Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Is there a way to prevent Jira (and Confluence) admins from using the Atlassian MCP server?

Matt Deimler
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
July 31, 2025

There is a concern that a Jira user with elevated permissions, like a Jira admin, having access to and using the Atlassian MCP server, creates a risk. In short, we'd like a standard Jira user to be able to use the MCP server, but in some instances, block or prevent a user with elevated Jira permissions from using it. Is that possible?

2 answers

2 votes
Marc - Devoteam
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
July 31, 2025

Hi @Matt Deimler 

Welcome to the community.

Going over the documentation, I think not.

https://support.atlassian.com/rovo/docs/getting-started-with-the-atlassian-remote-mcp-server/ 

Within the article, there is a feedback suggestion option, provide your concern there.

But the same applies to the API and elevated user has more permissions than a normal user, this can't be denied to Jria admins as well.

In my opinion people with elevated rights should no the risks based on the elevated permissions they have.

And if it could be limited admins can't use the option, thant wold be strange, not?

Matt Deimler
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 1, 2025

Thank you for the reply.

0 votes
Vitalii Rybka
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
August 1, 2025

Hi @Matt Deimler,

I understand the security concern, but as @Marc - Devoteam mentioned, this would be quite unusual from an access control perspective. Here's why this restriction isn't typically possible:

Technical Reality:

  • MCP server access is tied to API permissions, which admins inherently need for their role
  • Blocking admins from tools that regular users can access breaks the standard permission hierarchy
  • Most enterprise security models assume admins are trusted with elevated access

Alternative Approaches:

  1. Audit & Monitoring - Track MCP server usage through Atlassian Access logs
  2. Role Segregation - Create specialized admin roles with limited API access for day-to-day tasks
  3. Conditional Access - Use IP restrictions or device policies to limit where MCP can be accessed
  4. Approval Workflows - Implement organizational policies requiring approval for MCP usage

Recommendation: Focus on governance rather than technical restrictions. Establish clear policies about when/how admins should use MCP, with regular access reviews and monitoring.

The feedback option Marc mentioned is definitely worth using - Atlassian might consider adding granular MCP access controls in future releases.

What specific risk scenario are you trying to prevent? That might help identify better mitigation strategies.

Feel free to DM me if you want to discuss specific security architectures!

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events