ツール一覧 › Zendesk
Zendesk のアクセス管理機能(SSO・MFA・IP制限・監査ログ)
公式資料によると、Zendesk は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-04)
判定(かんたん基準)
Step1:MFA(0.92) / SSO(1.00) + 監査ログ(1.00)|許可 最終|許可
かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。
項目ごとの読み取り
| 項目 | 公式資料の記載 | 確率 | 根拠 |
|---|---|---|---|
| MFA | 対応と記載 | 0.92 | Managing two-factor authentication |
| SSO | 対応と記載 | 1.00 | Setting up SAML single sign-on with Okta |
| 2FA | 対応と記載 | 1.00 | Managing two-factor authentication |
| IP制限 | 対応と記載 | 1.00 | Restricting access to Zendesk using IP restrictions |
| 監査ログ | 対応と記載 | 1.00 | Viewing the audit log for changes to your account |
「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。
根拠(公式資料の原文)
SSO:Setting up SAML single sign-on with Okta – Zendesk help
https://support.zendesk.com/hc/en-us/articles/4408821683738-Setting-up-SAML-single-sign-on-with-Okta
Setting up SAML single sign-on with Okta – Zendesk help
What's my plan?
Team, Growth, Professional, Enterprise, or Enterprise Plus
続きを読む(ほか 61 段落)
Team, Professional, or Enterprise
Verified AI summary ◀▼
Set up SAML single sign-on with Okta to streamline user authentication. Start by configuring SAML in Okta, then use the provided SAML SSO URL, Remote logout URL, and Certificate fingerprint to complete the setup. Assign SSO to users and manage authentication methods. Note: Switching from third-party SSO to native authentication requires users to reset their passwords.
Location: Admin Center > Account > Security > Single
Note: The tools described in this article were developed by a third
party. Zendesk doesn't support the tools or guarantee results. For more information, see the
Okta documentation.
Okta supports single sign-on with Zendesk using SAML (Security Assertion Markup Language).
For many of the settings used to configure single sign-on in Okta, you'll find much more
detailed information in the Okta user interface. For more about Single sign-on using SAML
support in Zendesk, see Enabling SAML single sign-on.
Configuring SAML must be done in both in your Okta account and in Zendesk. You start in Okta
first and get the SAML information you'll need to complete the configuration in Zendesk.
This article includes the following topics:
Configuring SAML in Okta
Configuring SAML in Zendesk
Assign users to SAML single sign-on with Okta
Switching authentication methods
Sign in to Okta as an administrator and then follow the steps below.
To configure SAML for Zendesk in Okta
In Okta, from the drop-down list in the upper-right corner, make sure you are using
the Classic UI interface (not the Developer
Select Add Applications from the dashboard.
Click Add Application, then search for and choose Zendesk. The Add
Zendesk wizard appears.
On the first screen, General Settings, add a name for the application and your
Zendesk subdomain. For example, if your Zendesk URL is mycompany.zendesk.com,
enter mycompany). Click Next.
On the second screen, Sign-On Options, select SAML 2.0. This is where
you'll find the SAML SSO URL, the Remote logout URL, and the
Certificate fingerprint (SHA2). You need this information to complete the SAML
setup in Zendesk.
Click the SAML 2.0 setup instructions for Zendesk link.
A page appears with
instructions on how to configure SAML in Zendesk. See Configuring SAML in Zendesk below for the latest
Copy the SAML SSO URL, the Remote logout URL, and the Certificate
You need this information to configure SAML in Zendesk. When
you've finished copying, close this window and return to your Okta dashboard.
(Optional) If you enable User Management, you'll be able to import users from
Zendesk into your Okta account, provision new Zendesk accounts from Okta, and push Okta
user profile updates and passwords to Zendesk.
You'll find information about these
Okta features in your Okta account and documentation.
(Optional) People allows you to select who in your Okta account has access to
Zendesk. This step is not covered in this article. You'll find information about these
When you've completed each step, click Next to complete and close the Zendesk
configuration in Okta.
When your Zendesk for Okta setup is complete and the information you need for setting up
SAML in Zendesk is available, sign in to your Zendesk account as an admin and enable SAML single sign-on. You'll need the SAML SSO URL,
the Remote logout URL, and the Certificate fingerprint from Okta to complete
Note: When you enable single sign-on via SAML or JWT, be aware that passwords do not expire
even if your Zendesk password policy is set to high because passwords are not stored in
Zendesk. Additionally, if agents manually add a Zendesk password to their account, these
passwords will not expire.
After configuring SAML single sign-on with Okta, assign this SSO option to end users, staff
members (agents and administrators), or both. For more information, see Assigning SAML SSO to users.
Important: If you use a third-party SSO method to create and authenticate users in
Zendesk, then switch to Zendesk authentication, these users will not have a password
available for login. To gain access, ask these users to reset their passwords from the
Zendesk sign in page.
Powered by Zendesk
MFA:Managing two-factor authentication – Zendesk help
https://support.zendesk.com/hc/en-us/articles/4408826974874-Managing-two-factor-authentication
Managing two-factor authentication – Zendesk help
Two-factor authentication is an added security layer that requires users to verify their identity after signing in using a passcode, reducing the risk of unauthorized access. You can require two-factor authentication, or each user can set up two-factor authentication for their own use.
Two-factor authentication adds another sign-in check to protect admin, agent, and end user accounts from unauthorized access. You can require 2FA, let users turn it on themselves, track usage with a 2FA status report, and help locked-out users regain access with recovery codes or profile updates. It works with email, authenticator app, or SMS for supported users.
続きを読む(ほか 51 段落)
Location: Admin Center > Account > Security >
using Google authentication.
Zendesk recommends turning on two-factor authentication to help protect against
potential situations that could result in an admin or agent account being
Set up two-factor authentication for the user so they
can sign back in again.
For example, select a new
method to receive recovery codes, such as an
authenticator app, or change the email address to
where codes can be sent. See Turning on
two-factor authentication.
Instruct the end user to sign in to Zendesk using the
authentication is optional
After you're signed in as the user, turn off two-factor
authentication.
Instruct the end user to sign in to Zendesk, where they
can optionally turn two-factor
authentication back on and set it up again.
The user will receive a new set of recovery
You can require two-factor authentication for all team members, all end users, or both user
types. Once this setting is turned on, users will be required to set
up two-factor authentication the next time they sign in. Users see
the following dialog after entering their email and password.
The two-factor authentication wizard guides users through the process,
which includes options for how they'd like to receive a passcode:
authenticator app, email, or SMS.
You can optionally notify users of the change and include a link to an
article for more information about two-factor authentication:
For admins and agents: Using two-factor authentication
to sign in to Zendesk Support
For end users: Accessing help
center with two-factor authentication
When you require two-factor authentication, users are prompted for a
passcode every time they sign in.
To require two-factor authentication
In Admin Center, click
Account in the sidebar, then select Security > Advanced.
Click the Authentication tab.
Select the options that apply:
Require two-factor authentication (2FA) for
You can generate a 2FA status report, in the form of a CSV spreadsheet, listing all the admins
and agents in your account and whether or not they're using
two-factor authentication. It's a good idea to do this periodically
if you require two-factor authentication. This option is not
available to track end users.
To generate a 2FA status report
Click Generate 2FA status report.
Check your Zendesk email. You should get an email shortly with a link to download the spreadsheet.
You can turn off two-factor authentication if you no longer want to
require it on your account. After you turn it off, users will no
longer be required to enter a passcode when signing in, unless they
2FA:Managing two-factor authentication – Zendesk help
https://support.zendesk.com/hc/en-us/articles/4408826974874-Managing-two-factor-authentication
Managing two-factor authentication – Zendesk help
Two-factor authentication is an added security layer that requires users to verify their identity after signing in using a passcode, reducing the risk of unauthorized access. You can require two-factor authentication, or each user can set up two-factor authentication for their own use.
Two-factor authentication adds another sign-in check to protect admin, agent, and end user accounts from unauthorized access. You can require 2FA, let users turn it on themselves, track usage with a 2FA status report, and help locked-out users regain access with recovery codes or profile updates. It works with email, authenticator app, or SMS for supported users.
続きを読む(ほか 106 段落)
Two-factor authentication is an added security layer that requires users to verify their identity
after signing in using a passcode, reducing the risk of unauthorized access.
You can require two-factor authentication, or each user can set up
two-factor authentication for their own use.
Two-factor authentication applies to users who sign in to your Zendesk using Zendesk
authentication (email and password). It's not available for users who sign
in using third-party authentication, such as Google authentication services,
JWT, or SAML. However, these users might still be able to use third-party
two-factor authentication, such as Google 2-Step Verification, if you're
using Google authentication.
Zendesk recommends turning on two-factor authentication to help protect against
potential situations that could result in an admin or agent account being
compromised, such as a leaked password. If you require two-factor
authentication, it's a good idea to periodically generate a 2FA status
report to track who's using two-factor authentication to access their
Zendesk account.
This article covers the following topics:
Important considerations before turning on two-factor authentication
Helping users regain access to their accounts
Requiring two-factor authentication on the account
Tracking who's using two-factor authentication
Turning off two-factor authentication
Before turning on two-factor authentication, make sure you understand the
following important considerations:
On trial accounts, agents can’t receive passcodes by
text message. If you’re turning on two-factor
authentication for a trial account, agents must use
email or an authenticator app to get their codes.
(Text message delivery isn’t supported for end users
to receive passcodes on any account type.)
You can use two-factor authentication on the Zendesk
website or with the Zendesk iOS or Android apps.
However, the Zendesk REST API doesn't currently
support two-factor authentication. See Using the API when SSO or
two-factor authentication is enabled in the
developer documentation.
Requiring two-factor authentication does not impact API
calls that are using an API token.
Team members can use one of their recovery codes to regain access
to their account. Recovery codes are displayed once to the
team member when they initially set up two-factor
account depends on whether two-factor authentication is
required on the account or optional and the end user enabled
sign in as an end user.
To help an end user regain access to Zendesk when two-factor
authentication is required
Assume (sign in as)
Click the profile icon on the upper-right side of any
help center page, then click Profile to
display the user's profile.
Click Manage 2FA.
Set up two-factor authentication for the user so they
can sign back in again.
For example, select a new
method to receive recovery codes, such as an
authenticator app, or change the email address to
where codes can be sent. See Turning on
two-factor authentication.
Instruct the end user to sign in to Zendesk using the
authentication is optional
After you're signed in as the user, turn off two-factor
authentication.
Instruct the end user to sign in to Zendesk, where they
can optionally turn two-factor
authentication back on and set it up again.
The user will receive a new set of recovery
You can require two-factor authentication for all team members, all end users, or both user
types. Once this setting is turned on, users will be required to set
up two-factor authentication the next time they sign in. Users see
the following dialog after entering their email and password.
The two-factor authentication wizard guides users through the process,
which includes options for how they'd like to receive a passcode:
authenticator app, email, or SMS.
You can optionally notify users of the change and include a link to an
article for more information about two-factor authentication:
For admins and agents: Using two-factor authentication
to sign in to Zendesk Support
For end users: Accessing help
center with two-factor authentication
When you require two-factor authentication, users are prompted for a
passcode every time they sign in.
To require two-factor authentication
In Admin Center, click
Account in the sidebar, then select Security > Advanced.
Click the Authentication tab.
Select the options that apply:
Require two-factor authentication (2FA) for
You can generate a 2FA status report, in the form of a CSV spreadsheet, listing all the admins
and agents in your account and whether or not they're using
two-factor authentication. It's a good idea to do this periodically
if you require two-factor authentication. This option is not
available to track end users.
To generate a 2FA status report
Click Generate 2FA status report.
Check your Zendesk email. You should get an email shortly with a link to download the spreadsheet.
You can turn off two-factor authentication if you no longer want to
require it on your account. After you turn it off, users will no
longer be required to enter a passcode when signing in, unless they
have turned on two-factor authentication for themselves in their
If you turned off two-factor authentication but users are still being
prompted for a passcode, users can refer to the following resources
to turn it off:
For agents: Turning off
two-factor authentication
For end users: Turning off
To turn off two-factor authentication
IP制限:Restricting access to Zendesk using IP restrictions
Restricting access to Zendesk using IP restrictions – Zendesk help
You can restrict access to Zendesk to users within a specified IP address range. You can also restrict access to users with specific IP addresses. This means that any attempt to make API calls, sign in, or access pages in any Zendesk product will fail from outside your allowed IP addresses. For example, to restrict access to users in your company, only allow access from your company's IP addresses.
Team, Professional, or Enterprise
続きを読む(ほか 41 段落)
You can restrict access to your account by allowing only specific IP addresses or ranges, blocking sign-ins, API calls, and page access from outside these IPs. Customers can be allowed to bypass restrictions while agents and admins cannot. Be sure to include all external IPs for integrations. Some undocumented endpoints remain accessible regardless of restrictions, so review their security implications carefully.
Location: Admin Center > Account > Security >
You can restrict access to Zendesk to users within a specified IP address range. You can
also restrict access to users with specific IP addresses. This means that any attempt to
make API calls, sign in, or access pages in any Zendesk product will fail from outside
your allowed IP addresses. For example, to restrict access to users in your company,
only allow access from your company's IP addresses.
You can also allow customers (but not agents and administrators) to bypass IP
restrictions. IP restrictions you manage in Admin Center apply to all Zendesk products
and Zendesk mobile applications. The restrictions may also affect how other products,
such as Gmail attachments, work.
Note: Enabling IP-based access restrictions can break third-party
integrations. Be sure to include all external IPs that need access to your account
via the Zendesk API.
To set IP restrictions
In Admin Center, click
Account in the sidebar, then select Security > Advanced.
Click the IP Restrictions tab.
Select Enable IP restrictions, then enter the Allowed IP Ranges,
which can include ranges or individual IP addresses.
When specifying IP
addresses, separate each address or range with a space.
are available to specify a range:
Use asterisk (*) wildcards. An IP address consists of four numbers
separated by periods, such as 192.168.0.1. You can substitute
a single asterisk character (*) for any number group to let Zendesk
know that it should accept any value in that space. For example,
192.*.*.* allows any IP address whose first number is
Use IP subnet mask syntax. For
example, 192.168.1.0/25 specifies all the IP addresses
You can't specify IP ranges where the CIDR (Classless
10.0.0.0/0, the /0 is invalid.
option ensures that your customers can access your help center and messaging
allowed IP addresses.
address restrictions.
(Optional) If your implementation involves any third-party services, such as
the IP restrictions in place. Review these endpoints carefully and consider any
These endpoints are considered unsupported. Zendesk is not responsible for any
/api/v2/pcm/campaign_analytics
Public access to this messaging analytics endpoint is required
/api/v2/pcm/campaign_list
監査ログ:Viewing the audit log for changes to your account
Viewing the audit log for changes to your account – Zendesk help
The audit log allows customers on Enterprise plans and above to view various changes in their Zendesk account since the account was created. It saves a record of these changes indefinitely, and you can view the entire change history.
What's my plan?
続きを読む(ほか 90 段落)
Enterprise or Enterprise Plus
Verified AI summary ◀▼
Access the audit log to track changes made by admins and agents to your account. View detailed entries, including time, actor, and activity type. Use filters to find specific events and export the log as a CSV file. This feature helps you monitor account modifications and maintain a clear record of activities.
Location: Admin Center > Account > Logs > Audit log
The audit log allows customers on Enterprise plans and above to view various
changes in their Zendesk account since the account was created. It saves a
record of these changes indefinitely, and you can view the entire change
Admins and agents with permission can
view the audit log in Admin
Center or through the Support API.
This article contains the following sections:
About the audit log changes
Viewing the audit log in Admin Center
Filtering the audit log
Exporting the audit log
There are two key things to understand about the audit log: the types of changes
captured and the details provided for each log
Changes captured in the audit log
The audit log tracks changes that agents and admins have made to
your Zendesk account. End user activities are not
The audit log shows changes to the following areas:
Account information and settings
Users (updates to existing users only; activities
related to creating new users are not captured)
Ticket settings
Audit log entries
For each entry in the audit log, the following information is
Time and date the event occurred
User or system that caused the event
changes are performed through automated system
processes and appear as actions by the system user
IP address of the user who caused the
Object changed by the actor
Type of action for the event (Created,
Updated, Deleted, Exported, or Signed in)
Details about the event
In Admin Center, audit log timestamps appear in your account's time
zone. If you are unsure what time the audit
log is using, hover over the information icon in the
Time column heading.
In the Zendesk API and CSV export file, audit log timestamps
appear in Coordinated Universal Time (UTC).
From the Audit log page in Admin Center, you can view the audit log as a
whole, sort the log by time, filter the list, or export a copy of
To view the audit log
In Admin Center, click
Account in the sidebar, then select Logs > Audit log.
Often, only part of the picture is available when you visit the audit
log. For example, you might know when something changed (but not
what) or who changed something (but not when). Since the audit log
can include a large volume of events, filtering makes it easier to
find what you’re looking for.
While top audit events are available as filters, not all event types can
be filtered. Additional audit events will be added over time.
Tip: If you repeat the same audit log
filters, bookmark them in your web browser after you apply them. The
filter displays in the URL.
To filter the audit log
Click the Time column to sort the entries by date.
To use more filters, click Filter.
Additional filters
appear in a side drawer.
To find entries within a specific date range, enter a Start
date and End date.
Enter a name in the Actor field to filter by the
people or systems responsible for the
Select an Activity type to filter entries by the action
type (Created, Updated, Deleted, Exported, or Signed
Use the filters in the Item section to filter by a specific
setting, user, or business rule that has changed.
In the Type field, select or search for
the generic item type you want to filter by (for
example, "trigger").
An initial list of item
types appears in the dropdown, but you can start
typing to access more. For example, typing
cus displays the Customer, Custom Status,
and Custom Object item types.
In the Names field, select or search for
the specific items you want to filter by (for
example, the trigger named "Notify assignee of
comment update").
Click Apply filters.
You can export a CSV formatted copy of the audit log. If you filter the
list before starting the export, the CSV file is also filtered this
way. The exported copy is emailed to your primary Zendesk email
To export a copy of the audit log
Filter the audit
Click Email CSV.
Powered by Zendesk