Is there a Cloud API yet to revoke access to the product/Instance for either managed or unmanaged accounts?
ie the Have Access Switch accessible via the REST API
Seems strange that this ability is available in Server but is still not available in the cloud version.
Just looking for a cloud version of the server PUT version that allowed you to set the active status to either true or false
ie Cloud version of: https://docs.atlassian.com/software/jira/docs/api/REST/8.3.0/#api/2/user-updateUser
curl --request PUT \
--url 'https://your-domain.atlassian.net/rest/api/2/user' \
--user 'email@example.com:<api_token>' \
--header 'Content-Type: application/json' \
--data '{
"accountId": "{accountId}",
"active": false
}'
Is there any other workaround to perform this via API/Automation?
There are multiple tickets and threads on this, and seems strange that this still cannot be done.
Part of this work is so that we can implement least privilege for people to onboard and offboard users, without making them site admin, trusted or product admins.
As those roles/groups provide too much access, and allow those users to add marketplace apps without permission, and change permissions, etc
We have already had several incidents with those roles, so we are looking for a different way to onboard and offboard.
Currently have project with linked automations that:
Only user in a certain group can resolve the tickets, and the automation kicks off at the relevant ticket resolution.
- Onboarding
- Adds user to instance,
- adds user to AAD,
- adds user to relevant AAD groups,
- adds non federated users to relevant Atlassian groups
- Offboarding
- Left the team
- Removes from AD Team group(s)
- Removes from Atlassian Team group(s) - for non federated domain users
- Left the business
- Removes from all relevant AD groups
- Removes from all Atlassian groups
- Attempts to Deactivate user
- Attempts to Delete the user
- Moves user to a dummy group, where they can be manually switched off (active to false)
Which prevents mistaken or disgruntled re-access.