We have had several external users added to our system from the external domain. No one having User Access Admin role approved their access.
I've been able to find that for some reason their domain was white-listed for third-party sign up, but unable to find any specifics on how this domain was added and who initiated their access. The Audit logs are unavailabe - throwing an error when trying to access or export them.
I've created 2 support tickets but these tickets get resolved and marked as Spam.
I'm looking for the information on how this happened and how to prevent this from happening in the future.
Welcome to the community.
Within the Atlassian Administration of you instance, check the User Access Settings.
Hi @Marc - Devoteam , thank you so much for the recommendation! That's how I found that whitelisted domain that was allowing the third party sign up.
But I unfortunately can not find how that domain got white-listed. Do you have any hints on this?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
If it says Any domain as the option, this is a default ootb.
If there is a specific domain added, then this has to be done by a site or org admin.
As you are not on a premium or above plan, you don't have the audit log option for the instance and you can't trace this.
You could reach out to Atlassian Support, to see if they can provide this info for you.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.