Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

How risky is it to have a customer portal set to 'Anyone can email the service project...'

Tom Brown September 30, 2022

Hi community,

I have a use case that requires a JSM Project to allow anyone to raise a request. What are the community views on the risks involved?

Atlassian recommend not using this unless unavoidable...

image.png

...and here is the security advice:

 image.png

Does anyone have experience of using this option and any tips to enhance security other than those detailed in the screen grabs provided?

Thanks,

Tom

1 answer

1 accepted

1 vote
Answer accepted
Dave Mathijs
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
September 30, 2022

HI @Tom Brown I recommend public signup for JSM:

 

Enabling public signup for Jira Service Management customer portals

With public signup enabled, agents can invite new customers to a service project, and new customers can create accounts on the Customer Portal and through email. Enabling public signup for your service project also enables a honeypot technique which helps prevent spambots from creating accounts through the customer portal.

Enabling public signup

You must first enable public signup at the system level:

  1. Log in as a user with the 'Jira Administrators' global permission.
  2. Choose Administration () > Applications. Scroll down to the Jira Service Management section and choose Configuration.
  3. In the Public signup section, allow project admins to enable public signup.

Enabling verification emails

After enabling public signup, we recommend that you also enable verification emails. This adds security to your Jira instance and makes sure that all customers are exactly who they say they are. This option should be enabled by default unless you haven't configured outgoing email.

  1. Enable and configure outgoing email so Jira can send verification emails. For more info, see Configuring an SMTP mail server.
  2. In the Public signup section, enable verifications emails.
Tom Brown October 4, 2022

Thanks for the answer @Dave Mathijs

Like Dave Mathijs likes this

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events