Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

If possible, restricting access by IP in the company firewall or gateway is also recommended. By only forwarding request that originate from a whitelisted IP-range, you will have an extra layer of safety on top of the bearer token. Some IDPs publish their IP ranges either either in the form of regular documentation, or as JSON files that can be consumed and converted to firewall rules/scripts. As an example, Azure AD ranges can be downloaded here: https://www.microsoft.com/en-us/download/details.aspx?id=56519

Data Center vs Server 

While Atlassian Datacenter is not required to use SCIM, we do recommend it for the added redundancy it provides. In a single server environment, provisioning can occur simply because the only server is taken down for temporary maintenance or a reboot, as that makes SCIM endpoints temporarily inaccessible. Depending on the IDP, this could simply mean a newly added user or group doesn't get provisioned for another hour (when the IDP automatically retries), or it could mean a manual refresh/force sync is needed for that user. Some IDPs, Azure among them, will disable SCIM provisioning and send the admin an e-mail if enough SCIM operations fail within a certain time frame.