Conditional access - overview

Conditional access - overview

Conditional access allows you to set policies that dictate how and when a user should be able to access their account. For example, you can set conditions that allow a user to sign in to their Zoho account only on certain days of the week, from certain locations, or through certain devices.

Conditions

When a policy is applied to a user, the conditions are checked for their current sign-in attempt. If the conditions match, the corresponding action will be done. Currently, the following conditions are supported:
  1. Day of the week
  2. Time of the day
  3. Platform: This condition checks the OS of the device the user is signing in from. Supported options are: Windows, Mac, Linux, Android, iPhone, and iPad.
  4. Applied routing policy: This condition checks whether the user is assigned to the mentioned routing policies or not. Learn more about routing policies
  5. Device management status: These are conditions based on the Device Management feature. This condition checks whether the device is managed via MDM or not and what the Device Security Score of the device should be. Learn more about device management
  6. IP address: This condition checks whether the user is trying to sign in from the approved IPs or not. IPs can be added in three ways:
    1. Current IP: The IP you're accessing Zoho Directory from when setting up the policy is detected and auto-filled.
    2. Static IP: You can enter a specific IP address manually.
    3. IP Range: You can enter a range of IPs manually.
  7. Country: This condition checks the geographical location from where the user is trying to sign in.

Actions

Actions dictate how the sign-in attempt is handled when it matches the conditions of a policy applied to a user. There are three possible actions:
  1. Allow: If the user's sign-in attempt matches with any of the policies applied to them with the Allow action, they will be allowed to sign in.
  2. Allow with MFA: If the user's sign-in attempt matches with any of the policies applied to them with the Allow with MFA action, they will be asked to verify with MFA before being allowed to sign in.
  3. Deny: If the user's sign-in attempt matches with any of the policies applied to them with the Deny action, they will not be allowed to sign in.
Policies with the Allow action are checked first, Allow with MFA next, Deny last. If none of the policies match, then the default action is applied.

MFA Factors

When the Allow with MFA action is selected, you will be asked to set which MFA factors have to be used when a user matches that specific policy. The supported factors are:
  1. Zoho OneAuth - Zoho's own authenticator app. Learn more
  2. OTP Authenticator - Any 2FA authenticator app. Learn more
  3. Security Key - A hardware security key. Learn more
Since these factors are configured separately for each policy, the order of priority is important for MFA policies. Learn more about policy priority

Default Action

When conditional access is set up, and a user's sign-in attempt doesn't match with any policies or fails all matching policies, the default action is carried out. The options are the same as any other policy—Allow, Allow with MFA, and Deny.
When planning your conditional access setup, it is suggested to stick with one of two approaches:
  1. Allow by default: In this approach, set your default action to be Allow or Allow with MFA. Then set up all other policies with the Deny action. In other words, during each sign-in attempt, Zoho Directory will check the Deny conditions to see if there is any reason to deny access. If there are no reasons, then the user will be allowed to sign in. 
    Example policies would be having conditions such as:
    1. Deny if the sign-in attempt is not from the selected countries
    2. Deny if the sign-in attempt is on a Sunday
    3. Deny if the sign-in attempt is not from the selected IP addresses
  2. Deny by default: In this approach, set your default action to be Deny. Then set up all other policies with the Allow or Allow with MFA action. During each sign-in attempt, Zoho Directory will check if the sign-in attempt matches any of the allowed conditions. If it doesn't, then the user will not be allowed to sign-in. Example policies would be having conditions such as:
    1. Allow if the sign-in attempt is between 9AM and 6PM
    2. Allow with MFA if the sign-in attempt is from a managed device
    3. Allow if the sign-in attempt is from a Mac laptop

      Create. Review. Publish.

      Write, edit, collaborate on, and publish documents to different content management platforms.

      Get Started Now


        Access your files securely from anywhere

          Zoho CRM Training Programs

          Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

          Zoho CRM Training
            Redefine the way you work
            with Zoho Workplace

              Zoho DataPrep Personalized Demo

              If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

              Zoho CRM Training

                Create, share, and deliver

                beautiful slides from anywhere.

                Get Started Now


                  Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                  BOOK A SESSION







                              Quick LinksWorkflow AutomationData Collection
                              Web FormsEnterpriseOnline Data Collection Tool
                              Embeddable FormsBankingBegin Data Collection
                              Interactive FormsWorkplaceData Collection App
                              CRM FormsCustomer ServiceAccessible Forms
                              Digital FormsMarketingForms for Small Business
                              HTML FormsEducationForms for Enterprise
                              Contact FormsE-commerceForms for any business
                              Lead Generation FormsHealthcareForms for Startups
                              Wordpress FormsCustomer onboardingForms for Small Business
                              No Code FormsConstructionRSVP tool for holidays
                              Free FormsTravelFeatures for Order Forms
                              Prefill FormsNon-Profit

                              Intake FormsLegal
                              Mobile App
                              Form DesignerHR
                              Mobile Forms
                              Card FormsFoodOffline Forms
                              Assign FormsPhotographyMobile Forms Features
                              Translate FormsReal EstateKiosk in Mobile Forms
                              Electronic Forms
                              Drag & drop form builder

                              Notification Emails for FormsAlternativesSecurity & Compliance
                              Holiday FormsGoogle Forms alternative GDPR
                              Form to PDFJotform alternativeHIPAA Forms
                              Email FormsFormstack alternativeEncrypted Forms

                              Wufoo alternativeSecure Forms

                              WCAG

                                        Create. Review. Publish.

                                        Write, edit, collaborate on, and publish documents to different content management platforms.

                                        Get Started Now







                                                          You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                              Manage your brands on social media


                                                                • Desk Community Learning Series


                                                                • Digest


                                                                • Functions


                                                                • Meetups


                                                                • Kbase


                                                                • Resources


                                                                • Glossary


                                                                • Desk Marketplace


                                                                • MVP Corner


                                                                • Word of the Day


                                                                • Ask the Experts


                                                                  Zoho Sheet Resources

                                                                   

                                                                      Zoho Forms Resources


                                                                        Secure your business
                                                                        communication with Zoho Mail


                                                                        Mail on the move with
                                                                        Zoho Mail mobile application

                                                                          Stay on top of your schedule
                                                                          at all times


                                                                          Carry your calendar with you
                                                                          Anytime, anywhere




                                                                                Zoho Sign Resources

                                                                                  Sign, Paperless!

                                                                                  Sign and send business documents on the go!

                                                                                  Get Started Now




                                                                                          Zoho TeamInbox Resources





                                                                                                    Zoho DataPrep Demo

                                                                                                    Get a personalized demo or POC

                                                                                                    REGISTER NOW


                                                                                                      Design. Discuss. Deliver.

                                                                                                      Create visually engaging stories with Zoho Show.

                                                                                                      Get Started Now








                                                                                                                          • Related Articles

                                                                                                                          • Groups - Overview

                                                                                                                            Groups are used in Zoho Directory to simplify user management. Groups allow you to provide app access to and enforce security policies for multiple users simultaneously. If you're using Zoho Mail, you will also be able to create email aliases for ...
                                                                                                                          • Rename conditional access policy

                                                                                                                            Sign in to Zoho Directory, then click Admin Panel in the left menu. Go to the Security tab, then go to Conditional Access Policies. Click on the policy you want to rename, then click Rename. Enter the new name, then click Rename.
                                                                                                                          • Delete conditional access policy

                                                                                                                            Sign in to Zoho Directory, then click Admin Panel in the left menu. Go to the Security tab, then go to Conditional Access Policies. Click on the policy you want to delete, click the icon, then click Delete. Confirm your action by clicking Delete ...
                                                                                                                          • Deactivate conditional access policy

                                                                                                                            Sign in to Zoho Directory, then click Admin Panel in the left menu. Go to the Security tab, then go to Conditional Access Policies. Click on the policy you want to deactivate, click the icon, then click Deactivate. Confirm your action by clicking ...
                                                                                                                          • Edit conditional access policy

                                                                                                                            Sign in to Zoho Directory, then click Admin Panel in the left menu. Go to the Security tab, then go to Conditional Access Policies. Click on the policy you want to edit. Use the sub-tabs to edit the policy: Policy Info: You can add or remove users to ...
                                                                                                                            Wherever you are is as good as
                                                                                                                            your workplace

                                                                                                                              Resources

                                                                                                                              Videos

                                                                                                                              Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                              eBooks

                                                                                                                              Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                              Webinars

                                                                                                                              Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                              CRM Tips

                                                                                                                              Make the most of Zoho CRM with these useful tips.



                                                                                                                                Zoho Show Resources