Zendesk provides the ability to create multiple SSO authentication configurations for different collections of users. This could be as simple as one authentication policy for end users and another for team members, or as complex as different authentication policies for specific groups and organizations of users.
After you've created your SSO configurations, you can view and manage them on the Single sign-on page in Admin Center.
Viewing your SSO configurations
Your SSO configurations display on the Single sign-on page in Admin Center in a list sorted from newest to oldest. The list includes the configuration's name, the type of configuration (SAML, OIDC, or JWT), which types of users it's assigned to, and whether it's active or inactive.
- In Admin Center, click
Account in the sidebar, then select Security > Single sign-on.
Editing SSO configurations
You may need to edit your SSO configurations after you create them. For example, you may need to create a new shared secret for a JWT configuration or update the remote login page URL.
To edit an SSO configuration
- In Admin Center, click
Account in the sidebar, then select Security > Single sign-on.
- Click the option menu icon (
) and select Edit for the SSO configuration you want to edit.
Activating or deactivating SSO configurations
SSO configurations are active when they are assigned to either team members or end users. To inactivate an SSO configuration, you must unassign it from both team members and end users, if applicable.
To activate or deactivate an SSO configuration
- Open the Security settings for team members or end users:
- In Admin Center, click
Account in the sidebar, then select Security > Team member authentication.
- In Admin Center, click
Account in the sidebar, then select Security > End user authentication.
- In Admin Center, click
- Under External authentication > Single sign-on (SSO), select the configuration you want to activate. To inactivate a configuration, clear the check box.
- Click Save.
Setting the primary SSO configuration
- Let them choose: Display all active authentication options on the sign-in page and allow users to choose how they sign in, or
- Redirect to SSO: Require users to sign in using the primary SSO method.
To set a primary SSO method
- Open the Security settings for team members or end users.
- In Admin Center, click
Account in the sidebar, then select Security > Team member authentication.
- In Admin Center, click
Account in the sidebar, then select Security > End user authentication.
- In Admin Center, click
- For Primary SSO, select the name of the SSO configuration you want to
send users to by default.
The Primary SSO field is visible if you have multiple SSO configurations active and you've selected Redirect to SSO.
- Click Save.
Adding "Continue with SSO" buttons to the Zendesk sign-in page
If you let users choose how to sign in, you can show a Continue with SSO button on the Zendesk sign-in page for each active SSO configuration. Customize the button labels so they are meaningful to your users. If you offer multiple SSO sign-in methods, create unique labels so users know which option to choose.
You might not authenticate users this way. For example, if your users only sign in using an identity provider (Idp-initiated SSO), you don't have to add SSO buttons because your users don't use the Zendesk sign-in page.
To add an SSO button to the Zendesk sign-in page
- In Admin Center, click
Account in the sidebar, then select Security > Single sign-on.
- Click the option menu icon (
) and select Edit for the SSO configuration you want to add to the sign-in page.
- Scroll to the bottom of the page and select Show button when users sign
in.
- In the Button name field, enter the text that should follow "Continue
with."
For example, typing team member SSO creates a button labeled Continue with team member SSO.
- Click Save.
- If the SSO configuration is inactive, activate it by assigning it to team members or end users.
Deleting SSO configurations
You can delete inactive SSO configurations.
To delete an SSO configuration
- In Admin Center, click
Account in the sidebar, then select Security > Single sign-on.
- If the configuration you want to delete is active, deactivate it first. See Activating or deactivating SSO configurations.
- Click the option menu icon (
) and select Delete for the SSO configuration you want to delete.
10 comments
Chris Fassano
Anton de Young - Are we able to delete SSO configurations? I don't see an option for that in the UI.
0
Dainne Kiara Lucena-Laxamana
Hi Chris Fassano,
At the moment we don't allow SSO configurations to be deleted. Hopefully, in the future, we can add that combined with logs & restoration features to deal with accidental deletes.
0
Peter Boast
We are currently configured for SSO through MO365 and Zendesk. We would like to stop using SSO and just have username and password login. What is the best process to acheive this?
0
Gabriel Manlapig
Hi Peter,
If External Authentication is turned off then Zendesk native authentication will be used when logging into Zendesk (username and password) and turning it on again will set it (SSO) as the default once more.
To edit your user authentication:
I hope this helps! Thank you!
0
abhishek sen
If I have multiple SSOs setup, then how do we display all options in sign in?
I see only one option "Continue with SSO" and that redirects to primary SSO all the time.
2
Chris Rose
What is the maximum number of SSO configurations we can have simultaneously?
0
Noly Maron Unson
Hi abhishek,
You can check How can I set up multiple Zendesk SSO integrations in separate help centers? for a workaround with this.
Hi Chris,
The default Zendesk authentication method allows the creation of two SSO options.
Hope this helps.
0
Rajeswara Rao Devavarapu
In Zendesk, Can we use User principal name (UPN) for SSO login?
As of now we are using the Email for SSO login we wants to move from email to UPN for SSO logins.
0
radong
How does one identify when the certificate fingerprint configured in Security > Single sign-on expires?
0
Niclas gmail
There is a bit of inconsistency with the naming… Why is the SSO not called "Sign in with …" ?
It would be nice to have a custom favicon for the SSO.
0