Set up OneAuth for your Zoho accounts | OneAuth

Set up OneAuth for your Zoho account

Info: This article explains the working of OneAuth and how you can set it up to secure your Zoho account. If you don't have a Zoho account, but want to secure your other non-Zoho accounts, check out OneAuth's OTP Authenticator.

How OneAuth works

Zoho OneAuth offers a three-step authentication flow to secure and improve the sign-in experience for its users. After you enter your username, you will need to verify yourself using the following steps:
  1. Enter your password.
  2. Verify your identity using one of three sign-in modes available in OneAuth.
  3. Verify your identity using your biometric data such as your finger print or facial recognition data.
Info: You can also choose to skip the password step using the passwordless sign-in feature. 

OneAuth sign-in modes

OneAuth offers three sign-in modes to verify yourself. You can set one of these as your preferred sign-in mode, and the other two will be set as alternate verification modes. When signing in to your Zoho account, you will be prompted to verify using the preferred sign-in mode, but you can always switch to an alternate verification mode by clicking Sign in another way on your sign-in page.

mode

How it works


Push notification

A push notification will be sent to your mobile device when you try to sign in. You will need to accept it to verify yourself.

Requires Internet

Time-based OTP

In the sign-in page, you will need to enter a verification code that your OneAuth apps generates (for every 30 seconds) to verify yourself.

Works offline

QR code

In the sign-in page, you will need to scan a QR code using the scanner in your OneAuth app to verify yourself.

Requires Internet

Biometric verification

In addition to the sign-in modes of OneAuth, you can also set up another layer of verification using your biometrics (provided that your device supports it). You can configure either Face ID or Touch ID for verification.

Passwordless sign-in

OneAuth also offers a way for you to sign in without using a password. With passwordless sign-in, the first step of entering your password will be skipped. Your preferred sign-in mode and biometric data will act as the first and second steps of verification.

You can enable passwordless sign-in when configuring MFA in OneAuth.
For a seamless sign-in experience, we recommend the combination of Passwordless sign-in + Push notification mode + Biometric verification.

Setting up OneAuth


  1. Must have a Zoho account
  2. Must have a supported browser (Google Chrome or Safari browser) installed in you mobile phone
Note: If you are part of an organization, your organization admin may have enforced MFA-related security policies. In that case, some MFA and recovery options may not be available to you.

A. Install OneAuth and enable MFA

  1. Download and Install the latest version of OneAuth (from Appstore/ Playstore).
  2. Open OneAuth and tap SIGN IN.
  3. Sign in with your Zoho credentials.
  4. Tap either Go Passwordless or Keep using Password.
  5. In the Authentication Summary page, tap Enable MFA.

B. Configure MFA

Once you have enabled MFA using OneAuth, you can configure MFA as per your requirements.
  1. In the MFA tab, tap .
  2. If you want to sign in without entering the password, enable Passwordless sign in.
  3. Select your Preferred sign-in mode, then click Done.
  4. If you want to add another layer of biometric verification, enable Fingerprint authorizationFace ID authorization.

C. Configure recovery mode

Configuring recovery modes will help you avoid getting locked out of your account, incase you lose your mobile device or lose access to OneAuth in some way.
  1. Go to the Settings tab.
  2. Tap Recovery.
  3. Configure your preferred recovery modes:
    1. Passphrase
    2. Backup mobile number
    3. Backup verification codes

D. Set OneAuth as your primary MFA mode

If you have multiple MFA modes configured, you can set OneAuth as your primary MFA mode using the steps below:
  1. Go to
  2. Click Multi-Factor Authentication in the left menu.
  3. Click Make Primary next to OneAuth.
Note: If you haven't configured any other MFA mode, OneAuth will be set as the primary mode by default.

Learn more about OneAuth

  1. Alternate verification
  2. OneAuth's OTP authenticator
  3. Recovering OneAuth

    Zoho DataPrep Personalized Demo

    If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

    Zoho CRM Training

      Create, share, and deliver

      beautiful slides from anywhere.

      Get Started Now

              Zoho CRM Training Programs

              Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

              Zoho CRM Training

                Zoho SalesIQ Resources

                    Zoho TeamInbox Resources

                              Zoho DataPrep Resources

                                Zoho DataPrep Demo

                                Get a personalized demo or POC

                                REGISTER NOW

                                  Design. Discuss. Deliver.

                                  Create visually engaging stories with Zoho Show.

                                  Get Started Now

                                                        • Related Articles

                                                        • Passwordless Sign-in

                                                          Our OneAuth's passwordless sign-in mode offers you a secure and seamless way to sign in to your Zoho account. It's a form of multi-factor authentication (MFA) where you don't need to enter your password to sign in. Regular MFA sign-in: Username ----> ...
                                                        • Sign-in Modes

                                                          Zoho offers various modes to sign in to your Zoho account, from the conventional method of signing in using only a password to the more secure method of signing in without using a password at all (passwordless sign-in). You can choose your preferred ...
                                                        • Getting started with OneAuth

                                                          What is OneAuth? OneAuth is a free industry-standard multi-factor authentication (MFA) app developed by Zoho for securing your Zoho accounts and social accounts such as Google, Facebook, and Twitter. Configuring MFA for your online accounts will ...
                                                        • OneAuth

                                                          Zoho's OneAuth is a multi-factor authentication (MFA) app designed to secure your Zoho accounts as well as other third-party accounts.   The key features of OneAuth include the following: Passwordless sign-in allows you to sign in to your account ...
                                                        • OneAuth authentication modes

                                                          After you install OneAuth, make sure to allow notifications for the OneAuth application. You will receive a notification only when you are trying to sign in to your Zoho account. Face ID Face ID is Apple's cutting-edge bio-metric recognition ...



                                                        Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.


                                                        Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.


                                                        Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.

                                                        CRM Tips

                                                        Make the most of Zoho CRM with these useful tips.

                                                          Zoho Show Resources