This person’s warning email probably ended up in spam.
In general I’m not sure the best way Atlassian could have handled this. The recent upgrade to move @company.com accounts into having a better security posture and control by the administration of the company does make sense.
Perhaps the person’s account should have just been disabled entirely until they removed either their personal email or @company.com email from the account to choose which way they wanted to go... That might have been the best solution to both protect corporate security and also the individual.