Security Policies Migration

Security Policies Migration

Overview

The security policies have been revamped with a new set of configurations and policies designed to enhance your users’ login experience. We have introduced four new policies, each with unique functionality to provide greater flexibility in managing your organization’s authentication process.
The new set of policies includes:
1. Conditional Access Policies
Conditional access allows you to set policies that dictate how and when a user should be able to access their account. For example, you can set conditions that allow a user to sign in to their Zoho account only on certain days of the week, from certain locations, or
through certain devices.
2. Routing Policies
Routing policies enable you to decide which of your users must use which authentication modes to sign in with.
3. Identity Providers
Identity providers enables both SAML and JWT single sign-on (SSO) from your preferred identity providers to Zoho Directory.
4. Security Policies
Security policies provide you with a customizable password policy and advanced settings.
To learn more about the policies, click here.

Your existing setup will be automatically migrated into this new structure, allowing you to configure more advanced and secure policies for your users.

Security Policies Migration

1. Multi-Factor Authentication (MFA)



If you have configured MFA for a policy and selected any authentication mode for your users, your existing setup will be migrated to the Conditional Access Policies.
In Conditional Access Policies:
  1. MFA is configured as an action.
When migrated, a Conditional Access Policy will be created with the following settings:
  1. Condition: None
  2. Action: Allow with MFA (with your previous authentication mode)
When a policy member attempts to sign in, the “Allow with MFA” action will be triggered, prompting users to authenticate using multi-factor authentication. To learn more about Conditional Access Policies, click here.
Notes
If Allow Passwordless Sign-in was disabled for any user then, a routing policy will be created for the user with Password as the authentication mode.

2. Allowed IPs


If Allowed IPs were configured for a policy, the specified IP addresses will be migrated to the Conditional Access Policies.
In Conditional Access Policies:
  1. Allowed IPs is referred as IP address.
  2. IP address is configured as a condition.
When migrated, a Conditional Access Policy will be created with the following settings:
  1. Condition: IP Address (the IP address will retain the name of your original policy and will be selected here)
  2. Criteria: IP is not
  3. Action: Deny access
When a policy member attempts to sign in from an IP address that does not match the specified condition, the action "Deny access" will be triggered, blocking the user's sign-in attempt. To learn more about Conditional Access Policies, click here.

3. Session Lifetime and Idle Session Timeout


If Session Lifetime and Idle Session Timeout are configured under Advanced Settings within Security Policies, both settings will be migrated to the Routing Policies.
When migrated:
  1. A Routing Policy will be created and Session Settings will be configured.
  2. With this, you can continue to manage users’ web sessions efficiently, enhancing security and user experience.
To learn more about Routing Policies, click here.

4. Device Management



If Device Management is configured for users, the existing setup will be migrated to the Conditional Access Policies.
In Conditional Access Policies:
  1. Device Management is referred to as Device management status.
  2. It is configured as a condition.
When migrated, a Conditional Access Policy will be created with the following settings:
  1. Condition: Device management status
  2. Criteria: Unmanaged Device
  3. Action: Deny access
When a policy member attempts to sign in with an unmanaged device that meets this condition, the action "Deny access" will be triggered, blocking the user's sign-in attempt. To learn more about Conditional Access Policies, click here.

5. Multiple Configurations

If Allowed IPs, Device Management, and MFA are all configured for a user under a single security policy, two separate policies will be created under Conditional Access Policy.
Policy 1 with two conditions: A policy will be created with the following settings:
  1. Condition 1: IP address (the IP address will retain the name of your original policy and will be selected here)
  2. Criteria: IP is not
  3. Condition 2: Device management status
  4. Criteria: Unmanaged Device
  5. Action: Deny access
This will restrict the user from signing in from any location other than the specified IP address and block user's sign-in from unmanaged devices.

Policy 2: A policy will be created with the following settings:
  1. Condition: None
  2. Action: Allow with MFA (with your previous authentication mode)
This ensures users can sign in only after completing multi-factor authentication. To learn more about Conditional Access Policies, click here.

6. Custom Authentication


If you have added IdPs in Custom Authentication and have assigned groups to be authenticated through those IdPs, the setup will be migrated to Routing Policies as authentication mode.
In Routing Policies:
  1. Custom Authentication is referred to as Identity Providers.
  2. It is configured as an authentication mode.
When migrated:
  1. The existing IdP setup will be added to Identity Providers.
  2. A Routing Policy will be created and assigned to the same users.
  3. The IdP that is added will be selected as the authentication mode under the Routing Policy.
  4. The members belonging to these groups will be required to sign in using the same IdP.
To learn more about Routing Policies, click here.

      Create. Review. Publish.

      Write, edit, collaborate on, and publish documents to different content management platforms.

      Get Started Now


        Access your files securely from anywhere

          Zoho CRM Training Programs

          Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.

          Zoho CRM Training
            Redefine the way you work
            with Zoho Workplace

              Zoho DataPrep Personalized Demo

              If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

              Zoho CRM Training

                Create, share, and deliver

                beautiful slides from anywhere.

                Get Started Now


                  Zoho Sign now offers specialized one-on-one training for both administrators and developers.

                  BOOK A SESSION







                              Quick LinksWorkflow AutomationData Collection
                              Web FormsEnterpriseOnline Data Collection Tool
                              Embeddable FormsBankingBegin Data Collection
                              Interactive FormsWorkplaceData Collection App
                              CRM FormsCustomer ServiceAccessible Forms
                              Digital FormsMarketingForms for Small Business
                              HTML FormsEducationForms for Enterprise
                              Contact FormsE-commerceForms for any business
                              Lead Generation FormsHealthcareForms for Startups
                              Wordpress FormsCustomer onboardingForms for Small Business
                              No Code FormsConstructionRSVP tool for holidays
                              Free FormsTravelFeatures for Order Forms
                              Prefill FormsNon-Profit

                              Intake FormsLegal
                              Mobile App
                              Form DesignerHR
                              Mobile Forms
                              Card FormsFoodOffline Forms
                              Assign FormsPhotographyMobile Forms Features
                              Translate FormsReal EstateKiosk in Mobile Forms
                              Electronic Forms
                              Drag & drop form builder

                              Notification Emails for FormsAlternativesSecurity & Compliance
                              Holiday FormsGoogle Forms alternative GDPR
                              Form to PDFJotform alternativeHIPAA Forms
                              Email FormsFormstack alternativeEncrypted Forms

                              Wufoo alternativeSecure Forms

                              WCAG



                                        Create. Review. Publish.

                                        Write, edit, collaborate on, and publish documents to different content management platforms.

                                        Get Started Now







                                                          You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.




                                                              Manage your brands on social media


                                                                • Desk Community Learning Series


                                                                • Digest


                                                                • Functions


                                                                • Meetups


                                                                • Kbase


                                                                • Resources


                                                                • Glossary


                                                                • Desk Marketplace


                                                                • MVP Corner


                                                                • Word of the Day


                                                                • Ask the Experts


                                                                  Zoho Sheet Resources

                                                                   

                                                                      Zoho Forms Resources


                                                                        Secure your business
                                                                        communication with Zoho Mail


                                                                        Mail on the move with
                                                                        Zoho Mail mobile application

                                                                          Stay on top of your schedule
                                                                          at all times


                                                                          Carry your calendar with you
                                                                          Anytime, anywhere




                                                                                Zoho Sign Resources

                                                                                  Sign, Paperless!

                                                                                  Sign and send business documents on the go!

                                                                                  Get Started Now




                                                                                          Zoho TeamInbox Resources





                                                                                                    Zoho DataPrep Demo

                                                                                                    Get a personalized demo or POC

                                                                                                    REGISTER NOW


                                                                                                      Design. Discuss. Deliver.

                                                                                                      Create visually engaging stories with Zoho Show.

                                                                                                      Get Started Now









                                                                                                                          • Related Articles

                                                                                                                          • Exempt users from security policies

                                                                                                                            Go to Zoho Directory. Click Admin panel on the left menu. Select Security. You will land on the Security Policies tab, where you can view the security policies added so far. If you have not added a security policy yet, add one. Click on the security ...
                                                                                                                          • Roles and Permissions

                                                                                                                            The Helpdesk Admins will no longer be able to manage the security operations of your organization. With the new update and additional policies, we have reverted the security permissions of the Helpdesk Admin role and introduced the Security Admin ...
                                                                                                                          • Subscription

                                                                                                                            Previously, all the security features were grouped under Security Policy. With the new update, the policy structure has been redesigned, and the subscription plan has been updated to reflect this change. What's Changing? We are updating and ...
                                                                                                                          • Import users to Zoho Directory from other cloud identity solutions

                                                                                                                            Transferring user information from one identity provider to another can be tedious, and requires utmost care and effort, since even one mistake can lead to data breaches or loss. Zoho Directory provides you with different ways to import your users. ...
                                                                                                                          • Configure lock period settings

                                                                                                                            Pre-requisites: Org owner Org admin To access and impose lock period settings: Log in to Zoho Directory, then click Admin Panel. Go to Security from the left menu. Click open a security policy. If there isn't one added, learn how to add a security ...
                                                                                                                            Wherever you are is as good as
                                                                                                                            your workplace

                                                                                                                              Resources

                                                                                                                              Videos

                                                                                                                              Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                                                                              eBooks

                                                                                                                              Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                                                                              Webinars

                                                                                                                              Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                                                                              CRM Tips

                                                                                                                              Make the most of Zoho CRM with these useful tips.



                                                                                                                                Zoho Show Resources