We have configured authorization in Jira via LDAP User Directory with the Microsoft Active directory type, with a configured filter, users who have the required group in the domain can authorize in Jira. After the user is dismissed, he is removed from the group with access to jira and the account is sent to the injective, users who were active in Jira and were removed from the group in the domain after the restart of jira become active.