Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1682

Add Last Authenticated in the User’s last active dates API

    • 9
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      User Problem

      Org Admins want to manage the number of users and their license seats, and having Last authenticated key and value in the last active dates API is essential to better manage users in one's organisation.

      Currently, users often use the Last Active values of each product to judge whether to deactivate/revoke access from them. However, this value is not always accurate for some products under certain situations.

      • ID-8132: Managed account last activity date for Trello users without product access
      • JSDCLOUD-10148: Enable "Last seen on" activity for Atlassian accounts with only site access(JSM customers)

      This behaviour is affecting especially those who are automating the process.

      Suggested Solutions

      1. Call the User’s last active dates API
        User’s last active dates
      2. The result contains an additional Last authenticated key and value

      Current Workarounds

      No way to obtain the Last authenticated information

            [ACCESS-1682] Add Last Authenticated in the User’s last active dates API

            Please be aware that a continuous user might not have to login on GUI for a longer time, so the time of last login might be too old. You do not enforce re-login on the sessions very often (we can enforce a re-authentication but this does not count as login as user does not logout when doing this, it is the same session).

            Bruno Abele added a comment - Please be aware that a continuous user might not have to login on GUI for a longer time, so the time of last login might be too old. You do not enforce re-login on the sessions very often (we can enforce a re-authentication but this does not count as login as user does not logout when doing this, it is the same session).

            "Last authenticated" might help, but please be aware also "technical users" are active, who only logged in once to get an API token, and since then never logged in again via GUI, but access data via API every day and they consume licenses too. They do also not watch web pages, which is how the "last active" date is calculated.

            Bruno Abele added a comment - "Last authenticated" might help, but please be aware also "technical users" are active, who only logged in once to get an API token, and since then never logged in again via GUI, but access data via API every day and they consume licenses too. They do also not watch web pages, which is how the "last active" date is calculated.

              Unassigned Unassigned
              a9811fcf7424 Kaz Nobutani
              Votes:
              3 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated: