Refering to this article https://support.atlassian.com/jira-service-management-cloud/docs/remove-confluence-product-access-for-users-in-your-site/ I can't see the option "Manage product access" in the Product access -> Confluence -> More menu (⋯) like described in step 2. a. iii.
Further I can't find the option New users have access to this product described in step 3.
Problem: Security issue about users getting access to confluence despite the user don't has product access to confluence nor is in any group with access to confluence.
We are using Jira Cloud and Confluence Cloud and I want to keep some users out of our confluence wiki, because they are external and are forbidden to see our confluence wiki at all.
But as I tested today every jira user created by us who don't has access to confluence can compromise the Atlassian Administration configuration! The external users are configured in https://admin.atlassian.com to only have access to jira software, but not confluence (!).
As soon as an external user logs in, opens the menu on top left (nine dots in the square), switch to "Confluence TRY", then he can click on "test now". The page reloads and displays the message that confluence is already active. Then the external user can click on "go to confluence" and then he gets access to it and to all internal spaces and sites!
When checking the user's configuration, he got all from sudden access to the product "Confluence" with product role "Users" and is added to the group "confluence-users"! Both entries were nonexistent before! So this is a huge security issue, when I can't fulfill the requirements of my company to deny access of external users to our confluence wiki!
Any ideas?