• Community
  • Products
  • Jira
  • Questions
  • Can we have an User , by which we can configure an application link in JIRA and that user should not be able to login to JIRA by JIRA Login Screen

Can we have an User , by which we can configure an application link in JIRA and that user should not be able to login to JIRA by JIRA Login Screen

Hi All,

 

I have an situation , where i want an user who should be able to configure application link and that user should not be able to login to JIRA from JIRA login scree. if there is a way help will be greatly appreciated.

This is due to some security reasons we want this behavior to happen.

 

Thanks

Avdhesh Chauhan

1 answer

1 accepted

2 votes

To be able to configure an application link, a user must have administrative rights.   If you have admin rights, you can log in.

So no. 

I'm also curious - what sort of logic gets you to this requirement?  It sounds like complete nonsense to me.

i know this point that to configure applicaion link a user should have the ADMIN permission to JIRA but is there any way so that we can prevent this user to login to JIRA by JIRA login screen as we have so many confidential projects in JIRA and if any employee from our organization came to know the password for this user anyhow then there will be a big problem so we want to user which can be used to Login by application link and should not be able to login by Login screen of JIRA, is there any mechanism we can do that. Thanks Avdhesh

No. They can log in. They can't change admin settings without being authenticated, so it allows loing. This does sound very much like a broken requirement. Why do you want this?

Thanks for reply Nic, As stated i am afraid if the credentials for this user is leaked any how then there is a possibility to leak our confidential data to our customers as we use this account to link our External Customer Facing JIRA and Internal Organization JIRA. Thanks Avdhesh

No, sorry, not wanting to give admin to other people is absolutely right. What I don't understand is the requirement to change application links without logging in. Application links should change rarely and should only be updated by Administrators that understand them. Your desire to let other people do it is a massive security risk even if you implemented what you're suggesting.

Hi Nic, I am Administrator to both the JIRA instances, and i will user my login credentials to configure application Link, but in Oath section authentication we dont use our personal credentials to configure application link, So i will login with My User Profile and configure the application link with the service Account created to serve the purpose, Our both JIRA Instances has the diffrent User Base. so is there any way to prevent this service account to login to JIRA from JIRA login screen.? Thanks Avdhesh Chauhan

That does not explain what the requirement is. Configuring application links is something that should only be done by proper JIRA administrators. Letting someone else configure them would be a security hole. I don't understand *why* you want to do this. Log in as yourself and configure the link. You don't need or want a service account to do that.

Well Avdhesh - not only that specific user that you are trying to configure . But any other user - if the credentials are exposed , anybody would login , I think the justification to your requirement lacks logic :-)

I just can't see a need for an account to do this one single piece of configuration work. Your admins should do it.

yeah thanks for your help :)

Suggest an answer

Log in or Join to answer
Community showcase
Sarah Schuster
Posted Jan 29, 2018 in Jira

What are common themes you've seen across successful & failed Jira Software implementations?

Hey everyone! My name is Sarah Schuster, and I'm a Customer Success Manager in Atlassian specializing in Jira Software Cloud. Over the next few weeks I will be posting discussion topics (8 total) to ...

3,279 views 14 20
Join discussion

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you
Atlassian Team Tour

Join us on the Team Tour

We're bringing product updates and pro tips on teamwork to ten cities around the world.

Save your spot