How does Zoho Vault’s 'One-Click Login Only' permission enhance security, and are there any limitations?
- The One-Click Login Only permission allows users to log in to websites without revealing their password.
- On desktop browsers, in most of the websites, the Zoho Vault extension prevents users from viewing passwords using the Show Password option, and also blocks autofill if the developer console is open or previously accessed.
- This feature is fully compatible with all major desktop browsers, except Safari, as Apple does not provide the necessary controls for third-party password managers.
- While Zoho Vault does not display the password within its interface, a tech-savvy user may still retrieve it using advanced browser techniques during login.
- On mobile devices (Android and iOS), since autofill is managed by the operating system (using their native credentials autofill service), Zoho Vault cannot restrict users from viewing passwords via the 'Show Password' option in mobile browsers and applications.
Additional security measures you can implement:
- Disable Developer Console access in browsers via group policies.
- Restrict browser extensions by allowing only whitelisted extensions through policy enforcement.