Hi,
We have enabled LDAP Authentication for our Jira Instance. As part of that, we have 3 groups created in LDAP i.e., jira-developers, jira-administrators and jira-systemadministrators. The process to get access to Jira is that the users need to raise an access request to either of these groups and once that is processed, they need to login with their user credentials (as in the Corporate Directory) and they get mapped to the group on which they raised an access request.
I understand that users get allocated to the default jira-users group if they login. We have blocked the feature where they could create their own IDs, but I understand that they can still get in without Authorization on use of the application.
Is there a way we can prevent that? Alternately, is there a way that when the user logs in for the first time, a mail is generated to the System Administrator? As a third option, when an user logs in for the first time, can they be logged in as an Inactive user to start with and it would be up to the System Administrator to make them Active based on inputs from the Application Owner or the relevant Authorizer for their access?