Ever since we transitioned to Single Sign-On (SSO), new users are no longer automatically enrolled in our "jira-users" and "confluence-users" groups. Instead, they are included in groups synchronized from our Identity Provider (IDP). While we've replicated global permissions, Jira permission schemes, and space permissions, and integrated these groups for product access, we've encountered a hurdle: the inability to switch default access groups from the product permissions admin page. The option is absent, and the tooltip indicates: "this is a read only group and cannot be set as default." This raises two questions:
Can we modify default access groups to a synchronized group, and if so, how?
Considering that permissions and access are synchronized with default access groups, what impact does changing the default access group have, especially considering new users aren't automatically assigned to the group by our IDP?