Azure Sync for Jira Assets: User Documentation 📝

Azure Sync for Jira Assets: User Documentation 📝

Welcome to Azure Sync for Jira Assets User Documentation

aBegin your journey to streamline your asset management between Azure and Jira Service Management. This powerful integration syncs Azure resources seamlessly into your Jira environment, enhancing your asset tracking capabilities.

Your Assets, Your Way

For any questions or assistance, please don't hesitate to reach out to us at support@sykorait.com. 🤙

Your Sykora IT Team.

Getting Started

To make it happen, simply install Azure Sync for Jira Assets on your Atlassian platform by following these simple steps:

  • Search for application Azure Sync for Jira Assets in the Atlassian Marketplace.

  • Install Azure Sync for Jira Assets into your Jira Software Cloud environment.

    • Ensure you have both Jira and Assets installed and ready to roll

First steps after installation

  • Configure the Azure Sync for Jira Assets app

    • Preparing Azure Connection Details

    • Configuring the Azure Sync for Jira Assets App import

Configuration

Preparing Azure Connection Details

Get your Directory Tenant ID (Microsoft Entra ID)

  • In your Azure portal, select All services > Microsoft Entra ID

  • Scroll down the left bar to Manage, open the Properties and search for Tenant ID

  • Save the Directory Tenant ID for future reference for usage in the import configuration

     

Get your Subscription ID

  • If you need specific subscriptions to be imported

  • In your Azure portal, search for Subscriptions

  • Select the Subscription(s) you would like to synchronize the Azure (Assets) data from

  • Save the Subscription ID(s) for future reference for usage in the import configuration

     

Register Access Application

You need to register an Application (the Azure Registration Application) that works as a gateway that enables the Azure Sync app to access data within your Azure environment. This registration app acts as an intermediary; it has permissions to view or manage certain parts of your Azure setup, but Azure Sync for Jira Assets does not directly access or modify Azure data. The registration app specifies which data the Azure Sync app can import.

  • In your Azure portal, select All services > Microsoft Entra ID

  • Under the “Add” tab, click on App registration (or in the left bar open App registrations and Select New registration)

  • Pick a name for your application. You can use something like "asset-azure-sync" as inspiration

  • Leave other settings at default values

  • Create the App registration

  • Save the Application (client) ID for future reference for usage in the import configuration

    image-20240430-195356.png

Create Application Secret Key

  • Go to the settings of the previous created application.

  • Scroll down to Manage and Select Certificates & secrets

  • Click New client secret

  • Type description for the Key, choose an expiration and Add it

  • Save the Key-Value for future reference for usage in the import configuration

image-20240430-194221.png

Assign Application Role assignment

Granting permissions to the registration app is essential as it defines the scope of data access: what the Azure Sync app can view in Azure.

In your Azure portal, search for Subscriptions

  • Select your subscription (or more if you want to be able to import data from multiple subscriptions)

  • Select Access control (IAM) and click on the Role assignments tab

  • Click Add (you need to have proper permission)

  • Choose Role = Reader and search at the select for the Application name that you have created in steps above (saying this registered application now can read this subscription data)

image-20240430-194918.png

Check Required Permissions

  • Go to the settings of the previous created application (Microsoft Entra IDApp registration)

  • Select API permissions (left bar)

  • make sure that the chosen permission User.Read is visible

image-20240808-105048.png
API permissions

(Optional) The following steps are required for the app to fetch Azure Entra ID data (users, groups, devices)

  •  On the search bar, search for App registrations. Select the App registration that you have created

  • Click API permissions and Add a permission

  • Select "Microsoft Graph"

  • Select "Application permissions"

  • Select User and check "User.Read.All", (recommended option)

    • If you only select lower permission “User.ReadBasic.All” user atributes will not be fully imported

  • Select following API permissions:

    • "Group.Read.All" or least privilege “GroupMember.Read.All“

    • “Device.Read.All” - to be able to synchronize devices

      • another possibility - “DeviceManagementManagedDevices.Read.All”

  • Click "Grant admin consent for “your specific subscription”.  

image-20240808-105300.png
Graph app permissions

 

image-20240430-195021.png
grant admin consent

Configuring the “Azure Sync for Jira Assets” App import

To import Azure data into Assets you will need all the data you have gathered in the steps above. Navigate to the Import section in the object schema configuration, click “Create import” and select Azure Sync for Jira Assets.

asset_imports-20240626-102551.png
Select “Azure Sync for Jira Assets” option

After creating an import, it will be in “NOT CONFIGURED” state. You will first need to provide your Azure Connection Details to execute it. Click on the “three dots” and then “Configure app” to open configuration modal.

Snímek obrazovky 2024-05-03 131333.png
Import before configuration

 

 

Connection configuration

Fill the necessary fields and click “Save configuration”. When you save configuration for the first time, the asset schema & mapping will be generated. This may take a while (by our testing 20 seconds to 2 minutes) so please be patient.
Also you should test the connection using the test connection button before proceeding to further tasks. You can also open the schema tree, and see the (empty) structure of Asset Object Types generated under the Root Object Type.

Connection Configuration tab

Azure Connection parameters:

  • Root object type name

    • Specify the name of the object type where the imported data will be stored.

      • Important note : It will automatically generate a new root object type. It's recommended to select a unique name for the root object type. If you attempt to connect the app to an object type that was created via the Atlassian Assets GUI, it may cause errors due to Atlassian's limitations. Therefore, it's recommended to use a unique name (so a new object is created) or choose an existing object type that was created by this application (such as when performing a prior import with the same root object).

  • Microsoft Entra ID (Directory Tenant ID)

  • Application (Client) ID

  • Application (Client) Secret Key

  • Choose what this import should synchronize (Import Scope):

      • Azure resources and Microsoft Entra ID – sync Azure subscription resources together with Microsoft Entra ID objects (Users, Groups, Devices, and Service Principals). Use this when you want a complete view of your cloud estate in Assets.

      • Microsoft Entra ID only – sync identity data without Azure subscription resources. This option creates its own dedicated (reduced) Assets schema, streamlined for identity: Users, Groups, Devices, and Service Principals. Ideal when you want a clean, focused identity inventory in Assets. Also within this option you can enable Sync user group membership (Beta) in Advanced settings.

Microsoft Entra ID only option
Microsoft Entra ID only Schema
Sync User Group Membership within Microsoft Entra ID only import scope
  • Subscription Options

    • In the latest version, you can now enable an option to import resources from all subscriptions that your Azure Registration App has permission to access. This significantly simplifies importing from multiple subscriptions at once.

Use all available S
    • If you prefer to specify subscriptions instead of importing all at once, you can toggle this feature off. Then, simply enter the Subscription ID of the subscription you would like to import data from. If you want to import data from multiple (specific) subscriptions in a single instance, separate them by commas. This makes handling a large number of subscriptions much easier and more efficient.

Specific subscription settings

Advanced settings

On separate tab you can modify import parameters not critical for import execution.

Advanced Settings Tab

 

Scheduling imports (Jira Automation recommended)

Azure Sync supports two ways to run imports automatically. Both are fully supported - choose based on how much control you need.

 

Jira Automation

Built-in scheduler

 

Jira Automation

Built-in scheduler

Best for

Custom schedules and workflow-driven runs

Simple recurring sync every 12 or 24 hours

Timing

Exact day/time, weekdays, flexible schedules

Every 12 or 24 hours

Extra control

Conditions, filters, manual triggers

Interval selection in the app

Follow-up actions

Slack / Teams / email, comments, audit trail

Where you manage it

Jira Automation (together with other rules)

App Advanced settings

How to choose

  • Use Jira Automation when you want a specific run time, notifications, conditions, or to manage the schedule together with other Jira rules.

  • Use the built-in scheduler when a straightforward every-12-hours or every-24-hours sync is enough.

Choose one scheduling mechanism per import. If both are enabled, the import could start twice.

Quick start: schedule an import with Jira Automation
  1. Enable the import for Automation

    • Open the Azure Sync for Jira Assets import configuration.

    • Go to the Advanced settings tab.

    • In the Jira Automation section, enable Available in Jira Automation.

    • Optionally enter a Label for Jira Automation (shown when selecting the import in a rule; if empty, the import ID is used).

    • Save the configuration.

    • Set the built-in Scheduler to Off (so the import is not started twice).

  1. Create a scheduled Automation rule

    • Open Project settings or Jira settings → Automation.

    • Create a new rule.

    • Trigger: Scheduled (for example every day at 06:00, or every Monday at 07:00).

    • Action: Run Azure Assets import (Beta).

    • Select the import you enabled above.

    • (Optional) Add a follow-up action: Slack / Teams / email / comment using the action result.

    • Save and enable the rule.

Automation Action

Only imports explicitly enabled in Advanced settings appear in the Automation action. That keeps unused imports out of rule configuration.

Jira Automation - more options

Beyond a simple schedule, you can start an import as part of a wider Jira workflow, for example:

  • After a planned maintenance window or operational process

  • From a manual Automation trigger (“Run now”)

  • Only when selected conditions are met

  • Combined with Slack / Teams / email / comment actions for notifications and audit trail

  • Managed together with other Automation rules in one place

When the rule runs, Azure Sync checks the selected import and starts it if it is ready.

Using action results in later rule steps

The Automation action provides output values for later rule steps (comments, notifications, conditions):

  • started – whether a new import execution was started

  • status – import / action result status

  • message – readable explanation

Example smart values:

Azure import result: {{createdAzureSyncImportrun.message}}

Import started: {{createdAzureSyncImportrun.started}}

Status: {{createdAzureSyncImportrun.status}}

Smart Values

Important: the action only starts the import. The import continues in the background, so the action cannot return the final import result, imported object count, or detailed import log.

What happens if the import is already running?

Azure Sync will not start a duplicate execution. The Automation action still finishes successfully and returns information that later steps can use, for example:

  • the import was started,

  • the import was already running,

  • the import is not ready to run,

  • the import is no longer enabled for Jira Automation.

Permissions

There are two permission-related parts:

  1. The import must be explicitly made available for Jira Automation in the Azure Sync import configuration (Available in Jira Automation). This is controlled by a user who can configure the import.

  2. The Jira Automation rule uses an app connection. According to Forge Automation behavior, the action is executed as the user associated with this connection, not necessarily as the user who triggered the rule event.

    • The connected user should have access to the relevant Assets schema and import.

    • The connected user must also have granted app consent in Atlassian Connected apps settings.

If the import is no longer available for Jira Automation, or if the selected import configuration is incomplete, the action returns a message explaining the reason.

Built-in scheduler

The built-in scheduler is a simple way to run imports automatically every 12 or 24 hours, configured directly in the app - no Automation rule required.

It is a good fit when you want a reliable recurring sync and do not need a specific clock time, weekday schedule, notifications, or conditions.

Options:

  • Off

  • Run every 12 hours

  • Run every 24 hours

Notes:

  • When enabled, the import runs automatically every 12 or 24 hours based on the selected option.

  • The first scheduled trigger typically occurs approximately 5 minutes after the application is deployed, even if imports have not yet been configured.

  • The exact start time for daily imports is not configurable - triggers are distributed across installations to balance system load. After the first trigger, the scheduler runs daily at approximately the same time.

  • If there are multiple scheduled imports, they execute one by one (not simultaneously).

  • There is no hard limit on the number of scheduled imports processed in one cycle, but total execution time of all scheduled imports should not exceed 12 hours (Forge limitations).

  • You can still manually synchronize imports at any time.

  • By default, the scheduler is turned off.

Important
  • Jira Automation support is currently available as a Beta feature. It is suitable for production scheduling; feedback is welcome at support@sykorait.com.

  • The import must be enabled in the Azure Sync import configuration before it can be selected in Jira Automation.

  • Removing Available in Jira Automation prevents the import from being used by newly configured rules. Existing rules that reference the import will report that the import is no longer registered for automation use.

  • Use one scheduling mechanism per import: either Jira Automation or the built-in scheduler.

Import options
  • Include hidden tags - hidden tags are special tags that are not displayed in Azure Resource view with “hidden-” prefix in tag name. You can toggle import of these here. Defaults to false.

  • Sync user group membership (Beta) – available only for imports with Microsoft Entra ID only import scope. When enabled, the app also syncs which Microsoft Entra ID groups each user belongs to, and creates the corresponding User → Group relationships in Assets.

    • To enable this option:

      • Open the Azure Sync for Jira Assets import configuration.

      • On the Connection tab, set Import scope to Microsoft Entra ID only and Save configuration.

      • Open the Advanced settings tab.

      • Enable Sync user group membership.

      • Save the configuration.

    • Notes:

      • Membership sync uses additional Microsoft Graph requests and may increase import duration, especially for tenants with many users.

      • Sync user group membership can also be used with imports that were created with the full schema (Azure resources and Microsoft Entra ID). To sync membership, temporarily set Import scope to Microsoft Entra ID only, save, enable the toggle, and run the import. In that run, only Microsoft Entra ID data is transferred (Users, Groups, Devices, Service Principals), including user–group relationships when the toggle is on. Afterwards you can switch the import scope back to Azure resources and Microsoft Entra ID for regular Azure resource syncs.

      • This does not apply to imports that were originally created with the Microsoft Entra ID only schema. Those use the simpler Entra-only schema and cannot be switched to the full Azure + Entra schema.

      • Support for user–group membership sync is currently available as a Beta feature.

Object Types Update

The Configuration modal includes an "Object Types Update" tab. When you deploy a new version of the app, it may support additional Object Types or Object Type Attributes. These changes are part of the new schema and mapping.

If you have imports created with older schemas and mappings, you will need to update them to use the new changes. We recommend keeping the schema and mapping up to date to ensure optimal functionality and compatibility.

 

Snímek obrazovky 2024-06-26 124215.png
Object Types Update tab

 

On this tab, you can:

  • See which Object Types or Object Type Attributes have been added, removed, or updated.

  • Run the schema and mapping update to apply these changes.

Structuring Your Imports in Jira

  • Depending on your organization’s needs, you may want to import data from different subscriptions into one shared “root object” within Jira Assets or keep them separated by creating distinct root objects.

    • Single Root Object: All resources, regardless of the subscription, are imported into a single location within Jira Assets. This works well if it’s not necessary to distinguish resources by environment (e.g., production vs. testing), or to track resources across your organization and have everything in one place.

    • Separate Root Objects: If it’s essential to differentiate resources for example by environment, you can set up separate root objects within Jira for each subscription (multiple import instances). This setup reduces the risk of data confusion, as each environment is clearly separated in Jira Assets.

Performing the Import

Once you have configured your settings correctly, you should be ready to perform the import process effortlessly. Before the first execution, configured import will be in state “READY TO RUN” and “Import data” button will appear. To start the import manually, simply click on the button.

Snímek obrazovky 2024-06-26 141015.png
Import ready to execute

The import will execute, fetching the Azure resources and creating Asset Objects.

Snímek obrazovky 2024-06-26 141036.png
Import during execution

After the execution finishes, you can click on 'Read details' to see what was imported.

Snímek obrazovky 2024-06-26 141053.png
Import after successfull execution

Finally, you can open the schema tree and browse through your imported Azure Resource Assets.

 

Snímek obrazovky 2024-06-26 135953.png
Object Schema Tree after Import execution

 

Imported Azure Data Types in Assets

image-20250324-115641.png
image-20250324-115452.png
image-20250324-115348.png

Discover the list of Azure resources now available in Azure Sync for Jira Assets by visiting our Resource Sync Feedback Hub. We'd love to hear your thoughts on what other resources you'd like to see added, so feel free to join the conversation and help us shape future updates!

Missing / deleted values


During the import process, if an asset object in Jira corresponds to an object that is no longer present in Azure, the user can decide how to handle this discrepancy. The user has three options:

  • Ignore it and keep the asset in Jira.

  • Delete the corresponding asset in Jira.

  • Update some parameters of the asset in Jira.

These actions can be configured individually for each object type in the "Edit Object Type Mapping" modal, similar to the setup for other Atlassian asset imports.

Snímek obrazovky 2024-06-13 141930.png

Data Residency

Azure Sync for Jira Assets, built on the Forge platform, offers you the advantage of data residency control. With the latest Forge capabilities integrated, you can securely store your Azure connection data with confidence. This empowers you to align with your organization's data governance policies and ensures compliance with regional regulations. Your data remains safe and accessible, giving you peace of mind while using our app.

Known Limitations

  • Character Limit Discrepancy: Azure allows longer string attribute values than Jira Assets, which causes import errors when creating assets with attributes of the "text" type that exceed Jira Assets' 254-character limit. Resources with attributes that exceed this limit will be skipped during the import.

Some Azure resource types can have IDs longer than the Atlassian Assets 254-character limit. For these resources, we use a shortened ID for referencing and store the full Azure ID separately in a textarea attribute.

Currently, this workaround is applied to:

  • Subnet - from 3.74.0

  • Desktop - from 3.74.0

  • Lock - from v3.55.0

  • Network Security Rule - from v3.53.0

  • IpConfiguration - from v3.15.0

  • Inbound NAT Rule - from v3.41.0

For Inbound NAT Rule, the Backend IP Config attribute replaces the former Backend IP Configuration attribute and stores the full Azure ID without the 254-character limitation.

Note: If you had any IpConfigurations/Network Security Rule/or any changed (this way) resource imported from a version prior to 3.15.0/3.53.0 and import them again, they will be treated as "duplicates" (since the Id attribute is being modified, the system sees it as a new object). To resolve this, we recommend bulk-removing all the existing IpConfigurations and then running the import again.

 

  • Limitation for imports: Currently, when using Azure Sync for Jira Assets, there is a limitation on the number of Azure subscriptions you can import at one time.

As of February 4, 2025, imports in our app now have improved capacity. This enhancement allows for significantly higher subscription limits per session, making the import process more efficient. In most cases, this increased limit should be sufficient to meet all user needs.
While the exact limit may vary based on factors like the amount of data associated with each subscription, here’s what you need to know:

  1. General Guidance on Limits:

    • In many cases, users may encounter restrictions around 350 subscriptions per session.

    • However, under certain conditions with smaller datasets per subscription, it is possible to import up to nearly 1000 subscriptions in a single session.

  2. Real-World Variations:

    • Due to differences in data volume, some users may encounter import limitations at lower subscription counts (in edge cases even just for one subscription). This variability makes it important to plan import sessions accordingly.

    • For large datasets there’s a constraint set by Atlassian’s Assets platform: the total size of external import. This limit may be reached when processing subscriptions with substantial data volumes.

      We recognize that in rare cases, a single subscription with extensive data can approach or exceed this limit, potentially interrupting the import process. We are actively exploring solutions to handle such scenarios more effectively. Our team is investigating different kinds of options. In the interim, users can mitigate this by importing fewer subscriptions per import session or reviewing subscriptions for particularly large datasets.

Workarounds for Larger Imports

If your organization has a high number of large subscriptions or encounters import limitations, consider these approaches:

Use Multiple Import Instances

  • Specify Individual Subscriptions
    Consider running separate import sessions. This can be done by listing up to around 350 subscriptions per session in the Subscription IDs configuration input field.

  • Import “All Available” Subscriptions
    Alternatively, you can create multiple Azure registration applications to divide and manage the subscription import process more effectively. Each app can be configured to import a different set of up to around 350 subscriptions, reducing manual input and simplifying the import setup (utilizing the "All Available" configuration option)

 

Duplicate Tags Imported from Azure Due to Case Sensitivity

When importing Azure resources into Jira Assets, duplicate tags can appear if the same tag exists with different capitalization (e.g., Application:Backend-v2 vs. application:Backend-v2). This happens because Azure treats tags as case-insensitive for uniqueness but preserves the original case, leading to both versions being imported.

How to fix:

  • Remove all variants of the problematic tag from every Azure resource.

  • Recreate the tag using the correct case.

  • Re-import into Jira Assets.

If duplicates persist, check all resources individually in Azure for leftover tags with the old capitalization.

  • User–group membership sync (Beta) is available only with Microsoft Entra ID only scope

Keeping membership sync with Entra-only runs helps stay within platform limits (additional Microsoft Graph requests and longer processing), which is why this option is designed around a focused identity sync rather than mixed Azure resource imports.

Workaround:

If your import uses the full schema, temporarily switch Import scope to Microsoft Entra ID only, enable membership sync, run the import, then switch back to Azure resources and Microsoft Entra ID when you want resource sync again. One import, flexible scope - membership when you need it, full Azure sync when you don’t.

 

Troubleshooting

Assets - Azure Integration requires both Jira and Assets to function. Also make sure all the specific permission in your Azure environment was set right.

Licence expiration

You might encounter an error (2) when starting the import (1). The first thing to check is whether your license is active, as it is the most common reason. The quickest way to verify this is in the import configuration dialog (3), where a message should appear in such case.

License expiration

Schema updates

Schema and mapping updates may not execute successfully if the schema or mapping has been manually modified (e.g., attributes removed or attribute/reference types changed). We strongly recommend not modifying the schema and mapping manually if you want to retain the ability to update it through our app.

Sometimes it may appear that schema&mapping update (on update tab) is taking too long. The operation might take longer in extreme cases because a retry event is performed there.

Unused Location asset objects

When running the import, all Locations will be imported, including those that are not used or referenced by any resource. This is not an error but a feature, allowing users to view all possible locations (e.g., for cloud infrastructure management, to see available locations where a resource can be deployed).

To display only the Locations that are currently in use (i.e., being referenced), we suggest using a filter within the asset view with the following AQL query:

object HAVING inboundReferences()

image-20241003-094247.png

Import appears stuck and no objects are created

Symptoms