Slack Administration: 6 Settings That Will Save Your IT Team Hours Every Month
A well-administered Slack workspace runs on rules instead of reminders: new hires land in the right channels on day one, only approved apps touch company messages, and every email sign-in is protected by a second factor. Six admin settings do most of that work:
- Enforce two-factor authentication and require approval for new invitations
- Require approved apps and decide who can create, archive and delete channels
- Set default channels and a retention policy that matches your obligations
Every setting below is available on all Slack plans and works identically at 5 people and at 120, so the right time to configure them is day one.
Prerequisites
- The Workspace Owner role. Owners can change every setting here; Workspace Admins can manage invitations and default channels only
- Slack on desktop or in a browser, where the Admin menu appears in the sidebar
- A short heads-up to your team before enforcing two-factor authentication
The paths below are for Free, Pro and Business+ plans. Enterprise plans manage several of these settings at the organization level.
Step 1: Enforce Two-Factor Authentication
- Click Admin in the sidebar, then select Workspace settings.
- Click Security.
- Next to Two-factor authentication for email sign-in, click Edit.
- Check Require members to have 2FA set up. Select Authenticator apps only to rule out text message codes.
- Click Save.
Members who have not set up 2FA within 24 hours are signed out and prompted to set it up before signing in again. This setting covers email sign-in; if your team signs in through SSO, second-factor enforcement lives in your identity provider.
Step 2: Require Admin Approval for Invitations
- Click Admin → Workspace settings.
- Click the Permissions tab.
- Next to Invitations, click Expand.
- Check Require admin approval.
- Choose whether requests go to all admins or to a specific channel, then click Save.
Routing requests to one channel, such as #it-requests, gives IT a single approval queue and ties every new account to a real hire or contractor.
Step 3: Require Approved Apps
- Click Admin → Apps and workflows.
- Click App Management Settings in the left sidebar.
- Next to Require approved apps, click Edit.
- Check Only allow pre-approved apps, then click Save.
Members can still request the apps they need. Each request arrives as a reviewable item instead of an unreviewed install with access to company messages.
Step 4: Decide Who Can Create, Archive and Delete Channels
- Click Admin → Workspace settings → Roles & permissions.
- On the Account types page, click the three dots icon next to the permission to adjust, such as Create public channels, Archive channels or Delete channels.
- Select Edit permission, choose the roles allowed to take that action, and click Save.
A common pattern keeps channel creation open to members and limits deletion to Owners and Admins. Archived channels stay searchable; deleted channels do not.
Step 5: Set Default Channels for New Members
- Click Admin → Workspace settings.
- Next to Default Channels, click Expand.
- Add the public channels every new member should join, such as #announcements and #it-help.
- Click Save.
Only public channels can be defaults, and every member joins #general automatically. Defaults apply to new members going forward, and guests are not added.
Step 6: Set Message and File Retention
- Click Admin → Workspace settings.
- Next to Data retention, click Expand, choose a setting from the dropdown, and click Save twice to confirm.
- Next to File history, click Expand, choose a setting, then click Save and Confirm Settings.
Paid plans can keep all messages, keep messages without edit history, or delete on a schedule with Choose custom timeline. Match the setting to your legal, compliance and customer contract requirements, and document it alongside your other security policies.
Verify
- Open Admin → Workspace settings → Security and confirm Require members to have 2FA set up is checked
- Send a test invitation from a member account and confirm it lands in your approval channel
- Try to add an unapproved app from a member account and confirm Slack routes it as a request
- Invite a test user and confirm they join every default channel
Troubleshooting
- A member was signed out after 2FA enforcement. They had not set up 2FA within 24 hours. They can complete setup at the sign-in prompt and continue.
- A setting described here is missing or locked. On Enterprise plans, organization-level settings for 2FA, apps and permissions override workspace settings. Change them in the organization settings instead.
ScaleIt configures and runs Slack administration as part of managed IT support for startups and SMBs, with every setting on this list in place from day one. Book a free call and we will review your workspace against this checklist.
Verified against Slack Help Center documentation on 2026-09-21. Vendor docs: https://slack.com/help/articles/212221668-Mandatory-workspace-two-factor-authentication-, https://slack.com/help/articles/115004854783-Require-admin-approval-for-workspace-invitations, https://slack.com/help/articles/222386767-Manage-app-approval-for-your-workspace, https://slack.com/help/articles/115004988303-Adjust-channel-management-permissions, https://slack.com/help/articles/201898998-Set-default-channels-for-new-members, https://slack.com/help/articles/203457187-Customize-data-retention-in-Slack.