SaaS ITGC チェック

ツール一覧 › Zendesk

Zendesk のアクセス管理機能(SSO・MFA・IP制限・監査ログ)

公式資料によると、Zendesk は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-04)

判定(かんたん基準)

Step1:MFA(0.92) / SSO(1.00) + 監査ログ(1.00)|許可
最終|許可

かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。

項目ごとの読み取り

項目公式資料の記載確率根拠
MFA対応と記載0.92Managing two-factor authentication
SSO対応と記載1.00Setting up SAML single sign-on with Okta
2FA対応と記載1.00Managing two-factor authentication
IP制限対応と記載1.00Restricting access to Zendesk using IP restrictions
監査ログ対応と記載1.00Viewing the audit log for changes to your account

「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。

根拠(公式資料の原文)

SSO:Setting up SAML single sign-on with Okta – Zendesk help

https://support.zendesk.com/hc/en-us/articles/4408821683738-Setting-up-SAML-single-sign-on-with-Okta

Setting up SAML single sign-on with Okta – Zendesk help

What's my plan?

Team, Growth, Professional, Enterprise, or Enterprise Plus

続きを読む(ほか 61 段落)

Team, Professional, or Enterprise

Verified AI summary ◀▼

Set up SAML single sign-on with Okta to streamline user authentication. Start by configuring SAML in Okta, then use the provided SAML SSO URL, Remote logout URL, and Certificate fingerprint to complete the setup. Assign SSO to users and manage authentication methods. Note: Switching from third-party SSO to native authentication requires users to reset their passwords.

Location: Admin Center > Account > Security > Single

Note: The tools described in this article were developed by a third

party. Zendesk doesn't support the tools or guarantee results. For more information, see the

Okta documentation.

Okta supports single sign-on with Zendesk using SAML (Security Assertion Markup Language).

For many of the settings used to configure single sign-on in Okta, you'll find much more

detailed information in the Okta user interface. For more about Single sign-on using SAML

support in Zendesk, see Enabling SAML single sign-on.

Configuring SAML must be done in both in your Okta account and in Zendesk. You start in Okta

first and get the SAML information you'll need to complete the configuration in Zendesk.

This article includes the following topics:

Configuring SAML in Okta

Configuring SAML in Zendesk

Assign users to SAML single sign-on with Okta

Switching authentication methods

Sign in to Okta as an administrator and then follow the steps below.

To configure SAML for Zendesk in Okta

In Okta, from the drop-down list in the upper-right corner, make sure you are using

the Classic UI interface (not the Developer

Select Add Applications from the dashboard.

Click Add Application, then search for and choose Zendesk. The Add

Zendesk wizard appears.

On the first screen, General Settings, add a name for the application and your

Zendesk subdomain. For example, if your Zendesk URL is mycompany.zendesk.com,

enter mycompany). Click Next.

On the second screen, Sign-On Options, select SAML 2.0. This is where

you'll find the SAML SSO URL, the Remote logout URL, and the

Certificate fingerprint (SHA2). You need this information to complete the SAML

setup in Zendesk.

Click the SAML 2.0 setup instructions for Zendesk link.

A page appears with

instructions on how to configure SAML in Zendesk. See Configuring SAML in Zendesk below for the latest

Copy the SAML SSO URL, the Remote logout URL, and the Certificate

You need this information to configure SAML in Zendesk. When

you've finished copying, close this window and return to your Okta dashboard.

(Optional) If you enable User Management, you'll be able to import users from

Zendesk into your Okta account, provision new Zendesk accounts from Okta, and push Okta

user profile updates and passwords to Zendesk.

You'll find information about these

Okta features in your Okta account and documentation.

(Optional) People allows you to select who in your Okta account has access to

Zendesk. This step is not covered in this article. You'll find information about these

When you've completed each step, click Next to complete and close the Zendesk

configuration in Okta.

When your Zendesk for Okta setup is complete and the information you need for setting up

SAML in Zendesk is available, sign in to your Zendesk account as an admin and enable SAML single sign-on. You'll need the SAML SSO URL,

the Remote logout URL, and the Certificate fingerprint from Okta to complete

Note: When you enable single sign-on via SAML or JWT, be aware that passwords do not expire

even if your Zendesk password policy is set to high because passwords are not stored in

Zendesk. Additionally, if agents manually add a Zendesk password to their account, these

passwords will not expire.

After configuring SAML single sign-on with Okta, assign this SSO option to end users, staff

members (agents and administrators), or both. For more information, see Assigning SAML SSO to users.

Important: If you use a third-party SSO method to create and authenticate users in

Zendesk, then switch to Zendesk authentication, these users will not have a password

available for login. To gain access, ask these users to reset their passwords from the

Zendesk sign in page.

Powered by Zendesk

MFA:Managing two-factor authentication – Zendesk help

https://support.zendesk.com/hc/en-us/articles/4408826974874-Managing-two-factor-authentication

Managing two-factor authentication – Zendesk help

Two-factor authentication is an added security layer that requires users to verify their identity after signing in using a passcode, reducing the risk of unauthorized access. You can require two-factor authentication, or each user can set up two-factor authentication for their own use.

Two-factor authentication adds another sign-in check to protect admin, agent, and end user accounts from unauthorized access. You can require 2FA, let users turn it on themselves, track usage with a 2FA status report, and help locked-out users regain access with recovery codes or profile updates. It works with email, authenticator app, or SMS for supported users.

続きを読む(ほか 51 段落)

Location: Admin Center > Account > Security >

using Google authentication.

Zendesk recommends turning on two-factor authentication to help protect against

potential situations that could result in an admin or agent account being

Set up two-factor authentication for the user so they

can sign back in again.

For example, select a new

method to receive recovery codes, such as an

authenticator app, or change the email address to

where codes can be sent. See Turning on

two-factor authentication.

Instruct the end user to sign in to Zendesk using the

authentication is optional

After you're signed in as the user, turn off two-factor

authentication.

Instruct the end user to sign in to Zendesk, where they

can optionally turn two-factor

authentication back on and set it up again.

The user will receive a new set of recovery

You can require two-factor authentication for all team members, all end users, or both user

types. Once this setting is turned on, users will be required to set

up two-factor authentication the next time they sign in. Users see

the following dialog after entering their email and password.

The two-factor authentication wizard guides users through the process,

which includes options for how they'd like to receive a passcode:

authenticator app, email, or SMS.

You can optionally notify users of the change and include a link to an

article for more information about two-factor authentication:

For admins and agents: Using two-factor authentication

to sign in to Zendesk Support

For end users: Accessing help

center with two-factor authentication

When you require two-factor authentication, users are prompted for a

passcode every time they sign in.

To require two-factor authentication

In Admin Center, click

Account in the sidebar, then select Security > Advanced.

Click the Authentication tab.

Select the options that apply:

Require two-factor authentication (2FA) for

You can generate a 2FA status report, in the form of a CSV spreadsheet, listing all the admins

and agents in your account and whether or not they're using

two-factor authentication. It's a good idea to do this periodically

if you require two-factor authentication. This option is not

available to track end users.

To generate a 2FA status report

Click Generate 2FA status report.

Check your Zendesk email. You should get an email shortly with a link to download the spreadsheet.

You can turn off two-factor authentication if you no longer want to

require it on your account. After you turn it off, users will no

longer be required to enter a passcode when signing in, unless they

2FA:Managing two-factor authentication – Zendesk help

https://support.zendesk.com/hc/en-us/articles/4408826974874-Managing-two-factor-authentication

Managing two-factor authentication – Zendesk help

Two-factor authentication is an added security layer that requires users to verify their identity after signing in using a passcode, reducing the risk of unauthorized access. You can require two-factor authentication, or each user can set up two-factor authentication for their own use.

Two-factor authentication adds another sign-in check to protect admin, agent, and end user accounts from unauthorized access. You can require 2FA, let users turn it on themselves, track usage with a 2FA status report, and help locked-out users regain access with recovery codes or profile updates. It works with email, authenticator app, or SMS for supported users.

続きを読む(ほか 106 段落)

Two-factor authentication is an added security layer that requires users to verify their identity

after signing in using a passcode, reducing the risk of unauthorized access.

You can require two-factor authentication, or each user can set up

two-factor authentication for their own use.

Two-factor authentication applies to users who sign in to your Zendesk using Zendesk

authentication (email and password). It's not available for users who sign

in using third-party authentication, such as Google authentication services,

JWT, or SAML. However, these users might still be able to use third-party

two-factor authentication, such as Google 2-Step Verification, if you're

using Google authentication.

Zendesk recommends turning on two-factor authentication to help protect against

potential situations that could result in an admin or agent account being

compromised, such as a leaked password. If you require two-factor

authentication, it's a good idea to periodically generate a 2FA status

report to track who's using two-factor authentication to access their

Zendesk account.

This article covers the following topics:

Important considerations before turning on two-factor authentication

Helping users regain access to their accounts

Requiring two-factor authentication on the account

Tracking who's using two-factor authentication

Turning off two-factor authentication

Before turning on two-factor authentication, make sure you understand the

following important considerations:

On trial accounts, agents can’t receive passcodes by

text message. If you’re turning on two-factor

authentication for a trial account, agents must use

email or an authenticator app to get their codes.

(Text message delivery isn’t supported for end users

to receive passcodes on any account type.)

You can use two-factor authentication on the Zendesk

website or with the Zendesk iOS or Android apps.

However, the Zendesk REST API doesn't currently

support two-factor authentication. See Using the API when SSO or

two-factor authentication is enabled in the

developer documentation.

Requiring two-factor authentication does not impact API

calls that are using an API token.

Team members can use one of their recovery codes to regain access

to their account. Recovery codes are displayed once to the

team member when they initially set up two-factor

account depends on whether two-factor authentication is

required on the account or optional and the end user enabled

sign in as an end user.

To help an end user regain access to Zendesk when two-factor

authentication is required

Assume (sign in as)

Click the profile icon on the upper-right side of any

help center page, then click Profile to

display the user's profile.

Click Manage 2FA.

Set up two-factor authentication for the user so they

can sign back in again.

For example, select a new

method to receive recovery codes, such as an

authenticator app, or change the email address to

where codes can be sent. See Turning on

two-factor authentication.

Instruct the end user to sign in to Zendesk using the

authentication is optional

After you're signed in as the user, turn off two-factor

authentication.

Instruct the end user to sign in to Zendesk, where they

can optionally turn two-factor

authentication back on and set it up again.

The user will receive a new set of recovery

You can require two-factor authentication for all team members, all end users, or both user

types. Once this setting is turned on, users will be required to set

up two-factor authentication the next time they sign in. Users see

the following dialog after entering their email and password.

The two-factor authentication wizard guides users through the process,

which includes options for how they'd like to receive a passcode:

authenticator app, email, or SMS.

You can optionally notify users of the change and include a link to an

article for more information about two-factor authentication:

For admins and agents: Using two-factor authentication

to sign in to Zendesk Support

For end users: Accessing help

center with two-factor authentication

When you require two-factor authentication, users are prompted for a

passcode every time they sign in.

To require two-factor authentication

In Admin Center, click

Account in the sidebar, then select Security > Advanced.

Click the Authentication tab.

Select the options that apply:

Require two-factor authentication (2FA) for

You can generate a 2FA status report, in the form of a CSV spreadsheet, listing all the admins

and agents in your account and whether or not they're using

two-factor authentication. It's a good idea to do this periodically

if you require two-factor authentication. This option is not

available to track end users.

To generate a 2FA status report

Click Generate 2FA status report.

Check your Zendesk email. You should get an email shortly with a link to download the spreadsheet.

You can turn off two-factor authentication if you no longer want to

require it on your account. After you turn it off, users will no

longer be required to enter a passcode when signing in, unless they

have turned on two-factor authentication for themselves in their

If you turned off two-factor authentication but users are still being

prompted for a passcode, users can refer to the following resources

to turn it off:

For agents: Turning off

two-factor authentication

For end users: Turning off

To turn off two-factor authentication

IP制限:Restricting access to Zendesk using IP restrictions

https://support.zendesk.com/hc/en-us/articles/4408894156186-Restricting-access-to-Zendesk-using-IP-restrictions

Restricting access to Zendesk using IP restrictions – Zendesk help

You can restrict access to Zendesk to users within a specified IP address range. You can also restrict access to users with specific IP addresses. This means that any attempt to make API calls, sign in, or access pages in any Zendesk product will fail from outside your allowed IP addresses. For example, to restrict access to users in your company, only allow access from your company's IP addresses.

Team, Professional, or Enterprise

続きを読む(ほか 41 段落)

You can restrict access to your account by allowing only specific IP addresses or ranges, blocking sign-ins, API calls, and page access from outside these IPs. Customers can be allowed to bypass restrictions while agents and admins cannot. Be sure to include all external IPs for integrations. Some undocumented endpoints remain accessible regardless of restrictions, so review their security implications carefully.

Location: Admin Center > Account > Security >

You can restrict access to Zendesk to users within a specified IP address range. You can

also restrict access to users with specific IP addresses. This means that any attempt to

make API calls, sign in, or access pages in any Zendesk product will fail from outside

your allowed IP addresses. For example, to restrict access to users in your company,

only allow access from your company's IP addresses.

You can also allow customers (but not agents and administrators) to bypass IP

restrictions. IP restrictions you manage in Admin Center apply to all Zendesk products

and Zendesk mobile applications. The restrictions may also affect how other products,

such as Gmail attachments, work.

Note: Enabling IP-based access restrictions can break third-party

integrations. Be sure to include all external IPs that need access to your account

via the Zendesk API.

To set IP restrictions

In Admin Center, click

Account in the sidebar, then select Security > Advanced.

Click the IP Restrictions tab.

Select Enable IP restrictions, then enter the Allowed IP Ranges,

which can include ranges or individual IP addresses.

When specifying IP

addresses, separate each address or range with a space.

are available to specify a range:

Use asterisk (*) wildcards. An IP address consists of four numbers

separated by periods, such as 192.168.0.1. You can substitute

a single asterisk character (*) for any number group to let Zendesk

know that it should accept any value in that space. For example,

192.*.*.* allows any IP address whose first number is

Use IP subnet mask syntax. For

example, 192.168.1.0/25 specifies all the IP addresses

You can't specify IP ranges where the CIDR (Classless

10.0.0.0/0, the /0 is invalid.

option ensures that your customers can access your help center and messaging

allowed IP addresses.

address restrictions.

(Optional) If your implementation involves any third-party services, such as

the IP restrictions in place. Review these endpoints carefully and consider any

These endpoints are considered unsupported. Zendesk is not responsible for any

/api/v2/pcm/campaign_analytics

Public access to this messaging analytics endpoint is required

/api/v2/pcm/campaign_list

監査ログ:Viewing the audit log for changes to your account

https://support.zendesk.com/hc/en-us/articles/4408828001434-Viewing-the-audit-log-for-changes-to-your-account

Viewing the audit log for changes to your account – Zendesk help

The audit log allows customers on Enterprise plans and above to view various changes in their Zendesk account since the account was created. It saves a record of these changes indefinitely, and you can view the entire change history.

What's my plan?

続きを読む(ほか 90 段落)

Enterprise or Enterprise Plus

Verified AI summary ◀▼

Access the audit log to track changes made by admins and agents to your account. View detailed entries, including time, actor, and activity type. Use filters to find specific events and export the log as a CSV file. This feature helps you monitor account modifications and maintain a clear record of activities.

Location: Admin Center > Account > Logs > Audit log

The audit log allows customers on Enterprise plans and above to view various

changes in their Zendesk account since the account was created. It saves a

record of these changes indefinitely, and you can view the entire change

Admins and agents with permission can

view the audit log in Admin

Center or through the Support API.

This article contains the following sections:

About the audit log changes

Viewing the audit log in Admin Center

Filtering the audit log

Exporting the audit log

There are two key things to understand about the audit log: the types of changes

captured and the details provided for each log

Changes captured in the audit log

The audit log tracks changes that agents and admins have made to

your Zendesk account. End user activities are not

The audit log shows changes to the following areas:

Account information and settings

Users (updates to existing users only; activities

related to creating new users are not captured)

Ticket settings

Audit log entries

For each entry in the audit log, the following information is

Time and date the event occurred

User or system that caused the event

changes are performed through automated system

processes and appear as actions by the system user

IP address of the user who caused the

Object changed by the actor

Type of action for the event (Created,

Updated, Deleted, Exported, or Signed in)

Details about the event

In Admin Center, audit log timestamps appear in your account's time

zone. If you are unsure what time the audit

log is using, hover over the information icon in the

Time column heading.

In the Zendesk API and CSV export file, audit log timestamps

appear in Coordinated Universal Time (UTC).

From the Audit log page in Admin Center, you can view the audit log as a

whole, sort the log by time, filter the list, or export a copy of

To view the audit log

In Admin Center, click

Account in the sidebar, then select Logs > Audit log.

Often, only part of the picture is available when you visit the audit

log. For example, you might know when something changed (but not

what) or who changed something (but not when). Since the audit log

can include a large volume of events, filtering makes it easier to

find what you’re looking for.

While top audit events are available as filters, not all event types can

be filtered. Additional audit events will be added over time.

Tip: If you repeat the same audit log

filters, bookmark them in your web browser after you apply them. The

filter displays in the URL.

To filter the audit log

Click the Time column to sort the entries by date.

To use more filters, click Filter.

Additional filters

appear in a side drawer.

To find entries within a specific date range, enter a Start

date and End date.

Enter a name in the Actor field to filter by the

people or systems responsible for the

Select an Activity type to filter entries by the action

type (Created, Updated, Deleted, Exported, or Signed

Use the filters in the Item section to filter by a specific

setting, user, or business rule that has changed.

In the Type field, select or search for

the generic item type you want to filter by (for

example, "trigger").

An initial list of item

types appears in the dropdown, but you can start

typing to access more. For example, typing

cus displays the Customer, Custom Status,

and Custom Object item types.

In the Names field, select or search for

the specific items you want to filter by (for

example, the trigger named "Notify assignee of

comment update").

Click Apply filters.

You can export a CSV formatted copy of the audit log. If you filter the

list before starting the export, the CSV file is also filtered this

way. The exported copy is emailed to your primary Zendesk email

To export a copy of the audit log

Filter the audit

Click Email CSV.

Powered by Zendesk

この結果について

確認状況
未確認(自動判定)
資料の取得日
2026-10-04
判定日
2026-10-04
判定モデル
TypeSafe Jev(jev-1.13.0)。公式資料の原文から各項目の記載を読み取り、判定の木はプログラムで計算しています。