I have a scenario where custom groups have been created in confluence. Space admins generally add the users who are entitled to see the contents of space to the group.
Now there have been cases where the space admin do not do due diligence and instead of creating the custom group and adding the users to the group, they directly attach the confluence-users group to the space. Now confluence-users group have all the users as the members. This poses a security risk where some of the restricted contents gets exposed to the unintended users.
I am trying to explore a solution where we can disable the right to add the confluence-users group or hide the confluence-users group from getting displayed in list of groups to the space by space admin by default. Confluence-group can be added only by confluence tool administrator if the space admin follows a particular approval mechanism of the organization.
No. You need to train your admins to be more careful.
The ability to add any group to a Space is critical, because most users need that (and you'd end up with lots of people saying "I can't find the group I want to add"), so Confluence has no functions for restricting the choice of groups.
What you could do is remove the confluence-users group completely, and add common groups into the "can use confluence" permission separately.
I'm sorry, but that makes no sense. What would "hiding a group" from a space actually do?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
(Question updated, so this is not a good answer any more)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.