Setting the password security level

Plan requirement

Subscription Any plan
Access Admin

How strict your password rules are. Stricter is not automatically better, and the one rule most people reach for first actively makes things worse.

Set it

  1. Open the security settings in Admin Center.
  2. Choose the level for team members.
  3. Choose the level for end users separately.
  4. Tell staff before it takes effect.

Set staff and customers separately

Agents have access to your customer data and should face a strict policy. Customers have access to their own tickets, and every extra requirement loses some of them at the sign-in page.

Length beats complexity

A long passphrase is both stronger and easier to remember than a short string with symbols in it. Requiring more character classes mostly produces predictable substitutions and a note on a desk.

Forced expiry is the rule to think twice about

Regular forced changes push people towards small predictable variations and writing them down. Current guidance from most security bodies is to change passwords when there is reason to, not on a timer.

If a compliance requirement mandates it, follow the requirement; otherwise it is worth questioning.

Two-factor is worth more than any policy here

A moderate password with two-factor beats a strict password without it, by a wide margin. If you only do one thing on this page, do that instead.

Tell people before it changes

A stricter policy prompts a wave of resets, and unannounced it arrives as a fault. One message beforehand covers it.

Single sign-on makes this moot

Where staff sign in through your identity provider, the policy lives there. Then this setting only matters for anyone who can still use a Zendesk password.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.