Domain Restriction for User Management Actions in Zoho One

Domain Restriction for User Management Actions in Zoho One

Greetings, Zoho One Admins!

To strengthen account security further and safeguard user management settings, we are imposing domain-based restrictions for user account-focused admin actions in Zoho One.

In addition to password reset of user, organization admins will now be restricted from performing the following actions:
  1. Reset MFA
  2. Disable MFA
  3. Generate backup code for a user
  4. Create Mailbox
  5. Manage email address
These actions will be permitted only for users belonging to verified domains within the organization.

Why is this restriction being imposed?

User management actions such as MFA resets, backup code generation, and email management directly impact a user's authentication and account recovery mechanisms. If misused, these actions can allow unauthorized access, account takeovers, or privilege escalation.

By enforcing domain verification, Zoho One ensures that only users who email domains are proven to be owned and controlled by the organization can have their sensitive security settings managed by the admins. 


What is the limitation in the current architecture?

As admins in an organization have access to all the user's app data, they can perform sensitive user management actions on accounts associated with unverified or external domains. Due to this, there's a possibility of a security breach or data leak when an admin unintentionally controls the data upon a user joining or being invited to the organization. 

What's getting protected?

To mitigate the issues in the previous architecture, we have now enforced domain verification to perform actions like MFA resets in Zoho One. By implementing this measure, only authorized users will have access to the domain, ensuring that data is prevented from misuse. 


Regards,
The Zoho One Team.




    • Sticky Posts

    • How to Add Users to your Organization in ZohoMail?

      A better clarity so you can create other users to start using Zoho Mail. You can directly Add Users from the Control Panel to your Organization. You can invite users with the existing email address. If the person (user) already uses ZohoCRM, then you can import users from Zoho CRM. You can also import them using a .csv file. (if you are planning to add them in Bulk)  In this topic, We will be discussing on how to Add and Invite users only.  The Import options are self explanatory. ____________________________________________________________________________________________________________