Plan requirement
| Subscription | Suite Professional or higher, Support Professional or higher |
| Access | Admin |
Yes, through SAML. The setup is the standard one, with two small details that catch people out.
How it works
Zendesk is added as an application in Entra, and sign-in goes through it. Nothing about Zendesk is specific to this provider; it is a SAML configuration like any other.
Detail one: the email claim
Zendesk identifies people by email address. Directory accounts sometimes carry a username or an identifier that is not the mail address, and sending the wrong one either fails or creates duplicate users.
Check what is actually sent for a real account rather than what the configuration implies.
Detail two: assignment
The application has to be assigned to people or groups. Configured perfectly and assigned to nobody produces an error for everybody, and it is the first thing to check when it works for you and not the team.
Assign by group
Then somebody joining the group gets access and somebody removed loses it. Assigning individually recreates the manual step this was meant to remove.
Watch the certificate
It expires, and when it does nobody can sign in, with no warning. Put the renewal date in a shared calendar.
This is the most common cause of an unexpected sign-in outage.
Test in a private window
With your ordinary session still open. A misconfiguration with no fallback locks out every admin including the one fixing it.
Then close the old route
Disable Zendesk passwords for team members once it works, or the account is still reachable by a path your provider does not govern.
Comments
0 comments
Article is closed for comments.