Just a heads up: On March 24, 2025, starting at 4:30pm CDT / 19:30 UTC, the site will be undergoing scheduled maintenance for a few hours. During this time, the site might be unavailable for a short while. Thanks for your patience.
×We got an email this morning that someone from outside our organization was added to our Jira/Confluence account.
None of our admins added him. When I called him he said that he joined by clicking a link from his company's self-hosted Confluence (without an invite from us).
This is very strange. We need to figure out just how he got in. I'm catching a lot of heat for this.
I tried looking at the security audit log but apparently, you need to purchase the "Access" license to see your security log
Hello @scott.coleman ,
As the user noted that they clicked a link to gain access it sounds like the user found a "Invite link" to the site, covered in more detail in "Specify how users get site access" but noting the warning:
Once you have shared an invite link, anyone can use it to create a new account. For this reason, you should only share invite links with people you trust. As an added security measure, invite links automatically expire after 30 days. You can also turn off invite links at any time, rendering any old links invalid.
I recommend first checking the link that the user used to access the site to verify if it is in the invite link format, and it will look something like this:
https://id.atlassian.com/invite/p/jira-software?id=<random hash value here>
You can go to your site's admin at admin.atlassian.com, then Select Site access > Invite links, and if there is an invite link present you can disable the link by selecting the green selector switch next to the link.
Regards,
Earl
Thanks, I noticed that I had some external domains approved and removed them.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Scott,
You may want https://support.atlassian.com/contact/#/ instead of the community. Cheers!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.