• 44
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      At this moment, user provisioning sync all the users and groups to all the sites below the hierarchy in the Atlassian organization where it is setup.

      This suggestion is to add flexibility and make it possible to configure which users and groups you want to be mapped to specific sites instead of having all to all mapping.

      Example of scenario:
      A company has an organization with multiple sites and want each of them to have only a subset of the user provisioned users and groups being synced into each site.

            [ACCESS-1164] Ability to sync users to sites based on the groups

            Hello,

            Any news on this topic?

            Nicolas Le Corno added a comment - Hello, Any news on this topic?

            We are a large organization with multiple affiliate companies.  Because in our industry we have certain "business firewall" rules we must to adhere to, this issue could prevent us from bringing those firewalled divisions on to Atlassian products and cause us to seek a solution with better control. 

            Marty Toscano added a comment - We are a large organization with multiple affiliate companies.  Because in our industry we have certain "business firewall" rules we must to adhere to, this issue could prevent us from bringing those firewalled divisions on to Atlassian products and cause us to seek a solution with better control. 

            We've just moved to an Access subscription and an identity provider SCIM sync, with 14 sites and thousands of centralised users. This new behaviour is quite an annoyance for the existing site admins who have small instances. Previously, their user admin UI would show just those users licensed for the site. It now shows them thousands of users from across the business, all being automatically granted site access (even though most of them will never be granted product access).

            Ben Middleton added a comment - We've just moved to an Access subscription and an identity provider SCIM sync, with 14 sites and thousands of centralised users. This new behaviour is quite an annoyance for the existing site admins who have small instances. Previously, their user admin UI would show just those users licensed for the site. It now shows them thousands of users from across the business, all being automatically granted site access (even though most of them will never be granted product access).

            I'm strongly in favor of implementing the proposed capability to map users to specific sites
            Enabling user access to be defined at the site level, rather than to all sites, allows admins to tightly align access to business needs. Users can be provisioned for only the specific resources required for their role. This will improves security and prevents over provisioned access.

            Swetha Keshavula DISH added a comment - I'm strongly in favor of implementing the proposed capability to map users to specific sites Enabling user access to be defined at the site level, rather than to all sites, allows admins to tightly align access to business needs. Users can be provisioned for only the specific resources required for their role. This will improves security and prevents over provisioned access.

            Lacking this feature is a privacy issue.  Consider a large publisher who has several different studios under their license.  A site admin at Site A being able to see the email accounts for other Sites could break NDAs and cause a media leak.  If someone discovers that Site B has a bunch of @epic.com email address with access to that site, then it's a pretty easy assumption that Site B is working on a game in the Unreal Engine.  That is unacceptable to most Studios.  Not to mention there's no data hygiene under this model.  If a new Site misconfigures their AAD sync as part of the onboarding and syncs their entire Directory instead of the prefilled access groups, now each site could potentially have THOUSANDS of unnecessary records clogging up the system and causing UI overload for Site admins with no control over that addition. 

            Jason Hawks added a comment - Lacking this feature is a privacy issue.  Consider a large publisher who has several different studios under their license.  A site admin at Site A being able to see the email accounts for other Sites could break NDAs and cause a media leak.  If someone discovers that Site B has a bunch of @epic.com email address with access to that site, then it's a pretty easy assumption that Site B is working on a game in the Unreal Engine.  That is unacceptable to most Studios.  Not to mention there's no data hygiene under this model.  If a new Site misconfigures their AAD sync as part of the onboarding and syncs their entire Directory instead of the prefilled access groups, now each site could potentially have THOUSANDS of unnecessary records clogging up the system and causing UI overload for Site admins with no control over that addition. 

            WPG added a comment -

            I would suggest under Site access or Product access at the site level you add a feature.

            Sync all users and groups from User provisioning Directory

            Sync existing Users in site with User provisioning Directory

            WPG added a comment - I would suggest under Site access or Product access at the site level you add a feature. Sync all users and groups from User provisioning Directory Sync existing Users in site with User provisioning Directory

            For Jira Enterprise Plan and Atlassian Access customers that have multiple Jira Cloud sites there is a need to distribute the initial provisioning of a user at a customer organization level. Not all users need or should be given access to all sites. If users transition between the customer AD organization administration that should propagate to and sync with Atlassian Access

            Rich Wolverton added a comment - For Jira Enterprise Plan and Atlassian Access  customers that have multiple Jira Cloud sites there is a need to distribute the initial provisioning of a user at a customer organization level. Not all users need or should be given access to all sites. If users transition between the customer AD organization administration that should propagate to and sync with Atlassian Access . 

              maho Matthew Ho (Inactive)
              6048cd401523 Felipe Oliveira
              Votes:
              55 Vote for this issue
              Watchers:
              47 Start watching this issue

                Created:
                Updated: