Admins can now configure certain security settings for an individual user, overriding the account-wide default for that person specifically. This article covers the user-level security settings currently available:
MFA Override at the User Level
Admins can also override MFA enforcement per individual user, regardless of the account level setting.
With this capability, an admin can configure a specific user to:
- Always require MFA for that user, regardless of the account-level setting.
- Never require MFA for that user (an exemption), regardless of the account-level setting.
Important — the user-level override always takes precedence:
Once an MFA override is set for a user, it always overrides the account-level MFA setting for that user — including if the account-level setting is changed later. For example, if a user is exempted from MFA and the admin subsequently enables (or disables) MFA enforcement for the whole account, that user's individual override still applies and is not affected by the account-level change. The override remains in effect until an admin explicitly changes or removes it for that user.
To set an MFA override for a user, follow these steps:
- [1]Navigate to Admin.
- [2]Open the Users app and select the user you want to configure
- [3]Go to the Security settings tab and click Edit.
- [4]Set the user's MFA override (Always require 2FA, or Do not require 2FA), and save.
Caveat — existing MFA configuration is not removed automatically:
If a user already has MFA configured (e.g., an Authenticator App or Security Key already set up) and an admin subsequently exempts that user from MFA, Talkdesk will still prompt the user for MFA at login. This happens because exempting a user from MFA only changes the enforcement rule going forward — it does not delete the MFA methods the user already configured.
For the user to stop being prompted for MFA, the admin must also reset the user's MFA (see the "Reset MFA per User" section below), in addition to setting the override, or the user himself can Disable their MFA at Profile > Security Settings.
Reset MFA per User
Administrators and users with the appropriate permissions can reset the MFA configuration for a specific user. This is useful when:
- A user has lost access to their authentication device and cannot log in, or
- A user has been exempted from MFA via the override above and should no longer be prompted for it.
To reset MFA for a specific user, follow these steps:
- [1]Navigate to Admin.
- [2]Open the Users app and select the user you want to configure
- [3]Go to the Security settings tab.
- [4]Click the Reset 2FA button.
Note: The "MFA Methods configured" section shows the authentication methods currently set up for the user. Clicking Reset MFA clears all configured methods for that user — the user will be prompted to set up MFA again from scratch the next time it's required at login (subject to their current override/enforcement setting).
Disable Automatic Logout (Inactivity Timeout) per User
Talkdesk has an account-level setting, Automatic User Logout, which — when enabled — automatically logs users out after a period of inactivity.
Admins can exempt an individual user from this automatic logout, so that specific user stays logged in even after the inactivity period elapses, while the setting continues to apply normally to everyone else.
Important — this exception only matters if the account-level setting is enabled:
The per-user exemption only has an effect when the account-level Automatic User Logout setting is Enabled. If Automatic User Logout is Disabled at the account level, no one is being logged out for inactivity in the first place, so there is nothing to exempt — setting an exception for a user has no practical effect in that case.
To exempt a user from automatic logout, follow these steps:
- [1]Navigate to Admin.
- [2]Open the Users app and select the user you want to configure
- [3]Go to the Security settings tab.
- [4]Click the Disable Automatic sing out button.