Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-1766

Prevent non-administrators from creating new Atlassian Cloud Organizations

    • 81
    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Context
      Enterprise organization admins have the ability to deny the creation of new sites by using product request settings to require admin review.

      That being said, it is not possible to prevent non-administrative users from accessing the https://admin.atlassian.com/ site.

      If said user has no org admin rights to any organization (or is stumbling on this page for the first time) the user is then redirected to https://admin.atlassian.com/o/create or https://admin.atlassian.com/o/create?from=atlassian-access

      This provides the user the ability to create a new organization (see screenshot)

      Idea
      Either:

      • Completely block non-administrative Atlassian Accounts from reaching the https://admin.atlassian.com/o/create endpoint
      • Or provide an administrative setting to block the creation of new organizations

            [ACCESS-1766] Prevent non-administrators from creating new Atlassian Cloud Organizations

            Another product created today. I started the deletion process and tried to see if it was time to complete the process for old products...some of them are showing warnings I do not know how to fix, some others are there sitting for the 90 days.

            Can you please read carefully the comment by 75f3e0bc41b1  who is sharing some useful suggestions for you if you care about customers' experience!! Do you really need a customer to suggest these basic customer journeys to be implemented?

            I've been contacted and I have in my network a dozen Atlassian account managers who want to do upsell but none is caring about solving existing issues.

             

            Matteo Tontini added a comment - Another product created today. I started the deletion process and tried to see if it was time to complete the process for old products...some of them are showing warnings I do not know how to fix, some others are there sitting for the 90 days. Can you please read carefully the comment by 75f3e0bc41b1   who is sharing some useful suggestions for you if you care about customers' experience!! Do you really need a customer to suggest these basic customer journeys to be implemented? I've been contacted and I have in my network a dozen Atlassian account managers who want to do upsell but none is caring about solving existing issues.  

            SUGGESTIONS FOR ATLASSIAN...

            Since Atlassian has locked out our ability to block creation behind an "Enterprise" paywall, then How about improving TWO THINGS: (1) The  ability to DELETE the sites, and (2) the Site creation process?

            1. Please ADD A WAY to QUICKLY remove the product & site – an EXPEDITED removal process.

            • Simply give us multiple confirmation prompts to ensure we know we're deleting the site – and then let us delete it, immediately! (Similar to how a "Product" is deleted.)
              • I understand the need for confirmation-delays, but ~90 days is excessive. 
              • The current deletion process in the “improved” billing experience takes almost 3 months. (The old way took 2 weeks!) Think about that for a second. I have to keep a trouble ticket open for 3 months to track the work on this. I have to show it in my stats for 3 months. I have to keep this on my radar for 3 months. All for a mistaken click from a user.
                 

            2. During CREATION, the Atlassian system should improve user prompts – Add CONFIRMATIONS.

            • Confirm the user's actions with pop-ups/messages to ensure they know what they are doing.
              • Prompts like, YOU ARE ABOUT TO CREATE A WHOLE NEW SITE…” and “YOU ARE ABOUT TO ADD A BILLABLE PRODUCT TO THIS SITE” and a confirmation, "CONFIRM: I AM  AUTHORIZED TO CREATE THIS NEW SITE AND ADD THIS NEW BILLABLE PRODUCT" and "CHECK WITH YOUR ATLASSIAN ADMINISTRATOR BEFORE CONTINUING" !!
              • This would reduce the accidental creations.
                • Every one of the site creations in my organization were created accidentally. This is 100% due to the way the system presents options for our users. The Jira App prompted it or the user wasn’t logged in and so they thought they were clicking into Confluence but they were actually creating a new site.

            Respectfully,

            Mark

            Mark B Wager added a comment - SUGGESTIONS FOR ATLASSIAN... Since Atlassian has locked out our ability to block creation behind an "Enterprise" paywall, then How about improving TWO THINGS: (1) The  ability to DELETE the sites, and (2) the Site creation process? 1. Please ADD A WAY to QUICKLY remove the product & site – an EXPEDITED removal process. Simply give us multiple confirmation prompts to ensure we know we're deleting the site – and then let us delete it, immediately! (Similar to how a "Product" is deleted.) I understand the need for confirmation-delays, but ~90 days is excessive.  The current deletion process in the “improved” billing experience  takes almost 3 months. (The old way took 2 weeks!)  Think about that for a second. I have to keep a trouble ticket open for 3 months to track the work on this. I have to show it in my stats for 3 months. I have to keep this on my radar for 3 months. All for a mistaken click from a user.   2. During CREATION, the Atlassian system should improve user prompts  –  Add   CONFIRMATIONS. Confirm the user's actions with pop-ups/messages to ensure they know what they are doing. Prompts like,  “ YOU ARE ABOUT TO CREATE A WHOLE NEW SITE… ” and “ YOU ARE ABOUT TO ADD A BILLABLE PRODUCT TO THIS SITE ” and a confirmation, " CONFIRM: I AM  AUTHORIZED TO CREATE THIS NEW SITE AND ADD THIS NEW BILLABLE PRODUCT " and " CHECK WITH YOUR ATLASSIAN ADMINISTRATOR BEFORE CONTINUING " !! This would reduce the accidental creations. Every one of the site creations in my organization were created accidentally.  This is 100%  due to the way the system presents options for our users . The Jira App prompted it or the user wasn’t logged in and so they thought they were clicking into Confluence but they were actually creating a new site. Respectfully, Mark

            Matteo Tontini added a comment - - edited

            Today other two users created products in new spaces.

            Is Atlassian planning to refund companies for the time wasted for addressing this issues as I am going to do now and as I am doing on a regular basis.

            FYI: we are unluckily renewing your suite for this year but we will scout for alternative solution over the course of next year given this poor support on key issues like this

            Matteo Tontini added a comment - - edited Today other two users created products in new spaces. Is Atlassian planning to refund companies for the time wasted for addressing this issues as I am going to do now and as I am doing on a regular basis. FYI: we are unluckily renewing your suite for this year but we will scout for alternative solution over the course of next year given this poor support on key issues like this

            Nicholi Gray added a comment - - edited

            I still am not fully understanding the need to be on Enterprise plan to block domain users from creating confluence site outside of the existing site we already pay for. 

            I guess if that is the way it is, fine, but why not limit to Free plan. 

            The problem is, what is the point of having a Billing contact/admin if general users can create new confluence sites and then add a Paid plan. 

            Why does this not align with Atlassian billing model and why can non admin users bypass it? 

            No one but the billing admin should be able to manage plans. 

            It is almost every time a user creates a new confluence site that they add a paid plan. IF I am not on top of the alerts when a new site is created, we could get charged without authorization. 

            Please at least remove the ability for non admin users to add paid plans. 

             

            Nicholi Gray added a comment - - edited I still am not fully understanding the need to be on Enterprise plan to block domain users from creating confluence site outside of the existing site we already pay for.  I guess if that is the way it is, fine, but why not limit to Free plan.  The problem is, what is the point of having a Billing contact/admin if general users can create new confluence sites and then add a Paid plan.  Why does this not align with Atlassian billing model and why can non admin users bypass it?  No one but the billing admin should be able to manage plans.  It is almost every time a user creates a new confluence site that they add a paid plan. IF I am not on top of the alerts when a new site is created, we could get charged without authorization.  Please at least remove the ability for non admin users to add paid plans.   

            I am surprised that we need a feature request for this behavior that appears to be a lack of admin settings.

             

            In our case multiple users inadvertently created workspaces and after few days they've been asked to pay because the trial of confluence premium (added by default) was expiring.

            This looks like a malicious choice and it caused an escalation process in our company that led to re-examine the case of funding the renewal of Atlassian suite.

            We are now in the position to identify acceptable mitigations for what we perceive as an unacceptable behavior of the platform. If the mitigations will not be accepted we will have to migrate to another vendor after years invested in customizing Atlassian suite.

            That will be a loss for as as a customer and for Atlassian as a vendor. 

            I expect a prompt solution of this before end of 2024 if Atlassian is serious with its customers.

            Matteo Tontini added a comment - I am surprised that we need a feature request for this behavior that appears to be a lack of admin settings.   In our case multiple users inadvertently created workspaces and after few days they've been asked to pay because the trial of confluence premium (added by default) was expiring. This looks like a malicious choice and it caused an escalation process in our company that led to re-examine the case of funding the renewal of Atlassian suite. We are now in the position to identify acceptable mitigations for what we perceive as an unacceptable behavior of the platform. If the mitigations will not be accepted we will have to migrate to another vendor after years invested in customizing Atlassian suite. That will be a loss for as as a customer and for Atlassian as a vendor.  I expect a prompt solution of this before end of 2024 if Atlassian is serious with its customers.

              Unassigned Unassigned
              ca528a390f48 Pablo Bastos
              Votes:
              49 Vote for this issue
              Watchers:
              52 Start watching this issue

                Created:
                Updated: