TL;DR We have tier licensing for Atlassian products at 200-300 users. Our Atlassian Guard user count is exceeding this because of the size of our identity provider sync group members. The total licensed users for each product (besides JSM) should be nearly identical (~280 licensed users).
We are using Entra ID to provision users into Atlassian through synced groups, and I am trying to confirm how Confluence guest users affect Atlassian Guard licensing.
My understanding is:
- A Confluence guest does not consume a paid Confluence license.
- A guest does not necessarily need to be provisioned through Entra ID and can be invited directly in Atlassian Administration.
- If a user is removed from the Entra ID group, has no other Atlassian product access, and is no longer provisioned through our identity provider, they should not consume an Atlassian Guard license.
- However, if that user still has Confluence guest access, they may still count as a billable Guard user because they retain access to an Atlassian product.
Can someone confirm whether this understanding is correct?
More specifically:
- Do Confluence guest users need to be synced or provisioned through Entra ID?
- Does a Confluence guest count toward Atlassian Guard Standard licensing even though they do not consume a Confluence license?
- If a user is removed from the Entra provisioning group and has no Jira, Confluence, Bitbucket, Trello, or JSM agent access, should they stop counting toward Guard licensing?
- If the user remains a Confluence guest, will they continue to count toward Guard licensing?
- Is placing guests under a non-billable external-user policy the recommended way to prevent Guard charges?
I want to make sure we are separating product licensing, identity-provider provisioning, and Guard billing correctly.