Our previous method for creating guest users was to grant them application access through a specific group, and then only give that group access to the project they needed to see. However, we've discovered that new Next Gen software projects, by default, are open to everyone in our directory, regardless of group. Even if we restrict all of our current projects, this doesn't solve the default behavior of new projects being open to everyone. So what we need to do is create guest users that don't count as part of our company for permissions purposes, and thus don't have access to any new projects that might get created under the default permissions. How can we do this?
Hi Tim,
You can still control who can see the Next-gen projects by going to Project Settings > Access and update who can see the project.
This wouldn't solve the problem of the new permissions being subtractive instead of additive. If a new next-gen project were created with the default permissions, any guest users would be able to see it. We deal with multiple clients from different companies and we need to be able to maintain security of different projects and minimize the risk of things being exposed to all users.
If there isn't a way to create guest accounts outside of the directory, is there at least a way to set the default security level for next gen projects to Private?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Ah I see. You have to choose the Access level when creating it.
This would be a training issue then, where we would have to make sure our project leads know to never choose Open or Limited when creating a new project. Barring the ability to restrict that at the admin level, I'm more inclined to turn off Next Gen Projects entirely for now, in the hopes that they'll be more secure later.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.