-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Monitoring - Insights / User counts
-
None
-
3
Managed Account Secure login Percentage % should be based on Active users (Deactivated accounts should be excluded)
Within the Atlassian Admin security guide the percentage of account that have:
- Two-step verification
- Password
The percentage of secure login users shouldn't include all the old accounts that are deactivated that were initially captured during the domain claiming activity. As an admin, I'm really concerned about the active users that I manage being properly tied to a secure login policy of some type. As implemented, this is a useless data value
Deactivated user accounts cannot access Atlassian Cloud services by design and therefore should not count in the user security overview.
When navigating to Insights https://admin.atlassian.com/o/<ORG ID>/insights User Security will include accounts that are deactivated.
In the Example image below 48/50 accounts do not have two-step verification enabled.
While this accurate 20 of these accounts are unable to login to Atlassian Cloud services as they are deactivated.
- Deactivate a managed accountWhen you deactivate an account, the user will no longer be able to log in to Atlassian account services. Atlassian account services include all organizations and sites used to access these products:
It would be helpful if the logic accounted for the deactivated accounts.