When I m trying to remove user it says this?
We're unable to remove this user
XYZ is synced from an identity provider. Remove this user in your identity provider instead
Which identity provider is it referring to?
Can anyone help please?
Thanks
Most likely, you're dealing with managed accounts situation in which users are provisioned into an Atlassian app (Confluence) via SSO (which requires Atlassian Guard). SSO = identity provider.
In real terms it means that the user must be first removed as a Confluence user in the SSO tool. Say you're using an Okta as your SSO indetity provider. In this case, an SSO admin will remove Confluence access for the said user. After this, you will be able to remove the user from Confluence.
Being an Org admin doesn't mean your also an admin of your identity provider tool.
Talk to your SSO tool admin to remove the said user's access to Confluence, then you'll be able to remove them from Confluence.
Recommendation: ensure that your company's offboarding policy defines the process for removing employees and that it's done in the correct order.
Hello @Jyotsana Kandani
Welcome to the Atlassian community.
Can you tell us step-by-step what you are doing to try to remove the user?
What is your level of administrative access in this environment? Are you an Organization Admin for the Atlassian Cloud Organization under which this Confluence subscription exists?
The message indicates that the user was created in Atlassian Cloud by having the user accounts synched from an identity provider. When a user is created in that way they cannot be deleted directly in Atlassian Cloud.
This may have been set up by the Organization Admins of your Atlassian Cloud Organization, if the user is from your company. Or if the user is not from your company then it may have been set up by the Organization Admins of the company to which they belong.
Do you actually need to delete the user from the global Atlassian Cloud? Or do you just need to revoke their permissions to your Confluence instance?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I m an Organization Admin and trying to remove our left employee from user earlier it was i could remove suddenly i cannot remove but only suspend them
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
@Kris Klima _K15t_ and @Trudy Claspill both have right.
When your Atlassian environment is connected to your domain through provisioning, you can still be an Organization Admin, but changes must be made at the level of your Identity Provider.
I know that very well because, in my company, I am also the Domain Administrator and connected our Atlassian tools to SSO myself.
The right path here is to get in touch with your Domain Administrator and discuss the offboarding process.
In this setup, the domain identity layer has higher priority than your Atlassian administrator permissions, because identities are managed, provisioned, and synchronized from there.
PS: Btw. Probably you don't need any actions because when your Domain Administrator delete User from Domain, he will be also deleted from all included Identity, including Atlassian. That's how it works.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hallo @Jyotsana Kandani
That mean your Domain Administrator need to Clean User from a group Direct from your Company Domain Directory.
PS: This mean always that your Users are provisioned Direct from your Domain controller and needs to be cleaned there. So far you are not Domain Administrator you must address that internally to your Domain Administrators.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Once try Going to your Identity Provider (Azure AD / Okta)
Remove or deprovision the user there (or remove them from the synced group)
Wait for the sync, the user will be removed from Atlassian automatically
After that, you’ll be able to clean them up fully if needed.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.