| Announced on | Rollout starts | Rollout ends |
| May 28, 2026 | August 17, 2026 | August 31, 2026 |
Zendesk is updating the password policy requirements for team members to ensure all accounts meet current security best practices. As part of this update, legacy password security levels will be removed to provide a more streamlined and secure authentication experience.
This announcement includes the following topics:
- What's changing?
- Why is Zendesk making this change?
- What do I need to do?
- Frequently asked questions
What's changing?
- Zendesk is removing the legacy password security levels: Low, Medium, and High for team member authentication. This change does not affect end-user authentication.
- Accounts using these legacy security levels must migrate to either the Recommended password security level or a Custom password policy.
- Starting August 17, 2026, any account still using a legacy password security level will be automatically migrated to the Recommended level.
-
Certain custom password policy settings are being updated to align with new standards. If your current settings fall into a legacy range, you must update them before rollout starts on August 17, 2026 to prevent a forced password reset.
Password policy setting Current legacy range New required range Minimum length 5-13 characters 12-20 characters Passwords can resemble email Allowed Not allowed
Accounts using weaker legacy configurations will require team members to reset their passwords to comply with the updated policy.
Why is Zendesk making this change?
Legacy password security levels no longer meet modern security standards and expose accounts to increased risk. Outdated lengths, weak lockout thresholds, and predictable passwords make accounts vulnerable to unauthorized access and credential attacks.
Updating these password policy settings ensures all Zendesk accounts are protected by strong, industry-standard authentication rules. While you can still use a Custom policy, switching to the Recommended security level aligns your account with evolving security protections, preventing forced password resets during future policy updates.
What do I need to do?
Update your team member password policy before August 17, 2026.
- Select the Recommended security level: Preferred for long-term compatibility with ongoing security enhancements.
- Select the Custom password policy: Use if your organization has specific requirements. Note that further changes to Custom policy settings may require additional password resets in the future.
If you take no action by August 17, 2026, your account will migrate automatically to the Recommended password security level, and all team members will be prompted to reset their passwords upon their next sign-in.
For more information and instructions on updating your settings, see Changing the password security level.
If you have feedback or questions related to this announcement, visit our community forum, where we collect and manage customer product feedback. For general assistance with your Zendesk products, contact Zendesk Customer Support.
Frequently asked questions
What’s happening and when?
The Low, Medium, and High password security levels are being removed for team members. Accounts using them move to Recommended. Accounts using a Custom password policy keep it, with two settings brought up to the new minimums where they fall short.
The update reaches accounts in stages between August 17 and August 31, 2026. Your account is updated at some point inside that window rather than on a single fixed date, and the sequence below then runs on your account's own schedule.
- Phase 1 (Between August 17 and August 31, 2026): Your password policy is updated
Your account moves to Recommended, or your Custom policy is brought up to the new minimums. Every team member's current password goes on a five day countdown. Passwords keep working during those five days, no one is signed out, and nothing in your account stops working.
- Phase 2 (Five days after your account is updated): Passwords expire
Each team member receives two emails at their primary email address: one three days before their password expires, and one on the day it expires. Both link to their security settings so they can set a new password ahead of time. Passwords expire on schedule whether or not someone opens the email.
- Phase 3 (At each team member's next sign-in): Team members set a new password
Once a password has expired, that team member sets a new one the next time they sign in. They keep their account, their permissions, and their data. Because this happens at the next sign-in, someone who is away keeps their expired password until they return, so expect reset prompts to continue after August 31.
What does the Recommended password level require?
A password that:
- Is at least 12 characters long
- Includes uppercase and lowercase letters
- Includes at least one number
- Includes at least one special character, such as ! @ # %
- Is not an email address
- Contains no term tied to your account or to you, including your subdomain, a brand name on your account, your own name, and the part of your email address before the @
- Has not appeared in a known data breach
Accounts lock after five failed sign-in attempts. These values are fixed, and Recommended passwords do not expire on a schedule.
What changes for Custom password policies?
Custom stays configurable. Two settings change, and either one on its own means your account is updated and your team sets new passwords.
| Setting | Your account is updated when | What it becomes |
| Minimum password length | Set below 12 characters | Raised to 12. The available range becomes 12 to 20 characters. |
| Passwords can resemble email | Set to Yes | The setting is removed, and email-like passwords are always disallowed. |
Only the setting that’s impacted changes. The rest of your Custom policy stays as you configured it, including failed attempts until lockout.
All Custom policies also start checking new passwords against known data breaches. On an account that already meets both minimums, that check applies the next time each person sets a password.
How do I know if I’m impacted?
- In Admin Center, click Account > Security > Team member authentication.
- Check whether Zendesk authentication, meaning email and password sign in, is turned on for team members. If it is turned off, no team member signs in with a Zendesk password, so nothing expires and no one is prompted.
- Read the password level.
- Low, Medium, or High: your account is affected and moves to Recommended.
- Recommended: your account is already there and nothing changes.
- Custom: open your Custom settings and check two fields. A minimum length of 5 through 11 characters, or "passwords can resemble email" set to Yes, means your account is affected. If your minimum length is 12 or higher and "passwords can resemble email" is set to No, the rollout finds nothing to change and no password expires.
Having SSO configured does not mean password sign in is off. On most SSO accounts, email and password sign-in stays enabled underneath as a fallback.
Can I update the policy myself if I want to control the timing?
Yes. An admin can switch the password level in Admin Center. For step by step instructions, see Setting the password security level.
Switching to Recommended yourself starts the same five day countdown and the same reset. Once your account is on Recommended or Custom, Low, Medium, and High are no longer available to select.
Should I tell my team what to expect?
Yes. The password expiration emails go to individual team members, not to administrators. Admins receive no summary and no copy.
Two points worth stating plainly to your team:
- Everyone who holds a password that was set before this rollout sets a new one, including people whose passwords are already long and strong.
- Team members who sign in through SSO are included, if Zendesk authentication is also turned on. See Accessing your Zendesk account when your SSO service is down.
What happens if I do nothing?
Your account is updated automatically when the rollout reaches it, your team's passwords expire five days later, and each team member sets a new password at their next sign-in. Nothing else in your account changes.
What happens on each key date?
| Date | What happens |
| August 17, 2026 | Rollout begins. The first accounts move from a legacy level to Recommended, and the first Custom policies below the new minimums are updated. Custom policies start checking new passwords against known data breaches. |
| August 17 to August 31, 2026 | Remaining accounts are updated in stages. Each account's five day countdown starts on the day it is updated. |
| From about August 19, 2026 | Password expiration warning emails begin. Each affected team member receives one three days before their password expires and one on the day it expires. |
| From about August 22, 2026 | The first passwords expire, five days after the first accounts were updated. Those team members set a new password at their next sign in. |
| August 31, 2026 | Rollout ends. Every affected account has the new policy applied. |
| Into early September 2026 | Passwords expire on accounts updated near the end of the window. Reset prompts continue for anyone who has not signed in since their password expired. |
Does my entire team have to reset, or only the people with weak passwords?
The entire team. The password policy applies at the account level and Zendesk does not inspect individual passwords, so a team member with a 20 character password sets a new one alongside a team member with an eight character password. Team members who set a compliant password after your account was updated are not prompted again.
Will my team be warned before their passwords expire?
Yes. Each affected team member receives an email at their primary email address three days before their password expires, and a second one on the day it expires. Both link to their security settings. If someone has more than one email address on their profile, only the primary address receives these emails. Treat the emails as a reminder rather than the trigger: the password expires on schedule either way.
If I update my password policy myself, can I avoid the password resets?
No. Switching your account to Recommended or Custom does what the rollout does, so your team's passwords expire and everyone sets a new one.
How do I set a new password before mine expires?
While you are signed in:
- Click your profile icon in the upper right, then select View profile page.
- Select the Security settings tab.
- In the Password section, click Change.
- Enter a password that meets the new requirements, then save.
This clears the countdown, so you are not prompted later.
My password has already expired. How do I sign in?
- Enter your email address and password on the sign in page as usual.
- You see a message stating that your password has expired.
- Enter your email address to receive a reset email.
- Follow the link in that email and set a new password.
Only your first sign-in after expiry sends you to that page automatically. After that, select Forgot password? on the sign-in page to get there yourself. Reset links are valid for 24 hours, and requesting a new link cancels the previous one.
I can't get into the inbox for the email address on my account. How do I set a new password?
The reset link goes to whichever verified email address you enter on the Reset your password page, so if you have another verified address you can reach, use that one. An unverified address does not work; entering it sends a verification email rather than a reset link.
If your only verified address is one you cannot reach, an administrator can help. The account owner or a Support administrator can add a new address to your profile and make it primary once you have verified it, or send you a reset email. See Managing team member user email addresses. If your account owner has turned on Enable admins to set passwords (Admin Center under Account > Security > Advanced > Passwords) that lets administrators set user passwords, an administrator can also set a password for you directly.
My team signs in through SSO. Why are they getting password expiry emails?
Redirecting sign-in to your identity provider does not turn off Zendesk email and password authentication. On most SSO accounts it stays enabled underneath as a fallback, which means your team members still have Zendesk passwords, those passwords have a policy attached, and they expire like any others.
If you would rather your team had no Zendesk password at all, you can turn off Zendesk authentication so SSO is the only way in. See Accessing your Zendesk account when your SSO service is down.
My account uses a Custom password policy. Is it affected?
Only if your minimum password length is set below 12 characters, or "passwords can resemble email" is set to Yes. Either one on its own is enough, and your other Custom settings are left alone. If your policy already meets both minimums, nothing changes and no one resets, and your policy starts checking new passwords against known data breaches the next time team members set a new password.
Can I switch back to Low, Medium, or High later?
No. Once your account leaves a legacy level, those levels are no longer available. You can move between Recommended and Custom, and each move expires your team's passwords and prompts everyone to set a new one, in both directions.
Do my end users have to reset their passwords?
No. This change covers team member authentication only. Your end users keep their current passwords, nothing expires for them, and they receive no emails about this. Team member and end user password settings are separate, and only the team member setting changes. Raising your end user password level yourself is a separate change that prompts your end users to reset.