Uploaded image for project: 'Atlassian Guard'
  1. Atlassian Guard
  2. ACCESS-601

Allow site-admin of an instance to see who has activated two-factor authentication

    • Our product teams collect and evaluate feedback from a number of different sources. To learn more about how we use customer feedback in the planning process, check out our new feature policy.

      Atlassian Update – 23 December 2020

      Hi everyone,

      I am pleased to announce that we have now added 2SV activation statistics to the admin insights page. You can find the page by logging into https://admin.atlassian.com and navigating to Security > Insights. You may need to scroll down to see the chart at the bottom of the page.

      Like all other admin insights, 2SV activation statistics are available to customers with a subscription to Atlassian Access or with Premium plans for Jira Software, Jira Service Management, and Confluence: https://confluence.atlassian.com/cloud/insights-998892816.html 

      Thank you,

      Ilya Bagrak
      Product Manager, Admin Experience

       

       

            [ACCESS-601] Allow site-admin of an instance to see who has activated two-factor authentication

            Hi Gary,

             

            Unfortunately the current implementation is garbage and they've missed the point of this feature.

             

            Yes you can now see how many users don't have 2FA enabled......but it doesn't tell you who the users are!! It's just a high level statistic. Example below:

             

            So I'm afraid you're not missing out on much Gary

            leigh.webster added a comment - Hi Gary,   Unfortunately the current implementation is garbage and they've missed the point of this feature.   Yes you can now see how many users don't have 2FA enabled......but it doesn't tell you who the users are!! It's just a high level statistic. Example below:   So I'm afraid you're not missing out on much Gary

            Hi, this insight seems to be only available for access users which, in turn, is only available for accounts that have a claimed domain. 

            I was told that an auditing feature was going to be delivered where I could establish if a premium account had 2fa configured that belonged to a client that was a member of an unclaimed domain.

            This would allow me to disable that account if 2fa was ever disabled, this functionality would be critical given that we use Jira as a security related ticketing system for clients.

            Regards

            Gary

            Gary Bostock added a comment - Hi, this insight seems to be only available for access users which, in turn, is only available for accounts that have a claimed domain.  I was told that an auditing feature was going to be delivered where I could establish if a premium account had 2fa configured that belonged to a client that was a member of an unclaimed domain. This would allow me to disable that account if 2fa was ever disabled, this functionality would be critical given that we use Jira as a security related ticketing system for clients. Regards Gary

            Hi @Ilya Bagrak, I am a site admin and I just tried to find the Insight Page, but there is no Insight under " Security". If I click "Security". it only gives me another Admin page. Are you sure that this new feature has been delivered in all users' instances?

            Thanks,

            Joseph

            Joseph Zheng added a comment - Hi @Ilya Bagrak, I am a site admin and I just tried to find the Insight Page, but there is no Insight under " Security". If I click "Security". it only gives me another Admin page. Are you sure that this new feature has been delivered in all users' instances? Thanks, Joseph

            Hi everyone,

            I am pleased to announce that we have now added 2SV activation statistics to the admin insights page. You can find the page by logging into https://admin.atlassian.com and navigating to Security > Insights. You may need to scroll down to see the chart at the bottom of the page.

            Thank you,

            Ilya Bagrak
            Product Manager, Admin Experience

            Ilya Bagrak added a comment - Hi everyone, I am pleased to announce that we have now added 2SV activation statistics to the admin insights page. You can find the page by logging into https://admin.atlassian.com and navigating to Security > Insights . You may need to scroll down to see the chart at the bottom of the page. Thank you, Ilya Bagrak Product Manager, Admin Experience

            This feature is very useful and proficient for administrators of Atlassian products. We hope this feature is delivered as soon as possible. Thanks!

            Joseph Zheng added a comment - This feature is very useful and proficient for administrators of Atlassian products. We hope this feature is delivered as soon as possible. Thanks!

            Any update please? 

            Jay McCarogher added a comment - Any update please? 

            Any update on this?

            leigh.webster added a comment - Any update on this?

            Can you please ensure this information can be retrieved via API, not just in the settings pages for an admin? That said, it's taken so long for you to do anything in the area of securing external users that anything would be better than nothing.

            James Valentine added a comment - Can you please ensure this information can be retrieved via API, not just in the settings pages for an admin? That said, it's taken so long for you to do anything in the area of securing external users that anything would be better than nothing.

            Joe Pakenham added a comment - - edited

            This feels like a key missing part of having a MFA option. If you can't see who's using it, what's the point? 

            The premium enforcement is only valid for email addresses within the domain registered, not helpful for an organisation which collaborates with others to get work down.

            Joe Pakenham added a comment - - edited This feels like a key missing part of having a MFA option. If you can't see who's using it, what's the point?  The premium enforcement is only valid for email addresses within the domain registered, not helpful for an organisation which collaborates with others to get work down.

            This is becoming a real issue for us. Atlassian is now the only SaaS tool in my technology stack where i cant enforce MFA, without paying for. Its a hygiene factor not a premium feature!

            Lars Öhlin added a comment - This is becoming a real issue for us. Atlassian is now the only SaaS tool in my technology stack where i cant enforce MFA, without paying for. Its a hygiene factor not a premium feature!

              Unassigned Unassigned
              ckek Kek Chee Young (Inactive)
              Votes:
              41 Vote for this issue
              Watchers:
              38 Start watching this issue

                Created:
                Updated:
                Resolved: