Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Restrict Jira project admins from adding jira-users group to a project role

Ravish Nayak April 1, 2023

Jira Project Admins can add any group (main target is jira-users group) to any role in a project.  This causes instance performance issues in combination with notification schemes (sending email notifications to thousands of users in big instances for thousands of notifications) and security disclosure issues with these notifications sent to all Jira users.

Is there a way to block jira-users from project admins? or any workaround solution to hide jira-users groups? Please suggest.

 

1 comment

Alex Koxaras _Relational_
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
April 1, 2023

Hi @Ravish Nayak 

I'm afraid there isn't a way to prevent this. This is an old post (date back to 2013) https://community.atlassian.com/t5/Jira-questions/Restrict-Project-Admins-from-adding-jira-users-group-or-all/qaq-p/357580 but I think that it still applies.

Like Vikrant Yadav likes this
Ravish Nayak April 2, 2023

Hi Alex,

Thanks for your reply, after going through above link this line made me think about this

"script something that regularly removes jira-users if it's found in any roles"

So please suggest is this approach is still valid? and any other impact?

Like Nihar Kumar Dalai likes this
Nihar Kumar Dalai June 5, 2023

@Ravish Nayak  Hi Ravish - We have a similar scenario  https://community.atlassian.com/t5/Jira-discussions/Permission-strategy-for-Jira-access-by-external-users/td-p/2371733

Were you able to implement something to send alerts at least if not come up with a restriction ?

Comment

Log in or Sign up to comment
TAGS
AUG Leaders

Atlassian Community Events