Update: New Security Admin Role

Update: New Security Admin Role

Hello Zoho Directory Admins!

This post is to highlight the recent role and permission changes introduced as part of the security enhancements.

Previously, Helpdesk Admins had the security permissions and were responsible for managing the security configurations in Zoho Directory. With the recent update, they will no longer be able to perform the security configurations. In short, the security permissions of Helpdesk Admin role will be removed, while all the other permissions remain unchanged.

Introducing the Security Admin Role

As part of the security enhancements, we are introducing a new admin role - Security Admin.
Security Admins are responsible for managing the organization's security configurations. They have permission to create, update, and manage the following:
  1. Conditional Access Policies
  2. Routing Policies
  3. Identity Providers
  4. Security Policies

Security Admin Permissions

The Security Admin role includes the following permissions:

Category
Permissions
Users

User Management:

View users | Edit users | Reset password | Manage MFA | Generate backup codes

User Email:
View user emails | Edit user emails | Delete user emails
Groups

Group Management:

View groups | Edit groups | Add groups | Delete groups

Group Members:
View group members | Edit group role | Add users to group | Remove users from group
Security

Conditional Access Policies:

Add conditional access policies | View conditional access policies | Edit conditional access policies | Delete conditional access policies

Routing Policies:

Add routing policies | View routing policies | Edit routing policies | Delete routing policies

Security Policies:

Add security policies | View security policies| Edit security policies | Delete security policies  

Identity Providers:
Add IdP | View IdP | Edit IdP | Delete IdP

Helpdesk Admin Migration

Existing Helpdesk Admins who have permissions to manage security configurations (such as MFA and Allowed IPs) will be migrated to the new Security Admin role upon migrating to the new policies.

If you are still using the older Security Policies, these changes will not affect your current Helpdesk Admin role and their permissions will remain unchanged.

To learn more about the new policies and the migration process, click here.

Regards,
Zoho Directory Team