Hello Atlassian Support,
I would like to ask for clarification regarding an unexpected situation with user access.
A few months ago, as the administrator of our company’s Jira instance, I deleted a user from the system. However, starting from last week, this user was able to join our Jira instance using an invitation that appears to have been sent earlier.
From what I can see, the user accepted the invitation and regained access despite having been previously removed.
I would like to understand how this could happen and under what circumstances an invitation remains valid for such a long period of time.
Specifically, I would appreciate clarification on the following points:
How long do Jira/Atlassian invitations remain valid?
Is it possible that an invitation sent before the user was deleted can still be used later?
Are there any settings or logs that allow administrators to track who sent the invitation and when?
What would be the best way to prevent similar situations in the future?
Thank you in advance for your assistance.
Kind regards,
Ihor
Hi @Ihor Krapivin ,
As I research, Atlassian’s docs don’t specify a fixed expiration time for invitations. In practice, invitations can remain valid for a long time even while the user remains in an invited/allowable state. More details: https://support.atlassian.com/user-management/docs/invite-a-user/
To see who invited or granted access to a user and when, check your org or site Audit log (This feature is only available to organizations with an Atlassian Guard subscription):
You take a look at these 2 documents:
To prevent similar cases, you can add an admin approval step when users invite others to use your apps:
Hope it helps 🙌
Looks like following might have happened.
The invitation was sent earlier
User never accepted it.
You removed the user later.
Invite was still valid.
User clicked it recently and regained access.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.