Restrict External Users/Groups to Certain Confluence Space(s)

Platform Notice: Cloud and Data Center - This article applies equally to both cloud and data center platforms.

Support for Server* products ended on February 15th 2024. If you are running a Server product, you can visit the Atlassian Server end of support announcement to review your migration options.

*Except Fisheye and Crucible

Summary

For restricting access to Confluence spaces so that a user/group may only view certain content.

Solution

Quick overview (Cloud)

  1. Create a dedicated group for the users you want to restrict (via admin.atlassian.com > Directory > Groups).

  2. In Confluence admin, go to Global Permissions and grant that group the Can Use permission.

  3. Remove the restricted users from the confluence-users group (or any other group with broad space access) — permissions are additive, so membership in a wider group overrides the restriction.

  4. In each target space, go to Space settings > Space access > Groups, add your new group, and assign the desired permissions.

  5. Ensure restricted users are members of only the new group for Confluence access.

Step-by-step guide

  1. Create a new group in the Users or Global Users (if this is a JIRA + Confluence installation) administration page (For Cloud, see Create and update groups, and for Server, see Confluence Groups for Administrators).

  2. (For Server) In the Global Permissions Overview Confluence admin page provide that group with 'Can Use' permission along with any other permissions you'd like.

    For Cloud, you will need to add the group  to Confluence via User Management > Application Access > View Configuration. See Manage group access for more information.

  3. In each space permissions page (1 page per space you wish the user/group to have access to) add the group to the permission with the appropriate level of access.

  4. Finally, make sure users you wish to restrict are only part of the group you've just setup.

Verify it worked

  1. Admin check: In admin.atlassian.com > Directory > Users, look up the restricted user and confirm they are a member of only the new restricted group — not confluence-users or any other group with broad Confluence access. (Remember: Confluence Cloud permissions are additive — membership in any group with "View" access to a space will grant access, regardless of restrictions elsewhere.)

  2. User check: Sign in as (or ask) the restricted user to verify:

    • They can access the intended space(s).

    • They cannot see other spaces (e.g., the space list shows only the permitted spaces, and search does not surface pages from other spaces).

If the user can still see unintended spaces, the most common cause is residual membership in a broader group. Check for IdP/SCIM synced groups that may automatically re-add the user.

Updated on August 6, 2026

Still need help?

The Atlassian Community is here for you.