Configure password policy
Passwords are the most commonly used authentication factor. Many users reuse the same, insecure password for all their online accounts, compromising their organization's security. To protect yourself from this common pitfall, make it mandatory for your users to create passwords that meet certain security standards.
In the mobile application:
For iOS devices:
- Open the Zoho One app on your mobile device.
- Tap
in the bottom right, then tap Security Policies.
- Tap the required security policy, then tap Password Policy.
- If your enabling a password policy for the first time, tap the toggle bar to enable the password policy.
- If a password policy is already enabled, proceed to set the password preferences,
- Tap SAVE.
To disable a password policy:
- Open the Zoho One app on your mobile device.
- Tap
in the bottom right, then tap Security Policies.
- Tap the required security policy, then tap Password Policy.
- Tap the toggle bar to disable the password policy.
- Tap SAVE.
For Android devices:
- Open the Zoho One app on your mobile device.
- Tap
in the bottom-right corner, then tap Security Policies.
- Tap the required security policy.
- If you are enabling a password policy for the first time, check the box to enable it.
- If a password policy is already applied, tap
.
- Set the password preferences, then tap
.
- Tap Enable in the pop-up message that appears.
To disable a password policy:
- Open the Zoho One app on your mobile device.
- Tap
in the bottom-right corner, then tap Security Policies.
- Tap the required security policy, then uncheck Password Policy.
- Tap Disable in the pop-up message that appears.
In the web application:
- Sign in to Zoho One
, then click Directory in the left menu.
- Go to Security, click Security Policies, then click on the policy you want to configure.
- Go to Password Policy, then click Setup.
- Select from the three preset Password Strengths or choose Custom.
- If you choose Custom, set:
PASSWORD COMPLEXITY | Minimum length for a Password | The minimum number of characters the password must have. |
Mixed Password | When this is enabled, users have to set passwords with both upper and lower case characters. |
Minimum special characters | The number of special characters the password must have. |
Minimum numeric digits | The number of numeric characters the password must have. |
PASSWORD AGE | Maximum password age | The number of days users can use a password for. |
Minimum password age | The duration that users must use a password before resetting it. |
Refusal of Previously Used Passwords | The number of most recent passwords that users can't reuse. |
- Click Update Policy.
To remove a password policy:
- Sign in to Zoho One
![]()
, then click Directory in the left menu.
- Go to Security, then click Security Policies.
- Click on the policy for which you want to remove the password.
- Go to Password Policy, then click Remove Password Policy.

If a password policy is removed, the next policy having the top priority will be applied to the user. Check our help documentation to know more about
policy priority.
- Click Yes, Remove. The password policy will be removed and in order to enforce the newly prioritized user policy, you will need to reset all passwords.

The maximum password age, minimum password age, and the refusal of previously used passwords will be effective immediately after the password priority is set and the older one is removed.