Too much to type in great detail, but can guide you what to read up on if applicable to your use case: - You can selectively manually claim your accounts in bulk using csv method after claiming your domain. It's just pain in the butt then to maintain with new user onboarding from there on when you don't opt for the automatic claim account option. - Read up on how Atlassian Directory / Guard handle/not handle nested - One Okta Tenant only, if you have more than one to connect you'll need enterprise - Every licensed app user you claim as managed account under your domain is billed a guard seat once. But good news if the user is only granted "customer role" atlassian doesn't bill guard seats for them even if its a claimed account on your domain. - You may come across external users that you invite to your site, that can't login with their external atlassian accounts if their org admin that claimed that domain and account suspended or deactivated their atlassian account within their org. That user either need to be given a email from your domain then or they have to ask their org admin to restore their atlassian account. - Non-billable policy can be used if useful in your scenario. Read up on it. - Don't know if its still the case, or if Atlassian fixed it since (i'll need to check) but if there's issues with your credit card when guard bill is due, you lose your guard setup and have to it again. I do hope they have put a fail safe in to stop that now, but thought I'd mention to be diligent. Two of my 2024/2025 clients had that happen with no warning when their credit card expired and payment didn't go through. There were no smiles in the room that day 😬