Password Policy in Zoho Mail: Set password rules to keep your organization secure

Password Policy in Zoho Mail: Set password rules to keep your organization secure

Weak or repetitive passwords are one of the most common causes of unauthorized account access in organizations. Zoho Mail's Password Policy feature allows administrators to define and enforce specific password requirements for all users in the organization, ensuring that accounts are protected with strong and regularly updated passwords.

What is Password Policy in Zoho Mail? 

Password Policy is a configuration available in the Zoho Mail Admin Console. It allows administrators to define a set of rules that users must follow when creating or updating their passwords. From setting a minimum password length to enforcing periodic password expiry, every rule can be customized to align with your organization's security requirements.

How can administrators use Password Policy effectively in Zoho Mail Admin Console? 

Password Policy in Zoho Mail enables administrators to enforce consistent password standards across the organization. This ensures structured account security, reduces the risk of unauthorized access, and keeps user accounts protected at all times.

  • Minimum password length: Set the minimum number of characters required for a password. The default minimum length is 8 characters and cannot be set lower than 8.

  • Minimum number of passwords in history: Prevent users from reusing their previous passwords. For example, if this value is set to 3, users will not be able to reuse any of their last 3 passwords.

  • Minimum number of special characters: Require users to include a minimum number of special characters such as $, #, @, or ^ in their password. The recommended value is 1 or 2 special characters.

  • Minimum number of numeric characters: Require users to include a minimum number of numeric characters (0-9) in their password. The recommended value is 1 or 2 numeric characters.

  • Password expiry period: Set the number of days after which user passwords will automatically expire, prompting users to create a new password. The recommended expiry period is 30 to 45 days.

 Steps to configure Password Policy in Zoho Mail Admin Console 

  1. Login to Zoho Mail Admin Console.

  2. Navigate to Security and Compliance in the left pane.

  3. Click Security and go to Password Policy.

  4. On the Password Policy section, specify the values for the respective fields.

  5. You can also choose to send a password expiry notification to the users and remind them to change their passwords by checking the Send password expiry notification to users option.

  6. Once done, click Update.