Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in
Celebration

Earn badges and make progress

You're on your way to the next level! Join the Kudos program to earn points and save your progress.

Deleted user Avatar
Deleted user

Level 1: Seed

25 / 150 points

Next: Root

Avatar

1 badge earned

Collect

Participate in fun challenges

Challenges come and go, but your rewards stay with you. Do more to earn more!

Challenges
Coins

Gift kudos to your peers

What goes around comes around! Share the love by gifting kudos to your peers.

Recognition
Ribbon

Rise up in the ranks

Keep earning points to reach the top of the leaderboard. It resets every quarter so you always have a chance!

Leaderboard

Disabling External User Access

Edited

We are preparing to implement user provisioning via Okta, and as a result, we want to completely disable any way for users to log in with any email other than the one tied to our Okta SSO. 

 For example, users can log in with username@mycompany.com with Okta SSO, but any other email will be rejected out of hand.

 Right now there seems to be an out-of-box access policy that pretty much lets people sign up with any email address they want.  This access policy is marked as a “Default” right next to our Okta policy which confusingly is also labeled “Default”

1 answer

0 votes
Mikael Sandberg
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
Nov 08, 2023

Hi @Alex Billings,

Welcome to Atlassian Community!

Those two default policies are expected, one it for the local user directory (for users that are not synced from idP) and the other one is for your synced Okta users. Each user directory can have multiple policies and the default indicate one Atlassian should add the user to. You can learn move about authentication policies in this KB

Thank you for the clarification.  Is it possible to create a policy that is just a blanket deny in this case?

We want all users to use their corp email via Okta, and in any other case simply be blocked from logging in.

Mikael Sandberg
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
Nov 08, 2023

No, but you can control that under Products > User access settings where you can add approved domains and then set what users get access to.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events