Got a "Identity Manager is now Atlassian Access " email from Atlassian.
It made me grumpy ...
We are using JIRA in our company and I did activate the Identity Manager some time ago so we could protect our access with 2FA Two Factor Authentication. (if I remember correctly)
Now it seems that this is now an out-of-beta service that will be billed $30 per month from August. Am I missing something or Atlassian is charging to have 2FA now ? Anyway around it ?
This seems unbelievable for such an essential and basic feature for an online service... and frankly we will not afford $30 for this (ie doubling the cost of the service).
It is like charging users for having strong passwords:
"For $5/month extra you can now have 1 additional character in your passwords, (upper and lower case letters allowed for free for a limited time)"
Hi,
And that's good and all. But how do I list all users and view if they comply to the manual enforcement. I can't find anywhere to list my users MFA status.
Thanks!
We just migrated to the cloud (had to, unfortunately) and I wanted to enforce the second factor for all our users because the data we store in this service is very sensitive information. Unfortunately we'd be forced to pay another $160/month to be able to enforce the industry standard that is recommended everywhere from anyone. There is and should be no professional service where this is not possible. More and more companies make it mandatory - for good reasons.
On top of that, I also expected there would be more 2nd factor options including Passkeys support.
But: Nothing. Very disappointing.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
In my opinion, this only shows how far behind and sick Atlassian are, making companies pay to enforce 2FA is just outdated, irresponsible and downright pathetic. Grow Up Atlassian! You are a farce to have this kind of attitude towards security.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
That works and you dont even have to view each account individually. Just export a csv file of all users and there is a column "Two-step verification enabled" that will give you the consolidated data.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
I have discovered how to check if 2FA is enabled (for users using email domains that you have control over)
1. Add the required TXT record to the email domain see:
https://confluence.atlassian.com/cloud/verify-a-domain-for-your-organization-873871234.html
2.Now visit Directory > Managed Accounts and click on "Show details" for each user. Under the Security heading you will see if 2FA is enabled for the user.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
2FA is essential to maintain security and it's therefore essential to be able to check that all users are using it! I also need to check if all our users are using 2FA as it's no longer being automatically enforced. I can't justify the cost of the Access service just to check if users are using 2FA!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
As per Lars, how can I as an admin see which of my users have 2FA enabled? This is an essential ability.
Thanks.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Fantastic!
Thanks @Rodrigo B_,
I will have a look at disabling Atlassian Access and maintain our 2FA then... we can live without enforcing it automatically :-) good old manual enforcement and psychological pressure will do for our users
I knew this was too bad to be true
Thanks again
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello @Erwan Cosnuau,
Welcome to the community!
Atlassian is not charging for 2FA, all Atlassian accounts can still enable it and use without cost, the feature that is part of the Atlassian Access product is the Enforced Two-Step Authentication, which is additional administrative control to enforce this policy to all Atlassian accounts under your verified domains, you can see more details below:
Documentation regarding 2FA for Atlassian accounts
And documentation regariding Enforced 2FA for Atlassian organizations
Kind regards,
Rodrigo Becker
Atlassian Cloud Support
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.