Hi,
We are experiencing an issue with our user provisioning process via Okta. When any member of our organization logs into an Atlassian product (like Jira or Confluence) for the first time through our Okta SSO, they are automatically added to the jira-servicedesk-user
group.
This action immediately consumes a Jira Service Management (JSM) agent license for that user.
Our organization has over 1,000 employees, but we only require and have licenses for 20 JSM agents. This default behavior is causing a significant, unintended consumption of our agent licenses, creating a major administration and cost issue for us.
We expect new users to be provisioned with general site access without being automatically added to any license-consuming groups like jira-servicedesk-user
. We need to be able to grant JSM agent licenses manually and exclusively to our 20 designated agents.
Could you please provide guidance on how to prevent this automatic group assignment for new users authenticating via Okta? We need to ensure that no user gets an agent license by default.
Thank you for your assistance.
Best regards,
Salvatore
Welcome to Atlassian Community!
You can change App access settings by going to admin.atlassian.com and then Apps > App access settings to change what users in an approved domain get access to when they first log in to your instance.
Welcome to the community.
Change the App Access Settings within Atlassian administration.
By default there is any option any domain, your organisation could have added other organisations, you can change this by organisation.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.