logoApps documentation
Active Directory Attributes Sync
Documentation
FAQ
Release notes
Active Directory Attributes Sync
Documentation
FAQ
Release notes
Last updated Jun 26, 2026

Migration from Active Directory Attributes Sync

This section covers migrating from Active Directory Attributes Sync (Data Center/Server) to Entra ID (Azure AD) Attributes Sync for Jira (Cloud). It includes a feature comparison, a step-by-step migration plan, and a rollback plan.

Overview

Active Directory Attributes Sync integrates Jira with an on-premises Active Directory via LDAP. Entra ID (Azure AD) Attributes Sync for Jira connects Jira to Microsoft Entra ID — the cloud-based identity directory.

Both apps share the same core purpose — displaying and synchronizing user attributes in Jira — but they connect to two independent systems: LDAP and Microsoft Entra ID. This means switching apps also requires migrating your identity provider from Active Directory (LDAP) to Microsoft Entra ID. The app migration and the directory migration must happen in parallel or the directory migration must be completed first.

Before you start, review the feature comparison below to understand what changes and plan accordingly.

Info

Migration without changing your identity provider is on our roadmap. If you’d like to stay updated, contact our support team.

Feature comparison

Note

N/A in the tables means the item isn’t applicable or there’s currently no workaround.

Feature Active Directory Attributes Sync Entra ID (Azure AD) Attributes Sync Workaround
Directory catalog synchronization N/A
Display user attributes on Issue View N/A
Display user attributes on Request Details View N/A
Mapping attributes to custom fields N/A
Automatic updates on workflow transition N/A
Custom user attributes from the directory N/A
Display groups and roles N/A
Editing directory users from Jira Manage users directly in the Microsoft Entra ID admin console
JQL search by user attributes Use standard JQL with custom fields populated by the app
Attribute visibility control by group N/A
Use attributes in email notification templates Populate attributes to custom fields and reference them in automation rules
Dashboard gadgets and statistics N/A
REST API for integrations and scripts N/A
On-premises directory (LDAP) N/A
Cloud identity directory (Microsoft Entra ID) N/A
Warning

Features listed as unavailable in Entra ID (Azure AD) Attributes Sync for Jira won’t be carried over automatically. Review the table above and document your current configuration before starting the migration.

Before you start

Before migrating, prepare the following:

  • Your organization has completed or is in the process of migrating its identity provider from Active Directory (LDAP) to Microsoft Entra ID — the app migration can’t be completed without this.
  • Access to the Jira Cloud instance with admin permissions.
  • An active license for Entra ID (Azure AD) Attributes Sync for Jira.
  • Admin access to the Microsoft Entra ID tenant.
  • An API permissions setup in Microsoft Entra ID (see Connecting the app to your directory).
  • A documented record of your current Active Directory Attributes Sync configuration: attribute mappings, custom field names, group visibility rules, and any JQL functions in use.

Migration steps

Steps

  1. Document your current configuration — Export or manually note all attribute-to-field mappings, group visibility settings, email notification templates using directory attributes, and any JQL queries that rely on directory-specific functions.

  2. Install Entra ID (Azure AD) Attributes Sync for Jira — Go to Jira Administration > Manage Apps and install the app from the Atlassian Marketplace, or have your Jira admin activate the license.

  3. Connect the app to your directory — Follow the steps in Connecting the app to your directory to authenticate and grant the required API permissions in Microsoft Entra ID.

  4. Re-create attribute-to-field mappings — In the app configuration, map the directory attributes to the corresponding Jira custom fields. Refer to Mapping directory data to a custom field for instructions.

  5. Configure the Issue View display — Set up which attributes appear on the Issue View and Request Details View. Refer to Displaying directory data in the Issue View and Request Details View.

  6. Set up workflow post functions — Re-create any automatic attribute updates that were triggered on workflow transitions. Refer to Copying directory data to Jira in the workflow.

  7. Validate attribute display — Open several Jira issues and confirm that the correct user attributes appear as expected for both Reporter and Assignee.

  8. Test custom field population — Trigger a workflow transition and confirm that the custom fields are updated correctly.

  9. Disable Active Directory Attributes Sync — Once the new configuration is validated, disable or uninstall Active Directory Attributes Sync from your Data Center instance.

Result

Entra ID (Azure AD) Attributes Sync for Jira is active and displaying user attributes from Microsoft Entra ID in Jira issues and custom fields.

Tip

If your previous configuration relied on JQL functions for searching by user attributes, consider populating those values to indexed custom fields — this allows standard JQL to work as a replacement.

Rollback plan

If you need to revert after encountering issues:

  • Don’t uninstall Active Directory Attributes Sync until the new configuration is fully validated.
  • Keep your documented configuration notes (from Step 1) so you can restore the original attribute mappings quickly.
  • To roll back, re-enable Active Directory Attributes Sync in your Data Center instance and disable Entra ID (Azure AD) Attributes Sync for Jira on Cloud.
  • Any custom fields populated by the new app retain their last-synced values — they won’t break existing issues, but they won’t update until the app is re-enabled.
Warning

Rolling back is only possible as long as your Active Directory (LDAP) is still active. If your organization has already decommissioned the on-premises directory and fully migrated to Microsoft Entra ID, there’s no directory to roll back to. Don’t decommission Active Directory until you’ve fully validated the cloud setup.

Migration FAQ

Do I need to migrate my identity provider before switching apps?

Yes. Active Directory Attributes Sync connects to Active Directory via LDAP, and Entra ID (Azure AD) Attributes Sync for Jira connects to Microsoft Entra ID. These are two independent systems. You can’t use the cloud app without Microsoft Entra ID being available on your tenant. The app migration and the directory migration must happen in parallel or the directory migration must be completed first.

Does the app migrate configuration from Active Directory Attributes Sync automatically?

No. There’s no automated migration tool. You need to re-create attribute mappings and display settings manually in Entra ID (Azure AD) Attributes Sync for Jira.

What happens to custom fields that were populated by Active Directory Attributes Sync?

The field values remain in Jira but stop updating after the old app is disabled. Once you configure and activate Entra ID (Azure AD) Attributes Sync for Jira, it starts populating those same fields — as long as the field names and mappings match your new configuration.

Can I run both apps at the same time during migration?

Yes. Both apps can be active simultaneously as long as they’re configured on separate Jira instances (Data Center and Cloud). Don’t configure both apps to write to the same custom fields on the same instance, as this causes conflicting updates.

What directory attributes are supported in the cloud app?

Refer to Supported directory attributes for the full list.

Where can I get help if something goes wrong?

Need help?

If you can’t find the answer you need in our documentation, raise a support request.
Include as much information as possible to help our support team resolve your issue faster.