General security practices for your Zendesk

Plan requirement

Subscription Any plan
Access Admin

The handful of settings that carry most of the risk, and the two habits that matter more than any of them.

Why this account is worth protecting

Your Zendesk holds what customers told you: names, addresses, order details, and whatever they attached. It is a substantial store of personal data, and it is usually reachable from anywhere.

The settings that matter most

  1. Two-factor authentication for every agent and admin. The single largest reduction in risk available.
  2. Single sign-on where you have it, so leaving the company removes access everywhere at once.
  3. Session length, so an unattended laptop does not stay signed in indefinitely.
  4. Admin count. Fewer admins is a security setting, and most accounts have more than they need.
  5. Data export, restricted to named people where your plan allows.

Habit one: offboard properly

Deactivate the account the day somebody leaves. An active account belonging to a former colleague is the one nobody is watching, and it is how most real incidents start.

Habit two: review access quarterly

Who is an admin, who has not signed in, who can export. Fifteen minutes, four times a year. It finds things no setting prevents.

Watch what agents can reach

Roles decide who sees which tickets. An agent role with access to everything is convenient and means a compromised account exposes everything.

Where to start

Two-factor authentication and the admin list. Those two, done today, cover more ground than anything else on this page.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.