Configuration

Configuration

The Configuration page in Zoho Vault gives administrators centralized control over two critical areas of organizational security: how passwords are created and reused, and how long user sessions stay active before timing out. Keeping these settings well-configured reduces the risk of credential recycling, unauthorized access, and unattended session exploits.
This guide explains every available option, what it does, and how to set it up correctly.

Accessing the configuration page 

  1. Log in to your Zoho Vault account as an administrator.
  2. In the left sidebar, click Settings.
  3. Under Admin Configurations, click Configuration.

Password management settings  

This section governs how passwords are stored, reused, and categorized across your organization.

Limit password history 

Zoho Vault can remember a user's past passwords and use that history to block reuse. This setting controls how many passwords are stored per user.

To configure:
  1. Click the Limit password history dropdown.
  2. Select a value from 5 to 25 passwords.
Tip: Set this higher if your organization has strict compliance requirements. A longer history means a broader reuse restriction window.

Restrict previously used passwords 

Once password history is in place, this toggle activates the actual reuse block. Without enabling this, history is tracked but not enforced.
To configure:
  1. Turn on the Restrict previously used passwords toggle.
  2. From the dropdown that appears, choose how far back the restriction should apply:
    • Last 3 Passwords
    • Last 5 Passwords
    • All Passwords
InfoTip: For most organizations, All Passwords is the strongest and most recommended option. Use Last 3 or Last 5 if your teams rotate passwords frequently and need more flexibility.

Enforce default settings for new passwords 

When a user saves a new password in Zoho Vault, this setting determines whether it defaults to Personal or Enterprise storage or leaves that choice up to the user.

To configure:
  1. Click the Enforce default settings for new passwords dropdown.
  2. Select one of the following:
    • Allow users to choose: No default is enforced. Users pick Personal or Enterprise at the time of saving.
    • Set default to Personal: New passwords are saved as Personal by default, visible only to the individual user.
    • Set default to Enterprise: New passwords are saved as Enterprise
      by default, making them centrally managed and auditable.

Inactivity timeout 

Inactivity timeout automatically logs users out after a period of no activity. This can be enforced separately for each platform.
To configure:
  1. Scroll down to the Inactivity Timeout section.
  2. You will see a table with two platforms: Web and Browser Extension.
  3. For each platform, click the dropdown under Enforce for Everyone and select a timeout duration.
    • Available timeout values: Allow users to choose, 5 Minutes, 10 Minutes, 15 Minutes, 20 Minutes, 25 Minutes, 30 Minutes, 35 Minutes, 40 Minutes, 45 Minutes, 50 Minutes, 55 Minutes, 1 Hour, 2 Hours, 4 Hours, 8 Hours, 12 Hours, 1 Day, 2 Days, 1 Week.
Info
Important: Setting this to a longer duration like 1 Week means sessions remain active for extended periods without re-authentication. This is not recommended for most organizational environments. When in doubt, shorter timeouts are always the safer choice.

Best practices for administrators 

  1. Enable password history restriction from day one to enforce password hygiene across the organization.
  2. Set new passwords to Enterprise by default if your organization shares credentials across teams, to prevent accidental personal storage of business accounts.
  3. Keep inactivity timeouts short (15–30 minutes) to minimize exposure on unattended sessions, especially on shared workstations.
  4. Review these settings periodically at least quarterly to ensure they align with your organization's evolving security policies.
  5. Pair these settings with Enforce MFA (found under User Management) and a strong Password Policy (found under Password Management) for a comprehensive security posture.