We would like to allow "Public links" for our colleagues (without access to Confluence) as "ready only" and only with our company domain.
Can this policy be set up somehow?
Thank you
Jan
Hello @Jan Velebny
To allow your company users without Confluence seats to access confluence content, you can use one of the follownig apps.
(To my best knowledge, only those two apps can help)
The app
a) creates a static website from you Confluence content
b) allows you to control access to that website with your SSO scheme.
At Emplifi, we're using Scroll Viewport to create a static website with the Internal version of the documentation and controll access with our SSO. You can determine who from your employees has access to such a site - all, specific roles, etc.
HI @Jan Velebny
No this is not possible, a created public link can be viewed by anyone on the internet if they have the link and as long as the link is active.
The content is always view only.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Jan Velebny as @Thiago P _Atlassian Support_
mentions,
Whitelisting can be an option, but it can be cumbersome if people need or want to access the pages outside the office.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hey there @Jan Velebny ,
As @Marc - Devoteam mentioned, Public Links are available to the whole Internet as long as they have the direct URL to the page (which is not indexed by search engines such as Google).
However, using Public Links in combination with IP Allowlist policies should work for you as access can be restricted to your Site for a specific list of IPs (or IP ranges using CIDR notation) used by your Company. Usually offices and VPNs have predefined outbound proxies that can be used for this.
Make sure to check our documentation: https://support.atlassian.com/security-and-access-policies/docs/specify-ip-addresses-for-product-access/
A few worthy notes:
We have seen a number of Customers implement this strategy, either with Public Links or Anonymous Access.
Hope this helps! =]
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hello Thiago,
thanks for your reply, very usefull.
In case we implement IP Allowlist policy, we will not affect our guest users outside of our organization? or users with we shared pages via "external share", will they have still access to contect where they had access before?
Thanks
Jan
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Jan Velebny , great question.
All users - including Guests - will be affected by IP Allowlist policies.
If you have Guests from outside your Organization, you'll need to include their source IP ranges as well.
If that's not a viable approach, then restricting Public Links to your company will not be possible.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.