Hi Everyone.
I have read multiple articles and messages boards prior to 2024. I am wondering if, as of today June 6th 2024, has there been any progress made in the ability to enforce security restrictions on non-managed external user accounts in Atlassian Access?
I have 70% of my users managed via OKTA, but the other 30% are external users. I always fear that some of these 30% folks are using Password123 as their passwords and I can do nothing about it... No ability to apply password restrictions or enforce 2FA.
Can anyone please tell me that there is some way to enforce some security for external non-managed users? I've seen requests for this going back to 2019. If this is not a priority for Atlassian it may be the proverbial last straw for my security team.
Thanks for your help and also letting me vent.
Mike
Yes, you are able to set authentication policies for external users that are not synced from an identity provider, and it allows you to force two-step verification, password requirements, etc. Check out this KB about authentication policies for more information.
Hi Mikael:
Thanks for the reply. I've looked into this previously. Authentication policies will only allow you to add managed accounts... at least that is what I see in my ORG. No account from the "local directory" show up when I type it in.
Please let me know if I am missing something.
Thanks.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You might still be on the "old" user management interface, I just checked my instance and the invite users screen looks totally different and it allows you to enter external users, not just managed ones.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.