In reviewing our Atlassian Admin page we found several applications have been added to our account by company users who are not admins, but do have other Atlassian product licenses (e.g. Jira, Confluence) and have a company email address/domain (e.g. jane.doe@acme.com).
Reviewing the "Security, Discovered products" page we have found many Atlassian products added to our company account, which were not authorized by our IT/Atlassian admins. These Products show end users as Org Admins for the specific products.
How are these non site admin users able to add applications to our Atlassian corporate account? I would think that having a corporate Atlassian suite we as admins should be able to control who can add products to our account?
That said is there a way as Atlassian Admins to configure our suite to prevent/block company email users (non admins) from self service creating Shadow IT products in our Atlassian suite?
Our company IT should be the only group sanctioned to add products (as Atlassian Admins).