We have hundreds of users and dozens of projects. User management is linked to ldap and all users are part of the jira-users group. jira-users are by default in a role in every project which allows them to browse and create issues.
I have a couple of projects that I want to deny browse and create permission to a small group of users.
Can I do this without modifying every project, while continuing to allow new users to automatically be able to browse and create issues in the target projects?
If I pull the blacklisted out of the jira-users group, then I have to modify every other project to include them explicitly. If I leave them in jira-users then how do I let everyone else browse/create?
It seems like I can't use the project role permissions to do this. So how do I do this?