Add conditional access policy

Add conditional access policy

The steps to add conditional access policy vary between three user Interface versions supported in Zoho One. Select the UI version you use from the tabs below and proceed with the steps that follow.
One Experience UI
Spaces UI
Unified UI
One Experience UI
  1. Sign in to Zoho One, then click Admin Panel icon  on the top-right corner.
  2. Click Security on the left menu, the Conditional Access Policies tab opens by default.
  3. Click Add Policy.
  4. Enter a name for your policy, and choose what type of Action should be taken based on your policy. The available actions are Deny access, Allow with MFA, and Allow access.
  5. If you chose the Allow with MFA action, set up MFA settings.
    1. Configure MFA Factors: Select the MFA factors your users should be allowed to configure for themselves. 
    2. Browser Trust Lifetime: Select if your users can mark a browser as a trusted browser, and if they do, how long they can sign in without MFA in that browser after marking it. 
    3. Backup Verification Codes: Select if users can generate and use backup verification codes to bypass MFA. 
    4. Prioritize Policy Above: Select the priority of this policy with other conditional access policies with the Allow with MFA action. 
    5. Click Next.
  6. Select which type of apps/users the policy's conditions should be applied for.
    1. Web and mobile apps: These are Zoho's own web and mobile apps.
    2. Client apps: These are apps with limited authentication control, like mail clients. When users sign in to these types of apps, only the IP address and Country conditions will be checked due to the limitations of the apps.
    3. RADIUS clients: The users who sign in with RADIUS. To receive OTPs, RADIUS clients require OneAuth to be configured as a mandatory MFA factor. 
  7. Configure the required Conditions, and select if the policy should be applied when all conditions match, or when at least one condition matches. 
  8. Click Next.
  9. Select if the policy should be applied only for specific groups, or for everyone in your organization. 
  10. Select if any users should be excluded from the policy, even if they are part of the selected groups (or even when you've chosen to apply the policy to everyone in your organization).
  11. Click Add. You may be asked to verify your identity by re-authenticating yourself.

Spaces UI
  1. Sign in to Zoho One, then click Directory Settings icon  on the top-right corner.
  2. Click Security on the left menu, the Conditional Access Policies tab opens by default.
  3. Click Add Policy.
  4. Enter a name for your policy, and choose what type of action should be taken based on your policy. 
  5. If you chose the Allow with MFA action, set up MFA settings.
    1. Configure MFA Factors: Select the MFA factors your users should be allowed to configure for themselves. 
    2. Browser Trust Lifetime: Select if your users can mark a browser as a trusted browser, and if they do, how long they can sign in without MFA in that browser after marking it.
    3. Backup Verification Codes: Select if users can generate and use backup verification codes to bypass MFA.
    4. Prioritize Policy Above: Select the priority of this policy with other conditional access policies with the Allow with MFA action. 
  6. Click Next.
  7. Select which type of apps the policy's conditions should be applied for.
    1. Web and mobile apps: These are Zoho's own web and mobile apps.
    2. Client apps: These are apps with limited authentication control, like mail clients. When users sign in to these types of apps, only the IP address and Country conditions will be checked due to the limitations of the apps.
    3. RADIUS clients: The users who sign in using RADIUS. To receive OTPS, RADIUS clients require OneAuth to be configured as a mandatory MFA factor. 
  8. Configure the required Conditions, and select if the policy should be applied when all conditions match, or when at least one condition matches. 
  9. Click Next.
  10. Select if the policy should be applied only for specific groups, or for everyone in your organization. 
  11. Select if any users should be excluded from the policy, even if they are part of the selected groups (or even when you've chosen to apply the policy to everyone in your organization).
  12. Click Add. You may be asked to verify your identity by re-authenticating yourself.
Unified UI
  1. Sign in to Zoho One, then click Directory in the left menu.
  2. Go to the Security tab, then go to Conditional Access Policies.
  3. Click Add Policy.
  4. Enter a name for your policy, and choose what type of action should be taken based on your policy. 
  5. If you chose the Allow with MFA action, set up MFA settings.
    1. Configure MFA Factors: Select the MFA factors your users should be allowed to configure for themselves. 
    2. Browser Trust Lifetime: Select if your users can mark a browser as a trusted browser, and if they do, how long they can sign in without MFA in that browser after marking it.
    3. Backup Verification Codes: Select if users can generate and use backup verification codes to bypass MFA.
    4. Prioritize Policy Above: Select the priority of this policy with other conditional access policies with the Allow with MFA action. 
  6. Click Next.
  7. Select which type of apps the policy's conditions should be applied for.
    1. Web and mobile apps: These are Zoho's own web and mobile apps.
    2. Client apps: These are apps with limited authentication control, like mail clients. When users sign in to these types of apps, only the IP address and Country conditions will be checked due to the limitations of the apps.
    3. RADIUS clients: The users who sign in using RADIUS. To receive OTPs, RADIUS clients require OneAuth to be configured as a mandatory MFA factor.
  8. Configure the required conditions, and select if the policy should be applied when all conditions match, or when at least one condition matches. 
  9. Click Next.
  10. Select if the policy should be applied only for specific groups, or for everyone in your organization. 
  11. Select if any users should be excluded from the policy, even if they are part of the selected groups (or even when you've chosen to apply the policy to everyone in your organization).
  12. Click Add. You may be asked to verify your identity by re-authenticating yourself.