I was looking forward to the mods to site-admin vs org admin,but it doesn't seem to be helping my internal confluence instance. We are using the Azure Connect for Nested Groups, which will sync a list of azure groups as seen under Security/Identify providers every 4 hours.
My service desk team adds additional groups relatively often (several times a week?). They don't have access to this location, so they need to contact an org admin to adjust the security of a confluence space (once the azure group is added to Atlassian and the sync runs, they can do the permissions work on the space).
I had hopes that the recent mods to site-admin could get them to where they could admin the user groups, and if we only used inside-atlassian invitations, that would make sense, but right now, actually adding new groups from Azure is not something I can give them without giving them OrgAdmin, which I am loathe to do.
Am I missing something? Anyone else hitting this limitation? Got any work arounds?