Uploaded image for project: 'Atlassian Access'
  1. Atlassian Access
  2. ACCESS-1558

IP Allowlist audit log to include incident and IP address of blocked requests

    XMLWordPrintable

Details

    • Suggestion
    • Resolution: Unresolved
    • Audit Log
    • None
    • 5
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

    Description

      Problem Definition

      The organization audit logs related to IP allowlisting is not sufficient to know when connections are blocked by the allowlist. For security auditing purposes, admins should be able to see data on when blocks occur. 

      We would like logs specifically around documenting user/IP information when a user is denied access because their IP does not fall under any of the ranges set in the Atlassian allowlist.

      Suggested Solution

      Please add all the details for any blocks that happen when connections are denied by the IP allowlist in the organization audit log entry.

      Examples are:

      • User Name of blocked attempt
      • IP address of blocked attempt

      Why this is important

      This is important to track when a blocked attempt is made for security auditing purposes. We would like logs specifically around documenting user/IP information when a user is denied access because their IP does not fall under any of the ranges set in the Atlassian allowlist. Currently, admins have no visibility to these events.

      Workaround

      No workaround is available right now

      Attachments

        Issue Links

          Activity

            People

              jyu@atlassian.com Jonathon Yu
              6b2430609069 Alexis
              Votes:
              6 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated: