We are using Jira and Confluence. While all employees have access to Jira, only a select few of them have access to Confluence. At least, that is the intention. As far as we can tell we disabled all features that allow users to requesting product access or gain it themselves and allow access only with org admin permission. However, today an employee got Confluence access twice.
First, he got a (unwanted!) popup stating "Your team is using Confluence. Want to join?" and with one button click he got access bypassing all policy settings.
Second, after we removed access again, he just logged in to <domain>.atlassian.net and by that alone he got Confluence access again.
From our perspective this is a really anoying behavior of Atlassian cloud services.
Since we seem to still miss some setting that allows this behavior: how can I shut it down permanently? We do neither want ads for other products, nor options to request access, nor any option to "self service access".
Any help is much apreciated.
PS: We don't use Atlassian Guard, but all our users are within our organization from a verified domain and managed accounts.