

While support will be built into the Data Center editions of Jira Software, Jira Service Management, Confluence, and Bitbucket incrementally across coming releases, you can get started immediately by downloading our plugin, SSO for Atlassian Server and Data Center. With the plugin, you can delegate authentication to the OIDC or SAML identity provider of your choice to connect the aforementioned Atlassian Data Center products with your identity infrastructure.

If you’re interested in learning more about some of the other investments we’re making into the security and compliance space in addition to support for OIDC, be sure to register for our upcoming webinar.

Exit mobile version