How Do You Configure Security Controls in ManageEngine ServiceDesk Plus? - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How Do You Configure Security Controls in ManageEngine ServiceDesk Plus?

Quick Summary

  • Goal: Lock down your service desk so only the right people reach the right data, and so you can prove it.
  • Core controls: Role-based access, password policy, two-factor authentication, single sign-on, session and lockout settings, encryption, file attachment protection, and audit trails.
  • Main location: Most settings live under Admin > General > Security Settings, with related options under Two Factor Authentication and Users & Permission.
  • Fast check: Use the Security Meter to see how many built-in controls you have enabled.
  • Time needed: Plan one to two hours for a baseline, plus time for SSO or directory integration.
  • Note: Menu names differ slightly between cloud and on-premises editions and between releases, so confirm them in ManageEngine’s current help guide.

What Is ManageEngine ServiceDesk Plus and Why Do Its Security Controls Matter?

ManageEngine ServiceDesk Plus – ITSM Software is an IT service management platform that handles incidents, requests, changes, assets, and projects in one place. Because it stores employee details, device data, approvals, and sometimes credentials mentioned in tickets, attackers view it as a valuable target. This article shows you how to configure its built-in security controls step by step.

Which protections does the platform provide?

ManageEngine’s security documentation describes bcrypt password storage, Active Directory and LDAP authentication, SAML 2.0 single sign-on, and enforced password resets for local accounts. Third-party security summaries also list AES-256 encryption for sensitive data, HTTPS for transmission, account lockout thresholds, inactive session timeouts, and antivirus scanning for file uploads. Availability varies by edition and version, so verify each feature against your build.

Why should you configure them deliberately?

Many controls ship disabled or set to permissive defaults. For instance, ManageEngine’s help guide states that the password policy is disabled by default and that concurrent login stays enabled by default. Therefore, a fresh installation needs hardening before real users arrive.


What Should You Review Before You Change Security Settings?

Careful preparation prevents lockouts and user frustration. Spend a few minutes on the checklist below.

Which preparation steps matter most?

  1. Back up your configuration. Take a database backup before you change authentication settings.
  2. Keep an emergency admin account. Store a local administrator login securely, in case SSO or two-factor authentication fails.
  3. Inventory your user types. List technicians, requesters, approvers, and external contacts.
  4. Check your identity provider. Note whether you use Active Directory, LDAP, or a SAML provider.
  5. Notify your users. Announce changes before you enforce them.

Which decisions should you make first?

DecisionOptions
Authentication sourceLocal accounts, Active Directory/LDAP, or SAML SSO
Password rulesLength, complexity, and expiry
Second factorAuthenticator app, email, or your SSO provider’s method
Session limitsTimeout length and concurrent login rules
Audit needsWhich actions you must log and review

How Do You Configure Roles and Permissions in ServiceDesk Plus?

Access control forms the foundation. Even strong passwords fail if every technician can delete records or change settings.

How does the least-privilege approach work?

Give each person only the permissions their job requires. Create roles that match real responsibilities, and assign users to those roles instead of granting rights one by one. ManageEngine’s admin guide describes roles that control access to modules such as requests, assets, purchase, contracts, and administration.

Which roles should you create?

RoleTypical access
Service desk technicianCreate and update requests, view related assets
Senior technicianManage problems and changes, edit assets
Asset managerFull access to assets, purchases, and contracts
ApproverView and approve requests and changes
AdministratorConfiguration and security settings
Read-only auditorView records and reports only

How should you manage admin rights?

Limit administrator roles to a small group. Furthermore, review role assignments every quarter, and remove access immediately when someone leaves or changes teams. Tie this review to your HR offboarding process.


How Do You Set Up a Strong Password Policy?

If you use local authentication, the password policy protects accounts directly. ManageEngine places it under Admin > General > Security Settings > Password Policy.

What options does the password policy include?

According to ManageEngine’s help guide, you can enable the policy and set a minimum password length between 8 and 99 characters. You can also require specific character types and set an expiry period. In addition, the option to force a password reset at first login makes new users replace the initial password immediately.

What settings should you choose?

SettingRecommended starting point
Minimum length12 characters or more
Character typesMix of upper case, lower case, numbers, and symbols
ExpiryFollow your organization’s policy, or rely on strong passwords plus 2FA
Force reset at first loginEnabled
Password reuseBlock recent passwords where the option exists

Does the policy apply to directory accounts?

The password policy covers local authentication passwords. If you authenticate through Active Directory or LDAP, your directory rules govern those passwords instead. Consequently, keep both policies aligned.


How Do You Enable Two-Factor Authentication?

Two-factor authentication (2FA) blocks most password-based attacks, so prioritize it for technicians and administrators.

Where do you turn it on?

ManageEngine’s help guide places the configuration under Admin > General Settings > Two Factor Authentication (for non-ESM setups). First choose your preferred authentication method, then enable 2FA for user logins. Users enroll during their first login after you enable the feature.

Which additional 2FA options help?

  • 2FA for admin configurations. Require administrators to re-authenticate before they change security settings, password policy, or advanced portal settings.
  • TFA Trust. Set a time window in which admins can change settings without repeated prompts.
  • Approval actions. Add 2FA to sensitive approvals through the portal-specific settings, where your version supports it.
  • Enrolled users. Review who has enrolled, and reset devices for users who lose phones.

What rollout plan works best?

Start with administrators and technicians. Next, extend 2FA to approvers and finally to all requesters if your risk profile demands it. Give users clear enrollment instructions and a support contact.


How Do You Configure SAML Single Sign-On and Directory Integration?

Single sign-on (SSO) centralizes authentication with your identity provider, which gives you stronger policies and easier offboarding.

How do you set up SAML SSO?

ServiceDesk Plus supports SAML 2.0 and places the configuration under Admin > Users & Permission > SAML Single Sign On. Follow this outline:

  1. Log in as an administrator.
  2. Open the SAML configuration page, and copy the service provider details, such as the ACS URL and entity ID.
  3. Create the application in your identity provider, and paste those details.
  4. Return to ServiceDesk Plus, and enter the identity provider’s login URL, logout URL, and certificate details.
  5. Map the login attribute, commonly the email address, to match your user records.
  6. Test with a pilot user before you roll it out.

What should you know about login names?

If the identity provider sends a login name that does not match an existing user, ServiceDesk Plus may reject the login or create a new user when dynamic user addition is on. Therefore, align email addresses and login names before launch.

Can you force SSO-only login?

Yes. ManageEngine’s SSO guides mention a “Collapse the login form by default” option that hides the local login form and steers users toward SAML. Keep your emergency admin route documented, in case the identity provider goes down.


How Do You Harden Session, Login, and Lockout Settings?

Session controls limit the damage from stolen credentials and unattended screens. Configure them under Admin > General > Security Settings.

Which settings deserve attention?

SettingPurposeSuggested action
Concurrent loginControls simultaneous sessions from different IP addressesDisable it for technician accounts if your workflow allows
Session timeoutEnds idle sessionsSet a reasonable idle limit
Account lockoutStops brute-force guessingEnable a threshold and a lockout duration
Login domain dropdownControls domain selection at loginDisable if you use a single domain
Security MeterScores your configurationReview it after each change

How does the Security Meter help?

ManageEngine describes the Security Meter as a tool that gauges how effectively you have configured the built-in security features, and it shows a percentage score. Use it as a checklist, not as proof of security. Work through each recommendation, and note any you skip on purpose.

How do you test your changes?

Log in with a test technician account, leave the session idle, and confirm the timeout. Then trigger a lockout with wrong passwords, and confirm the recovery process. Testing prevents surprises on a busy Monday.


How Do You Protect Data, Attachments, and Communications?

Tickets often contain screenshots, logs, and documents with sensitive details. Protect them.

Which data protections should you enable?

  • HTTPS. Serve the application over HTTPS with a trusted certificate, and redirect HTTP traffic.
  • Attachment protection. ManageEngine’s security guide mentions an option to enable password protection for file attachments under Security Settings.
  • Antivirus scanning. Where your version supports it, scan uploads through an ICAP-compatible antivirus service.
  • Database encryption and backups. Use encrypted, password-protected backups and store them off the main server.
  • Least data in tickets. Train staff to avoid pasting passwords or personal data into tickets.

What network controls help?

Place the server behind a firewall, restrict administrative access by IP address or VPN, and expose only the ports you need. Additionally, keep the operating system, database, and ServiceDesk Plus build up to date, because vendors patch vulnerabilities regularly.


How Do You Monitor Activity With Audit Trails and Reports?

Security does not end after configuration. You must watch for problems and prove compliance.

What should you review regularly?

Review itemFrequency
Admin and role changesWeekly
Failed login and lockout eventsWeekly
New technician accountsMonthly
Inactive accountsMonthly
Security Meter scoreQuarterly
Backup restore testQuarterly

How do audit trails support investigations?

ManageEngine lists audit trails among its security features. They record who changed what and when, so you can trace mistakes and misuse. Export relevant logs to your central logging or SIEM tool if you run one.

What belongs in your incident plan?

Write down how you revoke access, reset credentials, and restore from backup if you suspect a compromise. Then test the plan once a year.


Conclusions: What Should You Remember About Security in ServiceDesk Plus?

Strong security comes from layers. ManageEngine ServiceDesk Plus – ITSM Software gives administrators a solid set of controls: role-based access, password policies, two-factor authentication, SAML SSO, session and lockout limits, attachment protection, and audit trails. However, the platform cannot protect you if you leave risky defaults in place.

To recap, prepare a backup and emergency account, design least-privilege roles, and enable a strong password policy. Then turn on two-factor authentication, connect SSO where you can, and harden sessions and lockout rules. Finally, protect data in transit and at rest, watch the audit trails, and review the Security Meter every quarter. Follow this routine, and your service desk will support your users without becoming your weakest link.


Frequently Asked Questions

Is the password policy enabled by default in ServiceDesk Plus?

No. ManageEngine’s help guide states that the password policy is disabled by default. Enable it under the security settings, choose a minimum length and complexity rules, and consider forcing a reset at first login. Remember that directory accounts follow your directory’s own password rules.

Can you require two-factor authentication only for administrators?

Yes. ServiceDesk Plus lets you enable 2FA for user logins and separately for admin configurations, such as security settings and password policy changes. Many teams start with administrators and technicians, then expand to other users. Check your version’s help guide for the exact options.

Should you use SSO or local accounts?

SSO usually works better because it centralizes authentication, supports stronger policies, and simplifies offboarding. Still, keep a protected local administrator account for emergencies. Also test SAML attribute mapping carefully, so login names match user records.


Recommended: