Plan requirement
| Subscription | Any plan |
| Access | Admin |
How people get in: passwords, social accounts, or your own identity provider. Different answers for staff and customers.
The options
- Zendesk passwords, managed here, with two-factor available.
- Social sign-in, where customers use an account they already have.
- Single sign-on, where your identity provider decides.
They are configured separately for team members and for end users, which is the distinction to hold on to.
For staff: single sign-on if you have it
One account to disable when somebody leaves, one place for policy, no separate password to manage. It is the highest-value security change most organisations can make here.
Where you do not have it, Zendesk passwords plus mandatory two-factor is the alternative.
For customers: as little as possible
Every sign-in requirement loses people who wanted an answer. If most of your help centre does not need to be restricted, most of your customers should not need an account.
Where they do, social sign-in removes another password.
Do not mix without deciding
Leaving Zendesk passwords enabled alongside single sign-on means an account can still be reached the old way, which quietly undoes the offboarding benefit.
Plan the recovery path
Whatever you choose, know what happens when somebody cannot get in: a lost phone, a provider outage, a colleague who left. Deciding that in advance avoids an urgent workaround that weakens the whole arrangement.
Comments
0 comments
Article is closed for comments.