Hello Zammad Community,
We are currently using Zammad as a Managed Service Provider (MSP) to manage support tickets for our external customers. Our internal technical support team (agents and administrators) handles these tickets, while our external customers need to be able to access the portal to create and track their requests.
For compliance and security reasons, we want to enforce mandatory Single Sign-On (SSO) authentication for our internal staff using Microsoft 365 / Microsoft Entra ID. However, we cannot enforce this globally across our entire instance because our external customers do not belong to our Microsoft tenant and must continue to use standard local authentication (or other non-SSO methods).
According to our support ticket #10234921 and the official Zammad documentation:
-
Zammad supports Microsoft authentication: Microsoft — Zammad Admin Documentation documentation
-
Zammad supports Microsoft Entra ID SAML authentication: SAML with Microsoft 365 — Zammad Admin Documentation documentation
-
Zammad offers various SSO options: Single Sign-On Options | Zammad Features
Currently, the ability to enforce SSO is a global option that applies to all users (customers, agents, and admins alike). There is no way to restrict or enforce SSO based on specific user roles.
The Use Case & The Problem:
-
For Agents/Admins: Mandatory SSO is a strict security requirement to secure our internal helpdesk operations.
-
For Customers: Forcing SSO globally blocks external customers from logging in, as they do not have accounts in our internal identity provider.
-
The Conflict: We are forced to keep SSO optional for everyone, allowing agents to still log in using “classic” authentication, which leaves a security gap.
Proposed Feature:
We would like to request the ability to enforce SSO configuration per role . Specifically, we need a setting that allows us to make SSO mandatory for “Admin” and “Agent” roles, while leaving local password logins active and available for the “Customer” role.
This would greatly improve security for MSPs and companies hosting public-facing support desks who must protect internal credentials while maintaining accessibility for external clients.
Thank you for considering this request!
Best regards,