Unintended user appeared in our cloud account

scott coleman December 3, 2021

We got an email this morning that someone from outside our organization was added to our Jira/Confluence account.  

None of our admins added him. When I called him he said that he joined by clicking a link from his company's self-hosted Confluence (without an invite from us).

This is very strange. We need to figure out just how he got in. I'm catching a lot of heat for this.

I tried looking at the security audit log but apparently, you need to purchase the "Access" license to see your security log

2 answers

1 accepted

1 vote
Answer accepted
Earl McCutcheon
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
December 3, 2021

Hello @scott coleman ,

As the user noted that they clicked a link to gain access it sounds like the user found a "Invite link" to the site, covered in more detail in "Specify how users get site access" but noting the warning:

Once you have shared an invite link, anyone can use it to create a new account. For this reason, you should only share invite links with people you trust. As an added security measure, invite links automatically expire after 30 days. You can also turn off invite links at any time, rendering any old links invalid.

I recommend first checking the link that the user used to access the site to verify if it is in the invite link format, and it will look something like this:

https://id.atlassian.com/invite/p/jira-software?id=<random hash value here>

You can go to your site's admin at admin.atlassian.com, then Select Site access > Invite links, and if there is an invite link present you can disable the link by selecting the green selector switch next to the link.

Regards,
Earl

scott coleman December 3, 2021

Thanks, I noticed that I had some external domains approved and removed them.

Like # people like this
0 votes
Joshua Sneed Contegix
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
December 3, 2021

Hi Scott,

You may want https://support.atlassian.com/contact/#/ instead of the community. Cheers!

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Site Admin
TAGS
AUG Leaders

Atlassian Community Events