We current use the following Atlassian products:
- Confluence
- Jira Service Management
- Bitbucket
We have the 2FA enabled via Atlassian and that covers all the Atlassian tools listed above. So if I want to log into any of those services, I need to provide a 2FA code. This 2FA is handled at the admin level (which makes it relatively easy to manage when someone loses a phone, etc.).
However, there is also the option to enable 2FA at a user level in Bitbucket. And this is enforced when setting up a new Bitbucket account. I'm assuming the reason for this is that the Atlassian 2FA is applied to all users with the relevant email domain.
This introduces a problem because the Bitbucket 2FA is not managed at an admin level and it is completely unrealistic to expect non-IT users to understand the importance of recovery codes, etc. So if they lose a phone and don't have recovery codes they are completely locked out of their Bitbucket account.
The workaround we have come up with is:
- Setup the account in Atlassian. 2FA is enforced at an admin level
- The user must set up 2FA when the connect to Atlassian
- The user must set up 2FA when they set up their Bitbucket account using the appropriate domain.
- We ask the user to disable the 2FA for Bitbucket ASAP. They must do that themselves because each user is the admin of their Bitbucket account.
With this approach, if anyone wants to connect to Confluence, JSM or Bitbucket, they must first provide the 2FA for Atlassian. There is no requirement however to provide a 2FA code specifically for Bitbucket.
The question is whether there is a better approach than what I have described above? Is it possible to remove step 3 and 4 from the above process?