Remove app access for users
Which user management experience do you have?
Go to Atlassian Administration. Select your organization if you have more than one. You can identify which user management experience you have by checking where your Users page is located.
Centralized | Original |
---|---|
In Atlassian Administration, Users is located in Directory. ![]() | In Atlassian Administration, Users is located in Apps > ![]() |
Jump to the
Centralized user management content
Remove app access from a user when they no longer need access to an app. If the user no longer needs access to your organization, you can remove them from your organization.
Users get access to apps through groups, usually default groups. Users can also get access to an app by being part of a group that isn’t the app’s default group, but has access to that app. Users need to be removed from all groups that give access to an app to remove their access to that app completely.
How app access works for Atlassian Government Cloud Atlassian Government Cloud organizations should provision users from an identity provider. If you provisioned users from an identity provider and need to remove their app access, follow the steps on this page to remove access from a group. |
Remove app access from a user
Who can do this? |
To remove access from a user:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Directory > Users.
Select the user to go to their profile.
In the Apps tab, find the app you want to remove access to, then select more actions (•••).
Select Remove access. This removes the user from all groups that give access to that app.
You can automate this process with the Revoke user access API.
If the user is an organization admin, you need to remove their organization admin role before you can remove their access to a app. Remove admin role from a user
Default groups that give access to more than one app
When you assign a role to a user, we add them to the default group for that role. If the default group for an app has been modified to also give access to other apps, a user access admin for that app only won’t be able to remove access to that app. This is so the user access admin doesn’t inadvertently remove access to other apps they don’t administer. Troubleshoot issues related to managing groups
Remove app access from a group
Who can do this? |
To remove access from a group:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Directory > Groups.
Select the group to go to its profile.
In the Apps tab, find the app you want to remove access to, then select Remove.
You can automate this process with the Revoke roles from a group API.
Users in this group will continue to have access to the app if they’re in other groups that give access to that app. To remove access to the app completely for any user, follow the instructions to remove app access from a user.
Remove app access from multiple groups
Who can do this? |
You may need to remove access to the same app for multiple groups at a time.
To remove app access from multiple groups:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Apps.
Select Manage app for the app that you need to remove access to.
Find the group you want to remove access from, then select more actions (•••).
Select Remove group from app.
Default groups are required
Every app role needs a default group. You can’t remove a group from an app, or app access from a group, if it’s the only default group for a role. You need to make another group the default group for that role first, before you can delete the other default group. Troubleshoot issues related to managing groups
Original user management content
Remove app access from a user when they no longer need access to an app. If the user no longer needs access to your site, you can remove them from your site.
Users get access to apps through groups, usually default groups. Users can also get access to an app by being part of a group that isn’t the app’s default group, but has access to that app. Users need to be removed from all groups that give access to an app to remove their access to that app completely.
Who can do this? |
Remove app access from a user
To remove access from a user:
Go to admin.atlassian.com. Select your site if you have more than one.
From the Users page, select the user to go to their profile.
In the Apps tab, find the app you want to remove access to, then select more actions (•••).
Select Remove access. This removes the user from all groups that give access to that app.
If the user is an organization admin or a site admin, you need to remove their admin role before you can remove their access to an app. Remove admin role from a user
Remove app access from a group
To remove access from a group:
Go to admin.atlassian.com. Select your site if you have more than one.
Select Groups.
Select the group to go to its profile.
In the Apps tab, find the app you want to remove access to, then select Remove.
Users in this group will continue to have access to the app if they’re in other groups that give access to that app. To remove access to the app completely for any user, follow the instructions to remove app access from a user.
Remove app access from multiple groups
You may need to remove access to the same app for multiple groups at a time. To do this:
Go to admin.atlassian.com. Select your site if you have more than one.
Select App access.
Find the app that you need to remove access to.
Find the groups you want to remove access from. Select more actions (•••) for a group, then select Remove group. Repeat this step for each group.
Default groups are required
Every app role needs a default group. You can’t remove a group from an app, or app access from a group, if it’s the only default group for a role. You need to make another group the default group for that role first, before you can delete the other default group. Troubleshoot issues related to managing groups
Was this helpful?