Plan requirement
| Subscription | Any plan |
| Access | Admin |
The single largest reduction in risk available in this account. Make it mandatory, and plan the recovery path first.
Turn it on
- Open the security settings in Admin Center.
- Require two-factor authentication for team members.
- Tell everybody, with a date.
- Have them enrol and save their recovery codes.
- Enforce it.
Why this one above everything else
A stolen or guessed password stops being enough. Most real incidents involving support tools start with credentials, and this is the control that breaks that chain.
Everything else on the security page is worth doing after this.
Mandatory, not optional
Optional means the people most worth protecting, the ones with the widest access, are as likely as anyone to skip it. Require it for team members.
Plan recovery before enforcing
Somebody will lose their phone. Decide in advance who can help, how they verify who is asking, and where recovery codes are kept.
Without that, the first lockout produces an improvised workaround that undermines the whole thing.
Recovery codes at enrolment
Have people save them when they set it up, not when they need them. Somewhere that is not the phone with the authenticator on it.
Give notice
A week, with instructions. Enforcing it on a Monday morning without warning produces a queue of people who cannot work and one admin trying to help all of them.
With single sign-on
Two-factor usually lives at your identity provider instead. Confirm it is enforced there, and that Zendesk passwords cannot be used as a way around it.
Comments
0 comments
Article is closed for comments.