We are using read only LDAP connection with local groups for our user management, and only certain users are in the jira-users group as we only have so many licenses.
At (seemingly) random times, (seemingly) random users will be added by JIRA to the jira-users group. Often these users have never used JIRA before, don't know what it is, and have not attempted to log in or interact with JIRA, Confluence, or Stash in any way. This causes a major problem for us since having just one extra user over our license limit makes the system virtually unusable until we're able to find the user who was added and remove them from the group.
Does anyone know why this happens?