I have read documentation that says that you cannot apply a password policy unless you verify a domain for your organization (https://confluence.atlassian.com/cloud/verify-a-domain-for-your-organization-873871234.html).
However at my company our email addresses aren't a publicly accessible domain. It is only used for our email address (me@abc.com) as well as internal routing to a company intranet page when you're on our corporate network. (www.abc.com is only accessible in the corporate network and assume there's no such public website as www.abc.com otherwise)
Additionally we send invites for Jira & Confluence to external business vendors and international business partners as well. Whlie Atlassian specifies:
You want to verify a domain that you don't own
To protect the privacy and security of Atlassian's users, it's not possible to verify domains that you don't own.
If you'd like to apply Atlassian Access security policies for these users, ask them to change their email address to a domain that you can then verify, or invite them to create Atlassian accounts that use email addresses from the domain.
In actuality many corporate security teams have mandates on password policy criteria, much of which Atlassian does not enforce by default and therefore a security issue in itself (I believe I read passwords just have to be 8 characters, and that's about it).
Are there any plans to allow for account administrators and owners to take more control over those contributing to their cloud based Jira/Confluence/Bitbucket accounts by allowing for more security enforcement without the overhead of domain validation which cannot be satisfied?