Multi-factor authentication (MFA) adds an additional layer of security to your organization. When MFA is enabled, your users will have to verify their identity not only with their password, but also with a second factor. The second factor could be either an authenticator app like
Zoho OneAuth or an SMS-based OTP.
When MFA is enabled for a user, they will not be able to sign in without setting up their preferred authentication mode and verifying themself. You can configure the list of MFA modes your users can choose from.
To configure MFA:
- Sign in to the Zoho One Admin Panel.
- Go to Security, click Security Policies, then click on the policy you want to configure.
- Go to Multi-factor Authentication, then enable Multi-factor Authentication.
Select the authentication modes that you want your users to choose from. The available authentication modes are:
- Face ID / Touch ID (through Zoho OneAuth)
- Push Notification (through Zoho OneAuth)
- Time-based OTP (through Zoho OneAuth)
- QR Code (through Zoho OneAuth)
- Google Authenticator (or similar authentication apps)
- Yubikey
- SMS
- Enable Allow backup recovery codes to let your users generate backup verification codes. These are single-use codes that can be used to sign in to your Zoho One account when you've lost your credentials, MFA devices, and all other recovery methods. Learn more about backup verification codes.
- Click Update Policy.