On our cloud location a few unknown persons entered, which were self-created and counted as users. These were from 2 different domains
The persons themselves we re not aware (they were in the domain which was defiend, but were not invited and did not have any stake in the project).
with 1 'unwanted'user i found out how it happened:
******quote
Hi Getjan,
Apologies for the issue. I was attempting to log into my corporate site but was redirected to the standard Jira log in. It had been a while since I had logged in, so I accidentally went to the wrong login (standard login rather than our corporate login). Once I chose Access Using Company, I had the option to choose two groups. This was odd to me but as I have recently returned from an extended leave, and our login is all controlled by our corporate account, I thought perhaps I had to reregister. Once I logged in using my corporate email, I was redirected to an admin screen to choose which group I wanted to log in with. I chose the available group, but it redirected me to your site. As soon as I realized this occurred, I immediately logged out. If you would like to remove me from your site, that would be great. Our email accounts apparently allow access to your site if we register using our corporate account.
******unquote
How can we secure this that corporate users are offered only their corporate accound?