Hi everyone,
Yesterday I removed a user from a jira group and removed the product her list of products. She then clicked a link of a Jira ticket that I gave her and confirmed that she no longer had access.
A few hours later she magically was added back as a Jira user and has access again.
I'm sure it's something dumb that I missed, but need your help in figuring out what it is.
Thanks in advance!
Alright, so I edited the User Access settings in Atlassian Administrator to deny/disable invitations outright. This seems to have do the trick for some reason, rather odd as there weren't any pending requests visible in the Admin view.
Regardless, I'm marking this as answered for now.
Hi @Sascha ,
How are you provisioning your users? You mention you removed her from a group was this a local group?
If you are using Atlassian Guard (Access) the sync will always add her back in. You should also be able to see in the Audit log what happened with the group and how she was added back.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Dirk!
Users are typically added manually, we're not synching with Active Directory or anything. we don't use Atlassian Guard either.
All employees have access to Confluence, but only a small subset should have Jira access as well. I've just noticed while checking in the Jira-users-group that there were another 3-4 users with access to Jira that should not be there. So perhaps something else it auto-adding users somehow.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I suggest looking at the Audit log then to see who is adding them to the groups.
https://support.atlassian.com/jira-cloud-administration/docs/audit-activities-in-jira-applications/
That should give you a lead on how they are added again.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hmmm... according to the log, on the 25th JIRA has added the offending user to the group and JIRA also added another user to the group on the 17th and 11th.
There aren't any other events around the same time as each entry. Could these people be clicking on a link somewhere that adds them to Jira automatically somehow?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
In Data Center, there's an option to automatically create users when they access Jira. I don't remember exactly where it is (and I have that option disabled in my environment), but maybe that's what's going on with your environment?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Matt Parks ! That sounds promissing, however I don't think that I have that feature on out account, at least, I'm not seeing it. How do I access this?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I just found it. We're using the built in SSO functionality, and it's an option in the SAML SSO login option configuration. This can be found under System > Authentication methods.
There is a JIT provisioning that will create users on login to the application when they log in through SSO for Atlassian Data Center applications.
Since you're on Cloud, I don't know if it works the same way, but I did a quick google search for "automatically create users jira cloud" and the AI overview had several different options for ways to do this. Maybe one of these ways is already configured in your environment.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Well we don't have SSO set up, nor do we have Atlassian Data Center.
I just noticed that our domain hasn't been validated yet with Atlassian so I'm in the process of doing that. I also edited the User Access settings in Atlassian Administrator to deny invitations altogether, disabled invitation links for good measure too. Let's see if that helps and if a validated domain provides me with more config options.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.