Mandatory Attachment Security Changes | The place for Zendesk users to come together and share
Skip to main content
March 19, 2026
Delivered

Mandatory Attachment Security Changes

Related products:Support
  • March 19, 2026
  • 7 replies
  • 129 views

Regarding: https://support.zendesk.com/hc/en-us/articles/10223024943770-Announcing-end-user-private-attachments-for-Zendesk-Support 

I appreciate the intention behind strengthening security across the platform however  I wanted to provide feedback that may be helpful as this change moves toward enforcement.
 

When a security enhancement becomes mandatory with no opt‑out or alternative configuration path, it can create challenges for organisations whose workflows, policies, technical environments, or customer‑facing models don’t align with a single enforced approach. Even when the goal is improved protection, removing flexibility can unintentionally introduce friction, disrupt established processes, or limit the ability for teams to manage risk in ways that suit their operational reality.
 

Please consider offering opt‑out functionality -  even if temporary, conditional, or time‑limited. 

7 replies

Jacob20
Community Expert
April 8, 2026

I agree completely! 

We don’t have a customer facing KB, with this setting enabled, end users clicking on an attachment from an email thread, will be lead to our KB and prompted to log in. This is not a good customer experience.

The only recourse I can think of at the moment, is to change our comment placeholders in notification triggers to only send the current comment, and not the whole thread. This sacrifices context for no gain what so ever.

We should be able to opt out here.

Newcomer
April 21, 2026

Hmm. This is going to be tricky with embedded attachments/images in emails because it can’t authenticate, for agents and end-users alike.

Jacob20
Community Expert
April 22, 2026

I feel like the security goal can be achieved further upstream without introducing the bad customer experience currently proposed.
If end user attachments are just scrubbed from the email comment threads, this should be a closed issue as far as I can see.

Newcomer
April 23, 2026

We have automations that generate descriptions of attachments using AI. It was trivial before to simply send the content URLs to something like the OpenAI API. This change vastly complicates that workflow. I’m also annoyed at the lack of information about how to access private attachments programatically; it turns out adding an Authorization header works but I had to discover this through testing. I wish there was an easier way to secure the attachment while keeping the URL portable, similar to a presigned S3 URL.

Shawna James
Community Manager
July 28, 2026
Updated idea statusFeedback submittedUnder review
Chika Chima
Product Manager
August 6, 2026

Hi everyone,

Thank you for taking the time to share such thoughtful and detailed feedback. You’ve highlighted a critical principle: robust security should protect your operations, not disrupt the workflows and productivity your teams rely on every day.

Listening to your feedback made it clear that enforcing a single, mandatory approach without configuration options created friction for many. Because of this, we have officially canceled the planned security enforcement.

What’s Next? We agree that security and usability must go hand in hand. Instead of forcing a rigid requirement, we have shifted our focus toward a One-Time Passcode (OTP) approach for attachment access.

Our goal with this discovery effort is to:

  • Maintain security: Ensure both agent and end-user attachments remain safe and protected.

  • Minimize friction: Allow easy access to attachments without breaking established processes or a need of a help center/Guide activated

  • Support diverse workflows: Give teams the flexibility needed to fit their specific operational environments.

We are currently evaluating the technical details and user experience for the OTP feature. 

Thank you again for candidly sharing your needs—it directly shaped this decision and is helping us build a better product experience for everyone

Chika Chima
Product Manager
August 6, 2026
Updated idea statusUnder reviewDelivered