Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

new user showing up enabled for access from Microsoft Teams for Confluence Cloud

Ben Derr
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 20, 2022

I wanted to see if anyone else was a bit surprised to see a brand new user showing up in their Space permissions with access enabled by default. 

As a security engineer as well as admin for our Atlassian stack, I don't appreciate new users with granted permissions showing up unannounced and I wish there would have been a better way of handing that transparently.

It did end up costing me a couple hours investigating, ultimately disabling the plugin in the System Plugins and finding that this did NOT appear to remove the user and access permissions in all our Spaces, including private ones.

I really think this should have been an opt-in app, not enabled by default.

We would really encourage Atlassian to think about how they release new plugins with potential security implications and how these might be a cause for concern in environments that are extremely concerned about privacy.

My organization has a policy of reviewing all integrations of software, and this was never something we had the opportunity to review and had to spend time figuring it out after the fact.

Screen Shot 2022-05-20 at 9.33.52 AM.pngScreen Shot 2022-05-20 at 9.40.33 AM.pngScreen Shot 2022-05-20 at 9.40.46 AM.png

1 answer

0 votes
Jurek Gurycz - JIRA ADMIN
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 24, 2022

"a bit surprised" in this case is an euphemism .. because of this I am now considering migrating out of atlassian and already started looking for alternatives .. I do not recollect trying out any Teams add-ons and users invited to the site which I maintain will be unhappy to see this user ... would love to know more what this is about

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
STANDARD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events