Plan requirement
| Subscription | Any plan |
| Access | Admin |
How strict your password rules are. Stricter is not automatically better, and the one rule most people reach for first actively makes things worse.
Set it
- Open the security settings in Admin Center.
- Choose the level for team members.
- Choose the level for end users separately.
- Tell staff before it takes effect.
Set staff and customers separately
Agents have access to your customer data and should face a strict policy. Customers have access to their own tickets, and every extra requirement loses some of them at the sign-in page.
Length beats complexity
A long passphrase is both stronger and easier to remember than a short string with symbols in it. Requiring more character classes mostly produces predictable substitutions and a note on a desk.
Forced expiry is the rule to think twice about
Regular forced changes push people towards small predictable variations and writing them down. Current guidance from most security bodies is to change passwords when there is reason to, not on a timer.
If a compliance requirement mandates it, follow the requirement; otherwise it is worth questioning.
Two-factor is worth more than any policy here
A moderate password with two-factor beats a strict password without it, by a wide margin. If you only do one thing on this page, do that instead.
Tell people before it changes
A stricter policy prompts a wave of resets, and unannounced it arrives as a fault. One message beforehand covers it.
Single sign-on makes this moot
Where staff sign in through your identity provider, the policy lives there. Then this setting only matters for anyone who can still use a Zendesk password.
Comments
0 comments
Article is closed for comments.