What's new: Today we're releasing two new security features related to Single-Sign-On (SSO) logins.

The first one: you can now completely disable the usual login method via user name and password. This will effectively force all users to use SSO.

The second feature is for accounts that have a mix of SSO and user/password user accounts, and that also want to enforce Two-Factor Authentication (2FA). 2FA is mostly for improving the security of user/password logins against the potential password leaks, but can be a burden for users using SSO to log in. However until now, if your organisation was enforcing the use of 2FA across the board, that would also apply to SSO users. You can now disable this and enforce 2FA only for non-SSO users.

The toggles to enable or disable these features are located under Settings, in the "Access Management" page under the "Account" heading. (This page is only accessible to users with administrative rights on the account.)

Who this applies to: All accounts that have SSO login methods enabled (Google, Microsoft 365, or custom).

Why it matters:

  • This enables some customers to be compliant with their internal security policies more easily.

  • When agents are offboarded, disabling their master account (on Google or Microsoft) will also automatically disable their access to the Gorgias helpdesk, avoiding the need to deactivate their access manually if they were not using SSO.

Refer to the updated documentation for details.