I'm running Jira 6.2.3. My instance is set up for LDAP authentication to Active Directory. The instance is read-only.
The problem is trying to remove jira-administrators. I'm a domain admin and have removed the users that shouldn't have admin access from the global security group jira-administrators in AD. When I force Jira to sync with AD, those users remain in Jira as jira-administrators.
Add/removing users from any other global security group works as expected when synced with jira. The added show up in Jira after I've added them to AD, and they're gone from those jira groups when I remove them from their respective AD groups.
The only group that the users are hanging on to in jira is jira-administrators.
I could manually delete them from cwd_members, but I'm not sure what the repurcussions would be if I did that.
Anyone have any idea what I've screwed up?