...
...
...
...
Info |
---|
...
Confluence Data |
...
Center Approved OWASP Security Verified |
Simple add-on to remove License for Inactive users and Deactivate or remove Security access groups for
...
users who left organization.
Use Cases:
- To
...
- Remove License for Confluence users who
...
- are Never Login or Not active.
- To Deactivate or Remove License Access Security Groups for Confluence users who
...
- left company or Not exists in organization directory.
- To
...
- restore license Or Grant Access on Successful Login attempt.
- To Search inactive users certain number of days and export to CSV.
- To Notify license alerts.
Features:
- Supports to process Large enterprise users base.
- All Atlassian provided user directories are supported.
- Supports custom remote external Directories, to check user status either active or deactivated.
- Option to choose multiple User Directories to process users.
- Option to process users from specific
...
- groups.
- Option to skip
...
- users from specific groups.
- Option to rename Deactivated user to {username}_inactive_yyyyMMdd
...
...
Info |
---|
Top Trusted Users |
- BNP Paribas Bank Polska S.A.
- Paytm Bank
- OTP Bank
- OCBC Bank
- Autodesk
- Thales
- Expedia
- Broadcom
- Intel
Info |
---|
Quick Start Steps. |
Here is Quick Start Steps to start using this plugin.
Status | |||
---|---|---|---|
|
...
|
...
|
Go to, System General Configuration > Click Manage Inactive Users
...
Step-1A: Configure Skip users for inactivation or deactivation process.
...
Step-1B: Verify Admin user in App settings > Click update again to confirm.
Note. If your admin username is email prefix then please ensure this email address is not associated for other users.
...
Go to, System General Configuration > Click Manage Inactive Users
Info | ||
---|---|---|
|
...
| |
Configuration to Remove License or Access Security Groups for Confluence users who are Never Login or Not active |
...
Note:
- User Directory Name: To process users for inactivation specific to these directories
- Processing Group (Optional): It gives flexibility to process users for inactivation from specific group (e.g confluence-users).
- For testing you can use the group with small number of users.
- If empty it processes all users
- Deactivate Users: Choose True/False either to de-activate users.
- Set False to just reduce license count.
- Set False if user directory is read-only.
- Remove Groups: Enter a comma separated license groups to remove for inactive users.
- Supported User Directory types:
- Any Read Only Directory with local groups. (Supports license groups removal and helps to reduce license count)
- Internal with LDAP Authentication. (Supports Deactivation, license groups removal and helps to reduce license count)
- Internal Directory. (Supports Deactivation, groups license removal and helps to reduce license count)
- Faq to Create Delegated LDAP Directory
...
| |
Configuration to Deactivate and Remove |
...
Access Security Groups for |
...
Jira users who left company or Not exists in organization directory. |
Note:
- User Directory Name: To process users for inactivation specific to these directories
- Processing Group (Optional): It gives flexibility to process users for inactivation from specific group (e.g confluence-users).
- For testing you can use the group with small number of users.
- If empty it processes all users
- Deactivate Users: Choose True/False either to de-activate users.
- Set False to remove defined license / access groups for inactive users and reduces license count.
- Set False if user directory is read-only.
- Remove Groups: Enter a comma separated license groups to remove for inactive users.
- Supported User Directory types:
- Any Read Only Directory with local groups. (Supports license groups removal and helps to reduce license count)
- Internal with LDAP Authentication. (Supports Deactivation, license groups removal and helps to reduce license count)
- Internal Directory. (Supports Deactivation, groups license removal and helps to reduce license count)
- Faq to Create Delegated LDAP Directory
Step-2A (Optional)
- For Manual runs:
- Go to, On Demand Run > Click Never Login Users Clean
- Go to, On Demand Run > Click Not Active Users Clean
- Go to, On Demand Run > Click Deactivated Users Clean
|
Please see, Manage Former X Confluence Users
Status | ||||||
---|---|---|---|---|---|---|
|
Info | ||
---|---|---|
| ||
To enable / grant Login access back to those inactive users automatically |
...
. |
Please see, Confluence License reclamation
Status | |||
---|---|---|---|
|
...
|
...
Go to, System General Configuration > Scheduled Jobs
Default schedule for Automatic user de-activation.
...
|
Two ways to Debug Manage Inactive Users App
...
i.e.
>>> Through atlassian log file — atlassian-confluence.log
Go to, System General Configuration > Logging and profiling > Add New Entry.
Code Block |
---|
Class/Package Name: com.tse.confluence.deactivateusers.plugin
Level: Debug |
Click Add.
>>> Through Audit log.
Go to, System General Configuration > Audit log.
Anchor | ||||
---|---|---|---|---|
|
Status colour
...
Green title Customer #1 Feedback
We use manage Inactive users plugin along side with Atlassian provided SAML / SSO Plugin for Overall Security as per InfoSec guideline.
- To deactivate users who left company in Delegated User Directory.
- To Clean up Inactive users who are not logged in last 90 days.
- Grant license to Inactive users who comes back on successful attempt.
Atlassian provided SAML SSO plugin with Delegated LDAP / AD User Directory On login:
- Helps us to create new users with default group.
- Helps us to trigger groups synchronise from AD LDAP / Okta with custom prefix.
Anchor | ||||
---|---|---|---|---|
|
Status colour Green title CUSTOMER #2 FEEDBACK
We used manage Inactive users plugin's REST API to migrate AD Users from Company X to Company Y.
From Connector User Directory to Delegated User Directory.
Step-1, We created New Delegated User Directory.
Step-2, Go to database update existing connector user directory users in cwd_user, membership and group tables with delegated directory ID
Step-3, Use manage Inactive users plugin's attribute update REST API to rename username and email addresses.
Status colour Green title CUSTOMER #3 FEEDBACK
We use Manage Inactive users plugin with Re:Solution SAML plugin.
- To deactivate users who left company in Delegated User Directory.
- To Clean up Inactive users who are not logged in last 90 days.
- Re:Solution SAML plugin helps to provision / grant license on login.
Status colour Green title CUSTOMER #4 FEEDBACK
We use Manage Inactive users plugin with MiniOrange SAML plugin.
- To deactivate users who left company in Delegated User Directory.
- To Clean up Inactive users who are not logged in last 180 days.
- MiniOrange SAML plugin helps to provision / grant license on login.
Please see, Common Asked Questions and Hints