Has anyone found a simple way to whitelist domains so that ONLY users from specific domains can be added to minimise risk of errors by admins?
e.g. I want only users with emails ending @Yellow.com and @blue.com to be eligible to join an instance
I've searched but can only find options to whitelist entire domains so that anyone from them can register etc...
Hi @Kit Friend
You can whitelist specific approved domains using the user access settings - see this help page
Or is it more complex than that with sub-domains, eg.
---
If yes, I'd probably look at user provisioning as a first option (albeit outside the platform).
An alternative would be to also direct users through a JSM help desk (or an equivalent ITSM tool) and use APIs / Automation to trigger this, eg.
Ste
Thanks @Ste Wright that's the page I got stuck at before tbh.
My understanding of that page (and the config) is that it works well if I want to say "let everyone from @test.com sign up themselves" but (I believe) it doesn't stop people from other domains being added.
My use case is basically that I want to stop admins accidentally opening up access to users outside a company.
My brain is furring up ahead of the weekend but I think that the user provisioning route would need me to be doing it at domain level? I'll have a read with fresh eyes perhaps :)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi @Kit Friend
I'd consider whether the accidental domain adding could be managed through training and good security practices - i.e it's not a setting to never look at, it should be reviewed on a semi-regular basis.
For user provisioning, I'd encourage checking out the help page on this as a good starting point: https://support.atlassian.com/provisioning-users/docs/understand-user-provisioning/
Ste
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.