Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Privacy and Security questions surrounding user accounts and access

Carter May 3, 2022

Hello Jira Community,

I am new to the board and my organization uses SSO and Two-Factor authentication to access Jira Service Management(JSM). Please kindly advise of the below questions:

1. For users that get locked out of their account due to failed attempts, does Jira inform the users that their accounts have been locked out? We'd like to simplify our helpdesk interactions and reduce user frustration should their account meet the threshold for lockouts.

2.  What security mechanism does JSM employ in instances of lockouts? 

A) Do account lockouts consider brute-force attacks(i.e. lots of usernames with a few passwords)?

B) Do account lockouts prompts leak or provide the validity of the usernames? We're hoping that usernames are not validated on the frontend.

Thank you.

0 answers

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events