Hi,
We have a requirement to create JIRA issues from ServiceNow. We already have an existing sevice account in JIRA and the integration was already in place. However, it is for a different project from what we handles.
We are considering using a different service account to create JIRA issues and access our projects/spaces in JIRA. Do you recommended this approach? What could be the pros and cons of this in JIRA? Thank you.
Hello @Angelica Pauli
Welcome to the Atlassian community.
I see that you posted a related question on this article:
Here is my opinion.
Cons:
- The burden on your Org Admins to track and regenerate tokens for multiple service accounts
Pros:
- adhering to least-privilege mindset by having any given service account granted access to only one project. If you have one account with access to all projects, then anybody who has the token could get access to data they should not be able to access.
So, what is more important to your company - low maintenance or higher security?
Hi @Trudy Claspill ,
Thank you for responding to my query.
If we are to add just 1 more service account, we can still have higher security without putting too much burden for Org admins, right?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello @Angelica Pauli
Going from 1 account to 2 seems reasonable. Going from 1 to 10 might even seem reasonable to your Org Admins. I suggest you talk with them about what they think a reasonable number is.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello @Angelica Pauli
Yes for one additional integration, that sounds like a reasonable approach.
It gives you cleaner separation and keeps permissions tighter, especially if that account only needs access to your Jira projects. At the same time, one extra service account is usually still manageable, so this feels like a good middle ground.
The only real downside is a bit more admin work around permissions and token management.
Small suggestion? if you are setting up a new integration now, also check whether you can use OAuth 2.0 for the service account.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thank you for your inputs @Arkadiusz Wroblewski !
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.