Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is Jira Asset Management account must be in on-premises Domain Administrators Group?

Michael Zolotarsky
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
October 19, 2025

Is Jira Asset Management account must be in on-premises Domain Administrators Group?

What minimum permission should Jira Asset Management account should have to manage assets in Domain

2 answers

1 vote
Taliah15
Contributor
October 19, 2025

Hello @Michael Zolotarsky 

Jira Asset Management account does not need to be in the on-premises Domain Administrators Group. Having Domain Admin rights is excessive and not recommended due to security risks. Instead, the account needs the minimum necessary permissions to manage assets in the domain, typically delegated write permissions for relevant Active Directory organizational units or asset locations. These permissions should allow the account to read and write asset attributes without granting full domain control, adhering to the principle of least privilege. This ensures secure, efficient asset management without overexposing critical domain controls. This approach balances functionality with security best practices for on-premises integrations with Jira Asset Management.

1 vote
Peter_DevSamurai
Atlassian Partner
October 19, 2025

Hi @Michael Zolotarsky , 

The answer is no, the account does not need to be in the Domain Administrators group, as that's excessive and a security risk. Instead, it needs minimal read-only permissions tailored to your use case (e.g., querying or importing users/groups as assets).

If you're just syncing users for Jira login (not Assets-specific), the minimum is "Read-only" access on users. 

 

Suggest an answer

Log in or Sign up to answer