Skip to content

Atlassian access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Atlassian, Black Cat runs 17 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Atlassian connector needs.

Checks (17)

severity: medium Inactive User fix difficulty: easy #

Deactivate inactive Atlassian users who are no longer needed

  1. Navigate to admin.atlassian.com > Directory > Users
  2. Find the inactive user and review their activity
  3. Deactivate the user if no longer needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Suspended User With Access fix difficulty: easy #

Remove all product access and group memberships from suspended Atlassian users

  1. Navigate to admin.atlassian.com > Directory > Users
  2. Find the suspended user
  3. Remove all product access and group memberships

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Dual Admin Role fix difficulty: medium #

Remove unnecessary admin role from Atlassian users with admin access to multiple products

  1. Review whether the user needs admin access to both Jira and Confluence
  2. Remove admin role from one product if not required
  3. Assign a more specific role instead of admin

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium External User With Product Access fix difficulty: easy #

Review and remove unnecessary product access for external Atlassian users

  1. Navigate to admin.atlassian.com > Directory > Users
  2. Filter by external users
  3. Review and remove unnecessary product access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-44.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high API Token Older Than 90 Days fix difficulty: medium #

Rotate Atlassian API tokens that are older than 90 days

  1. Contact the user and ask them to rotate the API token
  2. User should visit id.atlassian.com/manage-profile/security/api-tokens
  3. Revoke the old token and create a new one
  4. Update any integrations using the old token

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.c NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User With Multiple API Tokens fix difficulty: easy #

Reduce Atlassian API tokens per user by revoking unnecessary tokens

  1. Contact the user to identify which tokens are still needed
  2. User should visit id.atlassian.com/manage-profile/security/api-tokens
  3. Revoke unnecessary tokens

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high SSO Not Configured fix difficulty: hard #

Configure SAML SSO for Atlassian to centralize identity management

  1. Navigate to admin.atlassian.com > Security > SAML single sign-on
  2. Add your identity provider configuration
  3. Verify a domain for SSO
  4. Test and enable SSO

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC7.2 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-02 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Session Duration Excessive fix difficulty: easy #

Reduce Atlassian session timeout to 24 hours or less

  1. Navigate to admin.atlassian.com > Security > Authentication policies
  2. Edit the session duration setting
  3. Set session timeout to 24 hours or less

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Jira Project Permissive Default Roles fix difficulty: medium #

Remove anonymous browse access and restrict default role permissions in Jira projects

  1. Open the Jira project settings
  2. Navigate to Access > Permission scheme
  3. Review and restrict the default role permissions
  4. Remove 'Anyone' browse access

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low API Token No Label fix difficulty: easy #

Add a descriptive label to unlabeled Atlassian API tokens to enable auditing and attribution

  1. Contact the user who owns the token
  2. User should visit id.atlassian.com/manage-profile/security/api-tokens
  3. Revoke the unlabeled token and create a new one with a descriptive label indicating its purpose and owner
  4. Update any integrations using the old token with the new token value

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high External Users Policy Disabled fix difficulty: medium #

Enable the external users policy to enforce controls on guest and external account access

  1. Navigate to admin.atlassian.com > Security > Policies
  2. Locate the External users policy
  3. Enable the policy and review the configured controls
  4. Define allowed domains and permitted actions for external users
  5. Notify your security team that the policy is now enforced

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Org Admin Product Access fix difficulty: medium #

Review and reduce org-admin product access to the minimum required set of users

  1. Navigate to admin.atlassian.com > Directory > Users
  2. Search for the user and open their product access settings
  3. Confirm whether org-admin access is required for their role
  4. Downgrade to a product-specific admin or member role if org-admin is not justified
  5. Document the business justification if org-admin access is retained

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium User Account Closed fix difficulty: easy #

Remove or fully deprovision closed Atlassian user accounts from the organization directory

  1. Navigate to admin.atlassian.com > Directory > Users
  2. Find the closed user account
  3. Remove the user from all groups and revoke any remaining product access
  4. Revoke all API tokens associated with the account
  5. Delete or archive the account from the organization directory

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.2 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium API Token Generic Label fix difficulty: easy #

Replace generic-labeled API tokens older than 30 days with tokens bearing descriptive, purpose-specific labels

  1. Contact the user who owns the token
  2. Determine the actual purpose of the token and whether it is still needed
  3. If still needed, user should visit id.atlassian.com/manage-profile/security/api-tokens
  4. Revoke the generic-labeled token and create a replacement with a clear, purpose-specific label
  5. Update any integrations using the old token with the new token value
  6. If the token is no longer needed, revoke it without replacement

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Empty Group fix difficulty: easy #

Remove empty groups that have no members to reduce administrative overhead

  1. Navigate to admin.atlassian.com and select the organization
  2. Go to Directory > Groups
  3. Identify the empty group and verify no automation or integration depends on it
  4. Delete the group if it is no longer needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: critical Admin Without MFA fix difficulty: easy #

Require the admin user to enable two-step verification immediately

  1. Contact the admin user and direct them to enable two-step verification
  2. The user should go to id.atlassian.com > Security > Two-step verification
  3. Verify the admin has enrolled in MFA before their next login
  4. Consider enforcing two-step verification org-wide via organization policy

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Product Access Admin fix difficulty: easy #

Review product-level admin access and reduce to the minimum required users

  1. Navigate to admin.atlassian.com and select the organization
  2. Go to Products and select the relevant product
  3. Review the list of users with admin roles
  4. Downgrade admin users who do not require administrative access to a standard role

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Atlassian checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial