Hi Community,
yesterday we had login issues into Jira Cloud and later on also we experienced multiple problems in our Jira instance. There was a former user already active (Org admin) and we have the feeling, this user could have manipulate some settings. But the Jira Audit Log and the Org Audit Log do not display anything relevant from this user. Also we checked the Global Automation Log Files with any detection.
The user has been disbled, but what is possible to do for an Org admin without being logged? I tried some actions like IP allowlist or Automation Rules deleting stuff (and than delete the rule), but all actions are logged correctly. We want to know if there are security gaps we have to take care on.
Thanks a lot for your ideas.