Microsoft Defender for Cloud Apps
Cloud and workloads

Protect your Atlassian environment | Microsoft Defender for Cloud Apps

In brief

The article now documents a 1-year default API-key validity, recommends refreshing keys every six months, and adds an 8,000-events-per-minute limit alongside the 1,000-requests-per-minute limit. Connection steps and monitored Atlassian services are also clarified.

What Defender admins need to know

Administrators should plan regular key refreshes and account for both documented connector rate limits when managing Atlassian integration capacity.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How Defender for Cloud Apps helps protect your Atlassian environment

This article explains how to connect Atlassian to Microsoft Defender for Cloud Apps, what activities the connector monitors across Confluence, Jira, and Bitbucket, and how to configure the required permissions.

Atlassian is an online collaborativeplatform for collaboration and software development platform (includingdevelopment. It includes Confluence, Jira, and Bitbucket). Along with the benefits of effectiveBitbucket. Cloud collaboration in the cloud,has many benefits, but it can also expose your organization's most critical assets might be exposed to threats. ExposedThese assets include posts, tasks, and files with potentially sensitive information, collaboration, and partnership details, and more. Preventing exposure of this data requires continuousdetails about partnerships or other topics. You need ongoing monitoring to prevent anystop malicious actors or security-unawarecareless insiders from exfiltrating sensitive information.leaking this data.

ConnectingWhen you connect Atlassian to Defender for Cloud Apps givesApps, you improved insightsget deeper insight into your users' activitiesuser activity and provides threat detectionalerts for anomalousunusual behavior. The connector covers all users in your organization that use the Atlassian platform, and shows activitiesactivity from Confluence, Jira, and specific Bitbucket activities.Bitbucket.

Main threats include:

Automate governance controls

In addition to monitoring for potential threats, youYou can apply andalso automate the following Atlassian governance actions to remediate detected threats:respond to threats. The following table lists the actions you can use.

Type Action
User governance Notify user on alert (via Microsoft Entra ID)
Require user to sign in again (via Microsoft Entra ID)
Suspend user (via Microsoft Entra ID)

For more information about remediatingfixing threats from apps, see Governing connected apps.

Protect Atlassian in real time

Manage SaaS security posture for Atlassian

SaaS security posture management helps you assesscheck and improve the security configuration of connectedhow your SaaS apps by surfacing recommendationsare set up. It shows helpful tips in Microsoft Secure Score.

After you connect Atlassian using the App Connector procedure toin this article, you get security posture recommendations for Atlassiantips in Microsoft Secure Score. To see security recommendations for Atlassian in Microsoft Secure Score:view these tips:

  1. Refresh your policies by opening and saving each policy in the Atlassian portal.
  2. In Microsoft Secure Score, select Recommended actions and filter by Product = Atlassian.

Configure Atlassian

Complete the following steps in Atlassian to create an API key and collect the values needed for the connector.

  1. Sign in to the Atlassian Admin portal with an admin account.

  2. Create an API key. The Atlassian App Connector currently supports API keys without scopes only. When creating the Atlassian API key for Microsoft Defender for Cloud Apps, do not select any scopes. API keys created with scopes (including read‑only scopes) may fail to authenticate. For more information, see Manage an organization with the admin APIs.

Configure Defender for Cloud Apps

Complete the following steps to create the Atlassian connector in Defender for Cloud Apps.

  1. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Connected apps, select App Connectors.

  2. In the App connectors page, select +Connect an app, followed by Atlassian.

Revoke and renew API keys

  1. By default, the API key is valid for 1 year and expires automatically. As a security best practice, Microsoft recommends using short short-lived keys or tokens for connecting apps as a security best practice.

  2. We recommend refreshingapps. Refresh the Atlassian API key every 6 months as a best practice. To refresh the key, revoke the existing API key and generate a new key.to avoid expiration-related issues.

  3. To revoke API key, navigateand replace the key:

    1. Navigate to admin.atlassian.com > Settings > API keys, determine the API key used for the Microsoft Defender for Cloud Apps integration, and select Revoke.
    2. Recreate an API key in the Atlassian admin portal.

    3. In the Microsoft Defender Portal, go to the App Connectors page, and edit the connector.

    4. Enter the new generated new API key and select Connect Atlassian.

    5. In the Microsoft Defender Portal, select Settings. Then choose Cloud Apps. Under Connected apps, select App Connectors. Make sure the status of the connected App Connector is Connected.

    Rate limits and limitations

    • Rate limits include 1,000 requests per minute (per API key/connector instance).

      For more information about the Atlassian API limitation, see Atlassian admin REST APIs

      Rate limits and limitations

      • Rate limits include 1,000 requests and 8,000 events per minute (per API key/connector instance).

        For more information about the Atlassian API limitation, see Atlassian admin REST APIs.