Outcome: By the end of this guide, you will have a production-oriented configuration and a repeatable test checklist.
1. Protect administrator accounts
Require MFA, review trusted devices and keep recovery codes offline.
2. Create least-privilege roles
Grant only the ticket, chat, analytics, integration or security permissions each role needs.
3. Set session and network policy
Choose idle and absolute session lifetimes, password requirements, allowed email domains and optional IP ranges.
4. Configure SSO safely
Test OpenID Connect before disabling password login. HelpoSoft blocks configurations that would remove the final login path.
5. Review security events
Export and inspect the tamper-evident event chain, failed logins, role changes and session revocations.