Setting up SSO with Active Directory and ADFS

Plan requirement

Subscription Suite Professional or higher, Support Professional or higher
Access Admin

Connecting Zendesk to Active Directory through ADFS. Same principles as any SAML setup, with its own details.

Set it up

  1. Add Zendesk as a relying party trust in ADFS.
  2. Configure the claim rules, including the email address.
  3. Restrict access to the right security group.
  4. Copy the certificate and endpoint into Zendesk.
  5. Test with one account in a private window.

The email claim is the critical one

Zendesk matches people by email address. Directory accounts sometimes hold a login name that is not the mail address, and sending the wrong one either fails or creates duplicate users.

Verify what the claim actually contains for a real account.

Restrict by security group

Rather than allowing everybody in the directory. Then Zendesk access follows group membership, which is what makes joining and leaving automatic.

Certificates expire

ADFS certificates roll over, and when one does without Zendesk being updated, sign-in stops for everybody at once.

Put the renewal in a calendar. This is the most common cause of an unexpected SSO outage.

Internal and external access

ADFS is often reachable inside the network and through a proxy outside it. Agents working from home use a different path, so test both rather than only the office.

Keep a way in

Test in a private window with an admin session still open. A broken trust with no fallback locks out everybody, including whoever would fix it.

Involve the directory team

Claim rules and certificates belong to whoever runs ADFS. Contact pluscloud support and we will work through the Zendesk side with them.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.