I have created a jira-system-administrators group in hopes of preventing the jira-administrators group from having access to domain-related settings like LDAP and AD. Am I missing something or is it not possible to prevent the jira-admin from accessing LDAP settings?
Hmm, https://confluence.atlassian.com/adminjiraserver072/managing-global-permissions-828787760.html?_ga=2.221609496.1210289335.1529944497-541760740.1525713204#Managingglobalpermissions-sysadminAboutJIRASystemAdministratorsandJIRAAdministrators just says that jira-administrators cannot configure LDAP, not whether they can view it. Looks like they can view it from what you've found.
But if they can't change the settings, are you concerned about them being able to view the settings?
I read that same article but after adding the jira-system-administrators group, the jira-administrator group still has the ability to not only view but change LDAP settings. This is a huge problem.
And you made sure that the Global Permissions only has jira-system-administrators in the JIRA System Administrators area?
Hi RM,
What version of Jira is this? I just tested this in my 7.10.1 and this works as expected.
Could you show us what your global permission settings look like? (Screenshot would be great!) It might also help to run the SQL query of
select group_id from globalpermissionentry where PERMISSION='SYSTEM_ADMIN';
This will return to us all the group(s) that have system admin rights on your Jira site.
You can then also run in SQL
select child_name, directory_id from cwd_membership where parent_name='groupnamehere';
where you can change the groupnamehere to the group name returned in the first query. This will provide all the users that have that permission right now.
It might also help to see
select * from cwd_directory;
Just to understand if you have multiple user directories.
Out of the box, Jira doesn't make a distinction between System admins and Jira admins. So if you are still finding that these jira-admins still have system admin rights, the only reason I can think that would be possible is if they are still members of a group that is granting that access here.
The actual question was whether jira-admins can view LDAP and AD configuration. I thought that they could not, but jira-system-admins could
Jira admins can not. Only the system admins can see or manage user directories settings like LDAP.
Good to know. The doc page linked at the top of this thread could make that clearer I think
It looks like you're new here. Sign in or register to get started.