The Two-Factor Authentication (2FA) App by miniOrange adds an extra layer of security to Jira Software and Jira Service Desk. This guide will show you how to configure 2FA using your Mobile Authenticator App. By the end of this guide, users will be able to log in to Jira with the added security of a second authentication factor.
For a more comprehensive understanding and additional tips, check out our comprehensive Atlassian 2FA handbook.
Before configuring the miniOrange Two-Factor Authentication (2FA) App for Jira, ensure you have the following:
Follow these steps to configure and enable the miniOrange 2FA app for your Jira users:
Google Authenticator
Microsoft Authenticator
Yubikey Hardware Token
OTP over Email
OTP over SMS
Duo Push Notification
WebAuthn
Security Questions
Backup Codes
Brute Force Configuration helps restrict access to your Jira application after a specified number of invalid
2FA login attempts within a set period.
To enable this feature:
This feature allows users to skip the 2FA check when logging in from the same device.
To enable:
This feature lets users skip 2FA in Crowd-connected applications after a successful 2FA validation any one
Atlassian application.
To enable:
Note: This feature is only available if authentication is done via Crowd.
This feature allows users to skip 2FA if they log in via Single Sign On (SSO) with any Identity Provider (IDP).
To enable this, admins need to:
This feature allows users to skip 2FA when logging in via SSO using the miniOrange Crowd SAML add-on and Jira
Crowd connector.
To enable this, admins need to:
By default, only administrators have access to the plugin pages. This feature allows you to define and customise
access permissions for specific user groups, granting them the ability to view and manage designated plugin pages.
By configuring access settings, you can ensure that the right users have the necessary permissions to perform
their tasks, enhancing collaboration and security within your organization.
To enable this, admins need to:
This feature gives administrators the ability to limit specific 2FA methods to certain user groups. For example,
an organization might offer two login methods, such as OTP Over Email and Mobile Authenticator.
With this feature, admins can require employees to use OTP Over Email for enhanced security, while allowing
customers to select a method of their choice.
To enable this, admins need to:
Any enabled methods not specified in this configuration will remain available to all users by default.
This feature allows you to enforce Multi-Factor Authentication (MFA) for all REST API calls. By enabling this
option, every API request requires a second form of verification, enhancing security and protecting sensitive data
from unauthorized access. Users can choose their preferred verification method, ensuring a balance between
security and user convenience.
To enable this, admins need to:
This feature allows you to configure automatic redirection after successful 2FA authentication based on your
domain name and port. If the domain name and port are not specified, the plugin will rely on the configured base
URL for redirection.
This ensures that users are seamlessly directed to the intended resource, such as a dashboard or home page,
enhancing their overall experience while navigating your application.
To enable this, admins need to:
The miniOrange 2FA app has provisions for efficiently managing 2FA settings for individual users, multiple users,
single groups, and multiple groups.
Let's take a look at how you can manage 2FA for your users and groups.
Enabling 2FA for Single Users:
Enabling 2FA for multiple Users:
Enabling 2FA for All Users:
Enabling 2FA for Single Groups:
Enabling 2FA for Multiple Groups:
Enabling 2FA for All Groups:
IP Whitelisting:
IP Blocking:
Jira SAML SSO application enables SSO for Jira Software and Jira Service Desk.
Know MoreSynchronize users, groups and directory with SCIM and REST APIs for Server DC.
Know MoreSecure your Jira Data Center/Server REST API using API Tokens.
Know MoreIf you don't find what you are looking for, please contact us at support-atlassian@miniorange.atlassian.net or raise a support ticket here.