our company has a security and IAM hygiene practice to not only deactivate, but also delete identities from applications if users are not working at the company anymore. We also need to do this from a control and compliance perspective.
We are going to automate to delete deactivated users 30 days after they have offboarded from the company.
Questions:
- is there any negative impact in removing users from a Jira or Confluence aspect, for example even when this deactivated users has a task assigned. ?
- are the audit logs preserved related with actions which this user in the past did ?
- what is the recommended security best practice in Atlassian cloud if the users are have offboarded from the company ?
Hello @r ghisa
Welcome to the Atlassian community.
When you permanently delete the Atlassian Cloud account for a user, everyplace that user account is referenced (page information, user selection fields, activity history, comments, etc.) will be changed to display "Former user". You will no longer have any record of where that user was used throughout your Jira and Confluence data.
https://confluence.atlassian.com/jirasoftwarecloud/delete-your-account-962956972.html
The user's name will also be purged from application System Audit Logs and from the Organization level audit logs in compliance with GDPR.
Welcome to the Atlassian Community @r ghisa
Why delete inactive users?
The don't count toward your licenses.
The one major problem you will face if there are any filters the inactive users have under their names will be broken once you delete them from Jira. You could affect reports as well.
Try first to check if inactive users have any filters, dashboards, under their name assign them to an active user then delete them.
Best,
Fadoua
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for all the answers, really appreciate it. But in my opinion, this is wrong wrong behavior in Atlassian. (large) companies end up with 100+K deactivated accounts over the years while their active population is only 20% of that number - this is a real example, not made up numbers.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello @r ghisa
I recommend you provide that feedback directly to Atlassian.
The path they have chosen aligns with GDPR which requires that they remove the name of the user.
Perhaps if you contact Atlassian you can arrange a discussion with a product managers or others at Atlassian who can provide more details about the compliance requirements for GDPR, or discuss with you other options that might address your needs.
If I were to receive such feedback my first question would be to ask for a clear description of the problems that arise with having a large number of deactivated users in the Cloud organization, and what actions have to be taken because of those problems? To be clear, I am not an Atlassian employee. I am just thinking about how I would approach trying to address such feedback so that I can suggest how your feedback can be more effective.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@r ghisa I always remove access but don't delete. If you do, you'll need to know their user id to do any searches for old information tied to them. It also makes taking ownership of spaces, private filters etc. harder to do.
I'd suggest you export the users to get the name and ID before removing them altogether if you are forced to do this by a policy that wasn't fully thought out.
@Trudy P Claspill do you know if there is a difference if your organization has claimed the accounts and/or is using Guard?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.