Enabling SAML single sign-on

Plan requirement

Subscription Suite Professional or higher, Support Professional or higher
Access Admin

Signing in through your own identity provider. The highest-value access change most organisations can make.

Set it up

  1. Configure Zendesk as an application in your identity provider.
  2. Enter the provider's details in the authentication settings.
  3. Map the attributes, including email address.
  4. Test with one account, in a separate browser session.
  5. Enable it for team members.

Why it is worth the work

Access ends when employment does, in one place. No separate password, no account left active because somebody forgot Zendesk was on the list.

Offboarding is where most real incidents begin, and this closes it structurally rather than by remembering.

Keep a way in while testing

Test in a private window while your normal session stays signed in. A misconfigured provider with no fallback locks every admin out, including the one fixing it.

This is the mistake worth planning around.

Email mapping decides identity

Zendesk matches on email address. If the provider sends a different address from the one on the account, you get a new user rather than a sign-in.

Check that mapping before enabling it for everybody.

Decide about Zendesk passwords

Leaving them enabled means an account can still be reached the old way, which undoes the offboarding benefit. Disable them for team members once single sign-on is working.

Plan for provider outages

If the provider is unavailable, nobody signs in. Agree what happens then, before it happens on a busy morning.

Do it with us

Contact pluscloud support and we will go through it with you. This is one of the configurations where a mistake affects everybody at once.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.