Explore the future of Atlassian cloud security at Guard in Action. See roadmap insights, customer panels, demos, and more. Start watching
Strengthen your security posture with Atlassian Guard
What to expect in this guide
If you're just getting started with Atlassian Guard, you've come to the right place. In this guide, we'll cover security capabilities like identity and access management (IAM), data loss prevention (DLP), threat detection, and AI governance, and how they come to life in Guard.
Aligned with NIST's Cybersecurity Framework, Guard extends the secure foundation of the Atlassian platform with controls that help organizations protect high-value data, detect threats, and respond to risks. As teams adopt AI across their workflows, Guard also helps you set guardrails to keep sensitive data out of AI prompts and responses. It is designed for complex, regulated organizations where built-in platform security requires an additional layer of customization.
In this guide, you'll learn how Guard helps you:
- Protect data with centralized identity and access controls
- Protect against data loss with data loss prevention controls
- Detect threats and risky behavior with deeper visibility
- Respond quickly to contain threats with automated remediation
- Govern AI usage to keep sensitive data out of prompts and responses
How to protect data from unauthorized access
Centralizing identity and access management (IAM) is an effective way to protect your organization's most valuable data. Guard provides you with security controls to help reduce the risk of unintended access and data exposure.
Identity and access management
Guard’s IAM capabilities give you a centralized way to ensure the right individuals have appropriate access to your Atlassian apps. IAM is a cybersecurity framework comprising processes, policies, and technologies for managing digital identities and controlling access to your organization’s data.
Manage how users log in with authentication policies
A strong authentication policy helps prevent compromised accounts from accessing your data and makes it easier to enforce a secure, consistent login experience. Because teams use a variety of tools and information, you can tailor security requirements to different user groups. Authentication policies let you:
- Enforce two-step verification or single sign-on
- Create different authentication policies for different groups of managed users
- Create multiple external user policies to manage access for users outside your organization
- Get alerts when authentication policies are changed Premium Exclusive
Automatically provision users
Avoid manual, error-prone processes by connecting your existing identity provider to automate user provisioning. Using the System for Cross-domain Identity Management (SCIM) schema, you can automatically create accounts and update group memberships, ensuring users have the right app access for their roles. By automatically removing users when they leave your organization, you avoid paying for users who no longer need access and reduce the risk of lingering access. With user provisioning, you can:
- Connect an identity provider and automatically provision and deprovision users
- Automatically sync new users, remove old users, and update group memberships for existing users
Control user API tokens
Users can generate API tokens to access Atlassian data via APIs. Tokens are tied to individual users and, if compromised, can pose a significant risk. With Guard, admins gain control and visibility into the lifecycle of user API tokens, with the ability to:
- Revoke API tokens so they can no longer be used
- Set an expiry date for user API tokens in an authentication policy
- Get alerts when tokens are created or revoked Premium Exclusive
Monitor and enforce mobile access controls
Distributed teams and mobile devices give people flexibility in how and where they work, but they also create security challenges. As mobile adoption grows, it gets harder to maintain control and visibility over access to your organization’s data. Guard lets you enforce mobile security controls at scale, ensuring users can access data only within established guardrails. Mobile access controls enable you to:
- Use a mobile app policy to block screenshots, screen recording, and downloads, enforce minimum device requirements, and more
- Use the Microsoft Intune mobile application management (MAM) integration to manage Atlassian mobile app security from your existing centralized dashboard
Securely manage automations and integrations
Service accounts are non-human Atlassian accounts used for automations and integrations that aren't tied to a specific user login. They use OAuth 2.0, the industry-standard authorization protocol. Service accounts ensure:
- Personal credentials are not shared, reducing the risk of unauthorized access
- Tighter permissions scoped to only the projects and spaces needed
- Clear audit logs so you can see exactly what each integration did
Enforce condition-based access
Condition-based access policies let you set rules for how users access Atlassian apps, so you can block risky access while still allowing trusted, managed options. With a condition-based access policy, you can:
- Block access from mobile browsers while allowing access only through managed mobile apps, where data protection policies can be enforced
How to protect against data loss
Define your data loss prevention (DLP) strategy with Guard. DLP is a security discipline focused on preventing unauthorized access to or misuse of confidential data such as personally identifiable information (PII), financial data, and intellectual property, through discovery, classification, and control.
Reduce the risk of data loss with data security policies
Loss of confidential company data can be disastrous. Critical work lives in Jira and Confluence, and that data needs to be protected. Data security policies help you enforce rules around how data is accessed, shared, and handled within Atlassian apps. This reduces the risk of data leaks, accidental exposure, and unauthorized access, while helping you meet regulatory and internal security standards. Data security policies allow you to:
- Create a data security policy to block risky actions like export, public links, and anonymous access
- Apply data security controls at the organization-level to protect confidential data, ensure consistency, and give admins the option to operate “closed-by-default”
- Set data security controls based on the classification level, so stricter rules apply to your most high-value data Premium Exclusive
Classify your data based on its level of confidentiality PREMIUM EXCLUSIVE
Data classification is the process of assigning labels to information. Many organizations use classification as the foundation of their data governance strategy, especially when they must comply with government or regulatory rules, to support compliance and access control. Data classification capabilities are exclusive to Guard Premium, and they allow you to:
- Manage organization-wide classification levels, and set an org-wide default classification so new or unclassified content starts at a baseline level
- Apply classification levels to Confluence and Jira content, and receive an alert when those levels change
- Set data security policies by classification level to block actions like export and public links for specific classifications
- Automatically apply classifications to Jira and Confluence content when specific data is detected, such as mapping credit card numbers to ‘Highly Confidential’
- Restrict who can reclassify content for a stronger data governance framework
How to detect suspicious activity and prevent data misuse
Gain visibility into unsanctioned apps and anomalous behavior so you can quickly identify high-risk threats and act on them. Guard provides insights, audit logs, and detection capabilities that give your team the context needed to investigate and respond to potential threats.
Monitor app usage and security practices
Managing risk is hard, if not impossible, when you have limited visibility into how teams use Atlassian apps. Visibility into your organization's app usage, shadow IT, and users' security posture helps you make informed decisions on app usage and security policies. With Guard, you can:
- Get insights into active users and authentication methods
- Detect apps created by managed users outside your organization so you can reduce shadow IT and bring them under central governance
Access organization-wide audit logs
When you need to diagnose issues or answer questions about user activity, app access, managed accounts, and organization settings, having a record of key activities is crucial. Guard's audit logs provide the audit trail you need to meet compliance requirements and investigate incidents. With Guard, you can:
- View audit logs for administrator activity, such as changes to user access
- View audit logs for user-created activity Premium Exclusive
- Track user API token usage Premium Exclusive
- Stream events to third-party tools via webhooks or the audit log API, so your security team can work where they prefer Premium Exclusive
Detect suspicious user activity Premium Exclusive
Guard offers various tools to surface suspicious activity, anomalies, and potential data loss. Get alerts when specific types of user activity are detected, including authorization and access events, data exfiltration events, and app or integration configuration changes across Atlassian Administration, Jira, and Confluence. Alerts give you and your security team the information needed to investigate and remediate, reducing your time to resolution. Activity detection capabilities are exclusive to Guard Premium and include:
- Get an alert when detection criteria are triggered
- Send alerts to your existing SIEM or messaging tool to keep work in one place
- Exclude specific users to reduce false positive alerts
Protect sensitive data from misuse Premium Exclusive
No matter how careful your teams are, sensitive data such as credit card numbers, API tokens, or AWS access keys can end up in Jira issues, Confluence pages, and other non-Atlassian tools. The more your organization grows and the more your data sprawls, the harder it is to keep track of it all. You need to understand where your most sensitive data lives so you can identify any blind spots.
Get alerts when specific types of confidential data are added to a page or issue, using built-in or custom detections, so your security team can investigate and remove it if appropriate. Content detection capabilities are exclusive to Guard Premium and include:
- Run an org-wide scan for sensitive data across Jira and Confluence to gain full visibility across years of data
- Select from 60+ built-in detections that scan for a wider range of data out of the box
- Create custom detections and get alerts for specific terms, phrases, and patterns in Confluence or Jira
- Exclude selected pages or issues to reduce false positive alerts
- Integrate alerts with your SIEM or messaging tools (for example, Splunk, Slack, or Microsoft Teams) so teams can respond quickly
How to respond before threats become incidents PREMIUM EXCLUSIVE
Investigation and remediation are critical steps in security incident response. It involves identifying, analyzing, and understanding the nature and scope of a security incident, then taking the actions needed to resolve it and limit its impact. Guard Premium provides the investigation and remediation tools to identify, analyze, and resolve security threats before they become incidents.
Respond to alerts
Unaddressed security risks can escalate and cause significant harm. As an admin or security professional, you can quickly identify risks, take immediate action to prevent further damage, and fine-tune your security measures and policies over time. Investigation capabilities are exclusive to Guard Premium and include:
- Investigate alerts holistically with a dashboard that brings the description, actor details, and remediation steps together in one place
- View information about the actor to see their broader activity, devices, and locations and determine whether the activity is suspicious
- See contextual data on the alert and actor, such as an activity timeline panel
Take remediation actions
When a threat arises, a delayed response increases its risk and impact. Each alert includes recommended remediation steps, so your team can act quickly to minimize the impact of risky activity or data misuse. Remediation capabilities are exclusive to Guard Premium and include:
- Take immediate steps to stop further suspicious activity, such as suspending the actor
- Scan for and redact confidential content in Jira and Confluence directly from an alert
- Automate common remediation actions, such as restricting or reclassifying a page or issue
How to govern AI usage to keep sensitive data out of prompts and responses
With AI infused into everyday workflows, security teams need a way to set guardrails before sensitive data is exposed. Guard Premium helps you do that with AI governance capabilities that give you control over what Rovo can access and how it handles sensitive content.
The AI governance capabilities below are coming soon. Follow our cloud roadmap for updates.
Granular controls for Rovo PREMIUM EXCLUSIVE
Guard Premium gives you control over AI interactions at two key points: when users interact with Rovo Chat, and when data from third-party connectors is ingested into Atlassian. Together, these controls help you roll out AI across your organization without exposing sensitive information.
Scan and block sensitive data in Rovo Chat
Guard scans prompts and responses in Rovo Chat across all agents. It can block or redact content that matches sensitive data detections, helping prevent users from pasting sensitive information into prompts and from having agents surface that data in responses. With Rovo Chat security:
- Scan prompt and response text in Rovo Chat
- Block sensitive data before it reaches an agent
- Redact matched content inline so conversations can continue safely
- Use built-in detections across categories like Financial, Identity, Credentials, and Health
- Review insights into blocked and redacted prompts and responses over time
Control what data is ingested into Rovo
Guard also stops sensitive data from third-party connectors, such as Google Drive, from being ingested into Atlassian in the first place. If a connected source contains sensitive data, Guard can prevent Rovo from indexing or surfacing it, keeping risk out of the Atlassian surface entirely. With Connector data security:
- Block connector documents that match sensitive data detections before they enter Atlassian
- Protect against risk from third-party sources without relying on chat-time scanning alone
- See which connector documents were blocked and which detection categories fired most often
Try Guard free for 30 days
Before you get started
Atlassian Guard is implemented company-wide and requires coordination between stakeholders, such as other admins, across your organization.
Before you set up an organization and verify a domain, make sure any other teams using Atlassian cloud products are aware of the upcoming changes.
Getting started
1
Confirm or create your organization by going to admin.atlassian.com
2
Add users to your organization by verifying domain(s) that your company owns.
3
Start your 30-day trial to set up Atlassian Guard features.