Resolving preflight blockers for an organization consolidation
When going through an organization consolidation, there are various preflight blockers that may need to be resolved before Atlassian can generate the dry-run report.
- For more information, please see the Atlassian Organization consolidation guide.
While the details of each preflight blocker may vary for each consolidation, the general concepts behind each blocker and the steps to resolve them are consistent across organizations.
See the relevant section(s) below for more information on preflight blockers for organization consolidations and general guidance on how to resolve them.
API keys
The API keys blocker (sometimes indicated as CONTAINER_TOKENS) is returned for a secondary organization that has created one or more admin API keys that are currently active.
For more information, please see Manage an organization with the admin APIs.
To resolve this blocker, an organization admin must revoke all API keys for the organization.
For instructions, please see Manage an organization with the admin APIs | Revoke an API key.
App access settings
The App access settings blocker (sometimes indicated as USER_ACCESS_SETTINGS) is returned for a secondary organization that has modified the Approved domains, User invites, or Invitation links configurations (all found via the App access settings page for an organization) since its App access settings were last reset.
For more information on App access settings and the various configurations available, please see Control how users get access to apps.
To resolve this blocker, an organization admin must reset the App access settings for the organization.
For instructions, please see How to Reset App Access Settings Before a Product Transfer.
Atlassian Guard Standard subscription
The Atlassian Guard Standard subscription blocker (sometimes indicated as ATLASSIAN_GUARD_STANDARD) is returned for a secondary organization that has an active Atlassian Guard Standard subscription.
For more information, please see Understand Atlassian Guard.
To resolve this blocker, an organization admin or billing admin must cancel the Atlassian Guard Standard subscription for the organization.
For instructions, please see Deactivate Atlassian Guard Standard.
Bitbucket usage-based subscriptions
The Bitbucket usage-based subscriptions blocker (sometimes indicated as BB_BUILD_TIME_CREDITS_LICENSE, BB_LFS_CREDITS_LICENSE, BB_PACKAGE_NETWORK_CREDITS_LICENSE, and/or BB_PACKAGE_STORAGE_CREDITS_LICENSE) is returned for a secondary organization that has active subscriptions for usage-based pricing associated with one or more Bitbucket workspaces.
- For more information, please see How usage-based pricing works.
To resolve this blocker, you will need to cancel the usage-based pricing subscriptions for Bitbucket in the secondary organization. If you have an active ticket with Atlassian’s technical support team for performing the organization consolidation, you can work with the support team via that ticket to cancel the Bitbucket usage-based subscriptions for the secondary organization. Otherwise, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling these subscriptions.
Custom email domains
The Custom email domains blocker (sometimes indicated as CDEN) is returned for a secondary organization that has added one or more domains as email domains for app notifications, regardless of status.
For more information, please see Add custom email addresses for app notifications.
To resolve this blocker, an organization admin must remove all email domains for the organization.
For instructions, please see Remove an email domain.
Deactivated grandfathered site admin users
The Deactivated grandfathered site admin users blocker is returned for a secondary organization that has one or more users that have been granted the "grandfathered site admin" role.
- This scenario is not very common, as the grandfathered site admin role was only rolled out to select users in organizations that were automatically migrated from the original user management experience to the centralized user management experience in 2023, before Atlassian released the official "Site admin" role for the centralized user management experience.
To resolve this blocker, you have two options for each affected account:
- Remove the user from the organization.
- For instructions, please see Remove user or suspend their access | Remove a user.
- Revoke the grandfathered site admin role from the user.
Please find the instructions below to revoke the grandfathered site admin role from a user:
- Reactivate the affected account.
- For instructions, please see Deactivate a managed account | Reactivate an account.
- If the account was deactivated via user provisioning, you may need to mark the account for deletion, then cancel the account's deletion to reactivate the account.
- For instructions, please see Delete a managed account | Delete an account and Delete a managed account | Cancel an account deletion.
- Remove the organization admin role from the affected account (if present).
- For instructions, please see Remove admin role from a user | Remove organization admin role.
- Grant the site admin role to the affected account.
- For instructions, please see Give users admin permissions | Make someone a site admin.
- Remove the site admin role from the affected account.
- For instructions, please see Remove admin role from a user | Remove site admin role.
- Optionally, deactivate the account again.
- For instructions, please see Deactivate a managed account | Deactivate an account.
Domain claims
The Domain claims blocker (sometimes indicated as DOMAIN_CLAIMS) is returned for a secondary organization that has claimed one or more domains for the purpose of managing accounts, regardless of verification status.
For more information, please see Verify a domain to manage accounts.
To resolve this blocker, an organization admin must remove all domains for the organization.
For instructions, please see Verify a domain to manage accounts | Remove a verified domain.
If you want to continue managing accounts on your currently-verified domains via the destination organization, we recommend that you contact Atlassian support for assistance with migrating management of the domains and their accounts to the destination organization prior to processing the consolidation.
Enterprise subscription
The Enterprise subscription blocker (sometimes indicated as ENTERPRISE_LICENSE) is returned for a secondary organization that has one or more active Enterprise subscriptions.
To resolve this blocker, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling all Enterprise subscriptions for the secondary organization.
Group rename
When an organization consolidation is processed, the userbases of the primary and secondary organizations are merged. Any groups in the secondary organization that have the same name as a group in the primary organization are automatically renamed to append the name of the secondary organization when the consolidation is processed.
Group rename blockers are returned when any of the groups in the secondary organization that need to be renamed are referenced in one or more Jira experiences that don’t support the renaming of groups.
The options to resolve each group rename blocker depend on the affected Jira experience. We recommend that you contact Atlassian support for assistance with identifying which groups are subject to one or more rename blockers, the affected Jira experience(s), and the available options to resolve the blocker(s).
Identity providers
The Identity providers blocker (sometimes indicated as SCIM) is returned for a secondary organization that has configured one or more identity provider directories for syncing and/or authenticating Atlassian accounts.
For more information, please see Connect identity providers to your organization.
To resolve this blocker, an organization admin must disconnect all identity providers from the organization.
For instructions, please see Disconnect your identity provider.
If you want to continue syncing and/or authenticating Atlassian accounts via the destination organization, we recommend that you contact Atlassian support for assistance with the identity provider migration prior to processing the consolidation.
IP allowlist
The IP allowlist blocker (sometimes indicated as IP_ALLOWLIST) is returned for a secondary organization that has one or more IP allowlist configurations.
- For more information, please see Specify IP addresses for app access.
To resolve this blocker, you will need to delete all IP allowlist configurations for the secondary organization.
Original user management experience
The Original user management experience blocker is returned for any organization that currently has the original user management experience enabled. Organization consolidations are only supported for organizations that have the centralized user management experience enabled.
You will need to contact Atlassian support and work with them directly to identify whether this blocker can be resolved, or what other options may be available.
Rovo and related subscriptions
The Rovo and related subscriptions blocker (sometimes indicated as ROVO_LICENSE, ROVO_CREDITS_LICENSE, INDEXED_OBJECTS_LICENSE, AUTOMATION_CREDITS_LICENSE, CS_RESOLUTIONS_LICENSE, and/or ASSET_CREDITS_LICENSE) is returned for a secondary organization that has active organization-level subscriptions for Rovo, Rovo Credits, Indexed Objects, Automation steps, Customer Service Management AI agent resolutions, and/or Assets objects.
For more information, please see Manage your bill for Rovo.
To resolve this blocker, you will need to cancel the Rovo and related subscriptions for the secondary organization. However, Atlassian doesn’t currently support customers' ability to self-service cancellation of Rovo or related subscriptions, though we do have a feature request open with our developers:
If you have an active ticket with Atlassian’s technical support team for performing the organization consolidation, you can work with the support team via that ticket to cancel the Rovo and related subscriptions for the secondary organization. Otherwise, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling these subscriptions.
Service Collection subscription
The Service Collection subscription blocker (sometimes indicated as COLLECTION_ENTITLEMENT) is returned for a secondary organization that has one or more active Service Collection subscriptions for Jira Service Management and Customer Service Management.
For more information, please see Introducing Atlassian Service Collection.
To resolve this blocker, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling or unbundling the Service Collection subscription(s) for the secondary organization.
Siteless apps
The Siteless apps blocker is returned for a secondary organization that manages one or more Atlassian apps that aren’t tenanted on a site using the <subdomain>.atlassian.net or <subdomain>.jira.com format, such as Trello, Bitbucket, or Jira Align. See each section below for more information regarding the relevant siteless app:
Bitbucket workspace
The Siteless apps: Bitbucket workspace blocker is returned for a secondary organization that is linked to one or more Bitbucket workspaces.
To resolve this blocker, you’ll need to delete all Bitbucket workspaces linked to the secondary organization, then wait for their data retention period(s) to elapse.
For instructions, please see Delete a Bitbucket Cloud workspace.
Trello Enterprise
The Siteless apps: Trello Enterprise blocker is returned for a secondary organization that is linked to a Trello Enterprise.
To resolve this blocker, you’ll need to contact Atlassian support and work with our Trello support team to unlink the Trello Enterprise from the secondary organization so that you can relink it with a different Atlassian organization.
Jira Align
The Siteless apps: Jira Align blocker is returned for a secondary organization that is linked to a Jira Align instance.
To resolve this blocker, you’ll need to contact Atlassian support and work with our Jira Align support team to unlink the Jira Align instance from the secondary organization and relink it with a different Atlassian organization.
Strategy Collection subscription
The Strategy Collection subscription blocker (sometimes indicated as COLLECTION_ENTITLEMENT) is returned for a secondary organization that has an active Strategy Collection subscription.
- For more information, please see Introducing Atlassian's Strategy Collection.
To resolve this blocker, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling or unbundling the Strategy Collection subscription for the secondary organization.
Studio app
The Studio app blocker is returned when both the primary and secondary organizations involved in a consolidation have an existing Studio app.
For more information, please see What is Rovo Studio?
If you have an active ticket with Atlassian’s technical support team for performing the organization consolidation, you can work with the support team via that ticket to cancel the Studio subscription for one of the organizations and expedite the data retention period for deleting the app’s data. Otherwise, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling the Studio subscription and expediting the data retention period for deleting the app’s data.
Teamwork Collection subscription
The Teamwork Collection subscription blocker (sometimes indicated as COLLECTION_ENTITLEMENT) is returned for a secondary organization that has an active Teamwork Collection subscription.
- For more information, please see Introducing Atlassian's Teamwork Collection.
To resolve this blocker, you’ll need to contact Atlassian’s pricing, billing and licensing support team for assistance with canceling or unbundling the Teamwork Collection subscription for the secondary organization.
User status conflict
The User status conflict blocker is returned when one or more users exist in both the primary and destination organizations with different statuses. Specifically, affected users are active in one organization but suspended in the other.
To resolve this blocker, you have the following options for each affected user:
Remove the user from the organization where they’re currently suspended.
For instructions, please see Remove user or suspend their access | Remove a user.
Restore the user’s access to the organization where they’re currently suspended.
For instructions, please see Remove user or suspend their access | Restore access.
Suspend the user’s access to the organization where they’re currently active.
For instructions, please see Remove user or suspend their access | Suspend access.