Improved Security in SAML/OIDC Sign-in Redirection Flow
To enhance the security of our authentication system, we’ve made a change to how SAML and OIDC sign-in redirections are handled. This update resolves a potential open redirection vulnerability and adds an extra layer of protection during the sign-in process.
Zoho Account's domain removal process
As part of our domain clean-up process, we plan to remove domains that have not been renewed. Why this matters Zoho handles a large number of domains added by organizations daily. However, many organizations stop renewing domains they no longer need,
Announcement: Upcoming changes to the permission grant flow for OAuth apps
This announcement is intended for app developers who use the Zoho API console. We're going to implement an important update to the way users grant permission for the OAuth apps created through the API console. What’s changing? Currently, users can grant
Deprecation of SMS-based multi-factor authentication (MFA) mode
Overview of SMS-based OTP MFA mode The SMS-based OTP MFA method involves the delivery of a one-time password to a user's mobile phone via SMS. The user receives the OTP on their mobile phone and enters it to sign into their account. SMS-based OTPs offer
Cleanup of inactive verified domains
Greetings from the Zoho Accounts team! We are bringing a new addition to our existing domain cleanup process. We already have a domain cleanup process for unverified domains, which happens after 90 days. We are extending it to inactive verified domains
How to create a strong password? #WorldPasswordDay
The first Thursday of every May is celebrated as the World Password day. It was started by Intel in 2013 based on the idea of a security researcher named Mark Burnet who encouraged people to change their passwords often. On this day, let's look into the possible ways one can create a strong password: Use combination of upper and lower case alphabets Use special characters Avoid using dictionary words Avoid using the same password for multiple online accounts Use a minimum of 8 characters Avoid using
How Zoho protects you from breached passwords?
Cyber attacks, password breaches, and hacked online accounts have been recurring news for quite some time now. In the last decade alone, dozens of companies ranging from social media giants like Facebook and LinkedIn to software tycoons like Adobe became major victims of cyber attacks. Zoho is constantly monitoring these security-related incidents closely and have added an extra layer of security to protect your data. One such feature is the Breached Passwords Check. What are breached passwords?