Zendesk is phasing out the old password levels for team members and introducing stricter requirements instead. The change will be rolled out between 17 August and 12 October 2026, affecting all accounts currently using the Low, Medium, or High levels. Here we explain what is happening, what you need to do, and what it means for those using SSO.
What is changing?
Zendesk is removing the older password levels Low, Medium, and High for team members. This applies to agents and administrators, not your end customers, who will continue with their current passwords as usual.
All accounts currently using one of these levels will be moved to the Recommended level. If you have not made the change yourself before 17 August 2026, the move will happen automatically.
If you are using a customised password policy (Custom), you will only be affected if one of the following applies:
- Minimum password length is set to less than 12 characters
- The setting allowing passwords resembling email addresses is enabled
If your customised policy already meets both requirements, nothing will happen, and no one on the team needs to change their password.
Why is Zendesk doing this?
The old levels allow shorter and weaker passwords than what is considered secure today, making accounts more vulnerable to intrusion attempts. The update is a way to ensure that all Zendesk accounts meet today’s security standards.
What are the requirements for the Recommended level?
A password that meets the Recommended level must:
- Be at least 12 characters long
- Contain both uppercase and lowercase letters
- Contain at least one digit
- Contain at least one special character, for example ! @ # %
- Not be an email address
- Have no connection to the account or person, such as subdomain, brand name, the person’s own name, or the part of the email address before the @
- Not appear in a known data breach
The account will be locked after five failed login attempts. Unlike the old levels, Recommended has no scheduled requirement to change passwords regularly; the one-off change occurring during this transition is an exception, not a new recurring requirement.
What do you need to do?
You have two options before 17 August 2026:
- Switch to Recommended yourself. The best option for most, and the one that keeps you aligned with Zendesk’s security updates going forward.
- Keep or set up a customised policy (Custom). Works well if your organisation has specific requirements, but be aware that future changes to your Custom settings may trigger new password changes for the team.
If you do nothing, the account will be automatically moved to Recommended, and all team members will be prompted to change their password at next login.
How to check if your account is affected:
- Go to Admin Center, then Account > Security > Team member authentication
- Check if password login (Zendesk authentication) is enabled for team members
- See which password level the account currently has
If it is Low, Medium, or High, you are affected. If it is already Recommended, you are done. If you use Custom, check the minimum length and the setting for email-like passwords according to the requirements above.
What happens, and when?
When an account’s turn comes in the rollout, three things happen in sequence:
- The policy is updated. The account is moved to Recommended, or the two Custom settings that are no longer sufficient are adjusted. No one is logged out and no password stops working at this stage.
- Five days later the passwords expire. Each team member receives two emails to their primary email address, one three days before the password expires and one on the day. Both link to the security settings.
- At next login the person changes their password. The account, permissions, and all data remain exactly as before; only the password itself needs to be renewed.
If someone is away from work when the rollout reaches the account, the change will wait until the person logs in again, which means individual password change prompts may appear even after 12 October.
| Date | What happens |
|---|---|
| 17 August 2026 | The rollout begins. The first accounts are moved to Recommended or have their Custom policy adjusted |
| 17 August–12 October 2026 | The remaining accounts are updated continuously, as the rollout reaches them |
| 12 October 2026 | The rollout is complete. All affected accounts have the new policy |
If you want to control the timing yourself, you can change the level in Admin Center now, but this will start the same five-day clock and the same password change as if Zendesk had done it for you.
Special note for those using SSO
Many believe that SSO means password login is disabled, but this is not always the case. On most SSO accounts, Zendesk’s normal login with email and password remains enabled in the background as a fallback if the SSO service stops working.
This means your team members most likely still have a Zendesk password, even if they never use it day to day. That password is subject to the policy just like any other and will expire and need to be renewed according to the same timeline.
How to determine if this applies to you:
Check under Admin Center > Account > Security > Team member authentication if Zendesk authentication is enabled. If it is, the update also applies to your SSO users.
Two ways forward:
- Leave it as is. The fallback password gives you a way in if the SSO service goes down, and the team will just receive a couple of extra emails and a password change they might not expect. Worth giving them a heads-up.
- Disable Zendesk authentication completely. Then SSO is the only way in, and no one on the team is affected by the password update. Bear in mind that you lose the fallback option if your identity provider experiences downtime.
Should you inform the team?
Yes. The emails about expiring passwords go directly to each team member, not to you as an administrator, so you will not receive a summary to forward. Two things are worth stating clearly to the team in advance:
- Everyone with a password set before this update will change it, even those who already have a long and strong password
- Those logging in via SSO may also be asked to change their password if Zendesk authentication is enabled in the background
Comments
0 comments
Please sign in to leave a comment.