Hey together,
I'm in the process of migrating my installation setup to a different server.
This consists of JIRA, Confluence, Bitbucket and Crowd for Authentication.
I'm now in the process of creating Application links for the first three. To facilitate that process, I created a "System-Superuser" that has administrative privileges on JIRA, Confluence and Bitbucket. During the link creation, I'm therefore checking "I'm Administrator on both servers" to get the reciprocal behaviour.
However, to implement least privilege, I would like to restrict an account with "System Admin" privileges to one application before going into production (for example only one user with the group "jira-administrators" who doesn't even has user access to Bitbucket).
So, my question is: For application links, is it necessary to leave the account the link was created with? Once the link is established, is it necessary to have a user that is system administrator on BOTH sides (for example JIRA and Confluence) at the same time?
Greetings Marcus