Announcements
Improved Security in SAML/OIDC Sign-in Redirection Flow
To enhance the security of our authentication system, we’ve made a change to how SAML and OIDC sign-in redirections are handled. This update resolves a potential open redirection vulnerability and adds an extra layer of protection during the sign-in process.
Zoho Account's domain removal process
As part of our domain clean-up process, we plan to remove domains that have not been renewed. Why this matters Zoho handles a large number of domains added by organizations daily. However, many organizations stop renewing domains they no longer need,
Announcement: Upcoming changes to the permission grant flow for OAuth apps
This announcement is intended for app developers who use the Zoho API console. We're going to implement an important update to the way users grant permission for the OAuth apps created through the API console. What’s changing? Currently, users can grant
Deprecation of SMS-based multi-factor authentication (MFA) mode
Overview of SMS-based OTP MFA mode The SMS-based OTP MFA method involves the delivery of a one-time password to a user's mobile phone via SMS. The user receives the OTP on their mobile phone and enters it to sign into their account. SMS-based OTPs offer
Cleanup of inactive verified domains
Greetings from the Zoho Accounts team! We are bringing a new addition to our existing domain cleanup process. We already have a domain cleanup process for unverified domains, which happens after 90 days. We are extending it to inactive verified domains