Hi Community,
While reviewing our Jira Cloud audit logs, I noticed a user was created, added to several administrative groups, and subsequently removed. The audit log shows the author as JIRA, and the account is no longer present in our user directory.
I found an Atlassian Community profile with the same name associated with the Atlassian Team, which made me wonder whether this account may have been related to Atlassian Support. However, I cannot confirm that the audit-log user and the Community profile are the same person.
We have also raised a support ticket with Atlassian to clarify the activity, but we've been waiting for an update for some time. We'd like to understand whether this type of temporary account and administrative group assignment is normal for Jira Cloud support or another Atlassian-managed process.
Specifically:
Under what circumstances might an Atlassian Support engineer or Atlassian-managed account be created in a customer's Jira site?
Is temporary membership in administrative groups an expected mechanism for Atlassian Support troubleshooting?
Is there a customer-facing setting where Org Admins can see whether Atlassian Support access is enabled or authorized?
Is there a way for customers to identify which support case or request resulted in the temporary access?
Should these activities normally appear in the Jira audit log with JIRA as the author?
Any insight from Atlassian staff or other Jira administrators would be appreciated.
Thanks,
Welcome to the community!
As far as I know, Atlassian support takes explicit consent to make changes in the cloud instance when working on support tickets. The best would be ask them to confirm the exact ticket or internal case number tied to access event. They should be able to correlate the audit log timestamps with their records.
Hi @Ajay _view26_ ,
Thank you for sharing this information. We have been waiting for an update from the Atlassian Support and have not received a response for almost three weeks, despite sending follow-ups. Hopefully, they will see this discussion and provide us with an update soon.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello and Welcome to Atlassian Community @Nick Languita
Did the timestamps of this temporary account activity coincide with any active Atlassian Support case where someone in your organization had explicitly granted Atlassian permission to access the site?
Atlassian documents a limitation in the Jira Cloud audit log for user-management actions, events such as creating users or assigning them to groups may not contain the username of the person who actually performed the change.
I also wouldn't use the matching Atlassian Community profile as evidence that the audit-log account belonged to that employee. Only Atlassian can correlate the account ID and timestamps with their internal records.
You have Open Request at Atlassian, so you should wait on Deterministic answer from them. Here we can only Guess, as Community Members we cannot see Backend.
Best,
Arek🤠
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks @Arkadiusz Wroblewski , you're right, hopefully Atlassian will provide us with an answer soon as this is somewhat of a security concern on our end. I've also confirmed with our Team that they don't have any support ticket or request that authorized Atlassian Support to access our instance during that period.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.