I just set my site up as an organization, so that I can add Atlassian Access and enforce password management, allow for single sign on, and be able to have admin level rights to the audit log. However, I just noticed that I can only apply Atlassian Access to the domains that I own. My site is for a multiple team contract including federal government, state government, various contractors and consultants across multiple domains. 97 to be exact. I will only be able to verify my own domain, not the other 96. So if I read everything on your site correctly, there's no way I can enforce ANY security feautures unless those accounts are on my own, verified domain?? How is this okay?? That is a huge liability and it doesn't help secure our site at all.
Please tell me I'm wrong and that there is another way to require users of my site to change their passwords and choose more secure passwords than "123"