I am trying to see if JIRA Cloud has a maximum # of login attempts for I need to complete my security assessment.
Thanks! Can you point me to the information/documentation around the user ids for the Cloud? I need to also capture the password (length, complexity, etc.)
Thanks again!
Hi Kathi,
The password policy for Atlassian ID is only that it needs to be between 8 and 100 characters long. This and the maximum login attempts are not documented on our site, but I was able to verify them by testing.
We will be rolling out our new Identity Manager for Cloud within the next few weeks, and once it's implemented on your instance, you'll be able to create an organization and control your own password policies for any managed domains that you have claimed.
For more information on the usage of the current setup, Atlassian Account, review the following:
If you want full control, however, I would definitely look into setting up SAML for your instance from the article I sent you earlier. Do let me know if you have any questions about that!
Kind Regards,
Shannon
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Kathi,
Using Atlassian ID login on Cloud will allow a user to attempt a login 10 times. On the 11th time, it will ask the user to complete a Google Captcha.
There is no "lockout" per se, and the user will continue to be asked for the Captcha until there is a successful login.
If attempting via API it will lock them out once the 11th try is reached, and then they will need to attempt to login normally from a browser to reset it.
Lastly, I have created a feature request below to be able to set maximum attempts for any users who have managed domains:
Please feel free to vote on this if you would be interested in such a feature.
One thing to note, if you decide to implement SAML on your instance, or use GSuite or login via Google, the policies on those providers will be enforced instead.
I hope this helps.
Kind Regards,
Shannon
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.