Limit password history
Zoho Vault can remember a user's past passwords and use that history to block reuse. This setting controls how many passwords are stored per user.
To configure:
Click the Limit password history dropdown.
Select a value from 5 to 25 passwords.
Tip: Set this higher if your organization has strict compliance requirements. A longer history means a broader reuse restriction window.
Restrict previously used passwords
Once password history is in place, this toggle activates the actual reuse block. Without enabling this, history is tracked but not enforced.
To configure:
Turn on the Restrict previously used passwords toggle.
From the dropdown that appears, choose how far back the restriction should apply:
Last 3 Passwords
Last 5 Passwords
All Passwords
Tip: For most organizations, All Passwords is the strongest and most recommended option. Use Last 3 or Last 5 if your teams rotate passwords frequently and need more flexibility.Enforce default settings for new passwords
When a user saves a new password in Zoho Vault, this setting determines whether it defaults to Personal or Enterprise storage or leaves that choice up to the user.
To configure:
Click the Enforce default settings for new passwords dropdown.
Select one of the following:
Allow users to choose: No default is enforced. Users pick Personal or Enterprise at the time of saving.
Set default to Personal: New passwords are saved as Personal by default, visible only to the individual user.
Set default to Enterprise: New passwords are saved as Enterprise
by default, making them centrally managed and auditable.
Inactivity timeout
Inactivity timeout automatically logs users out after a period of no activity. This can be enforced separately for each platform.
To configure:
Scroll down to the Inactivity Timeout section.
You will see a table with two platforms: Web and Browser Extension.
For each platform, click the dropdown under Enforce for Everyone and select a timeout duration.
Available timeout values: Allow users to choose, 5 Minutes, 10 Minutes, 15 Minutes, 20 Minutes, 25 Minutes, 30 Minutes, 35 Minutes, 40 Minutes, 45 Minutes, 50 Minutes, 55 Minutes, 1 Hour, 2 Hours, 4 Hours, 8 Hours, 12 Hours, 1 Day, 2 Days, 1 Week.
Important: Setting this to a longer duration like 1 Week means sessions remain active for extended periods without re-authentication. This is not recommended for most organizational environments. When in doubt, shorter timeouts are always the safer choice.
Best practices for administrators
Enable password history restriction from day one to enforce password hygiene across the organization.
Set new passwords to Enterprise by default if your organization shares credentials across teams, to prevent accidental personal storage of business accounts.
Keep inactivity timeouts short (15–30 minutes) to minimize exposure on unattended sessions, especially on shared workstations.
Review these settings periodically at least quarterly to ensure they align with your organization's evolving security policies.
Pair these settings with Enforce MFA (found under User Management) and a strong Password Policy (found under Password Management) for a comprehensive security posture.