Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Unauthorized users added via third-party sign up

Antonina Bujinova
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 24, 2025

We have had several external users added to our system from the external domain. No one having User Access Admin role approved their access. 


I've been able to find that for some reason their domain was white-listed for third-party sign up, but unable to find any specifics on how this domain was added and who initiated their access. The Audit logs are unavailabe - throwing an error when trying to access or export them.

I've created 2 support tickets but these tickets get resolved and marked as Spam.

I'm looking for the information on how this happened and how to prevent this from happening in the future.

1 answer

1 vote
Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 24, 2025

Hi @Antonina Bujinova 

Welcome to the community.

Within the Atlassian Administration of you instance, check the User Access Settings.

control-how-users-get-access-to-products 

Antonina Bujinova
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 24, 2025

Hi @Marc - Devoteam , thank you so much for the recommendation! That's how I found that whitelisted domain that was allowing the third party sign up.

But I unfortunately can not find how that domain got white-listed. Do you have any hints on this?

Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 24, 2025

Hi @Antonina Bujinova 

If it says Any domain as the option, this is a default ootb.

If there is a specific domain added, then this has to be done by a site or org admin.

As you are not on a premium or above plan, you don't have the audit log option for the instance and you can't trace this.

You could reach out to Atlassian Support, to see if they can provide this info for you.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events