Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Does the 2FA keep working with the new Security setting for external Users turned on?

Cornelia August 1, 2023

I would like to enable the two-factor verification for external Users, which was lateley implemented.

If I do so, what happens with the 2FA already set up by external Users? Will this stay and nothing changes to them and they wont even notice or will they receive the one-time passcode by mail after enabling it? 

Thanks and Regards,

Cornelia

2 answers

1 accepted

1 vote
Answer accepted
Kian Stack Mumo Systems
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 1, 2023

@Cornelia

 

I just tried this out. It made me sign in through my SSO and then also enter the OTP Atlassian emailed me.

 

Thanks,

 

Kian

Cornelia August 3, 2023

@Kian Stack Mumo Systems 

Thank you very much for trying this out.

Now I know I have to inform the external users before I activate the security feature. 

 

BR, Cornelia

1 vote
Bhavya Nag
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 1, 2023

Hi @Cornelia ,

I'm the Product Manager for the external user security feature (the security settings that you see under "External users" on Atlassian Administration).

Any 2FA settings on an account continue to apply when you turn on external user security settings. The way this works is as follows.

Let's say that xyz.com is a verified domain under your organization and external users are from abc.com:

  • These users from abc.com will log in to their Atlassian accounts as they do today, subject to any 2FA settings configured by the individual users or enforced as part of authentication policies by the admins of the org under which abc.com is a verified domain.
  • After they log in, before they can access your organization's content, they would be subject to two-step verification that is enforced by your organization (i.e. the org under which xyz.com is a verified domain) if you turn external user settings on. Currently, the only supported method for 2FA is an OTP via email, but we are also planning to support SSO enforcement for external users in the future

If you'd be interested in discussing your needs with regard to external user security in more detail, please email me at bnag@atlassian.com and I'd love to discuss this topic in more detail.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
TAGS
AUG Leaders

Atlassian Community Events