Security key

Security key

What is a security key?

Security key is a hardware device that can be used to enable multi-factor authentication (MFA). They don't require a battery to function and need no software installation to authenticate your accounts.

How security keys work?

First, you will have to register your security key with your Zoho account. After registering, when you try to sign in to your account, you will be prompted to verify using your security key. When prompted, you will either need to insert the security key on to your device's port and tap its disc, or connect via NFC to verify. Once verification is complete, you will be signed in to your account.

Security key in Zoho: Points to note

  1. Zoho supports both FIDO U2F and FIDO2-based security key.
  2. You can register multiple security keys for your Zoho account, and use anyone of them to sign in.
  3. You can also register the same security key with multiple Zoho accounts and use it to sign in to them.
  4. You can also sign in to your mobile devices by connecting your security key through the device's port or through NFC.

Supported devices

FIDO U2F and FIDO2-based security keys are supported in Zoho.

Supported browser and their versions

The following browsers support security key for signing in to Zoho.

Supported browsers
Supported versions
    Mozilla Firefox
60 and above
    Google Chrome
67 and above
    Safari
13 and above
  Microsoft Edge
18 and above
    Opera
54 and above
In mobile devices

    Safari on iOS
13 and above
    Opera mobile
64
    Chrome for Android
102
    Firefox for Android
101

If your try signing in using security key from an unsupported browser, an error will be shown stating that the browser is not supported.

How to register a security key with Zoho account?

Requirements

  1. A FIDO U2F or FIDO2-based security key
  2. A supported browser and device

Steps to register

  1. Sign in at accounts.zoho.com.
  2. Click Multi-Factor Authentication in the left menu.
  3. Click Set up Now under Security key.
  4. If you are registering on a computer:
    1. Insert it into the USB port of your computer.
    2. Click Next .
    3. Wait for the security key to blink, then tap its disc.
    If you are registering on a mobile device, you can connect your security key either through the device's port or through NFC. 
    1. Insert the device port into the device port, or tap it against the NFC detection area on your device.
    2. If you are prompted for a PIN, enter your security key's FIDO2 PIN.
  5. Name your security key, then click Configure .
  6. Sign out of your Zoho Account and sign in back to confirm that security key authentication is enabled.
Using these steps, you can configure multiple security keys for your account.

How to set security key as primary MFA mode?

If you have configured multiple MFA modes for your account, you can set one of them as your primary MFA mode. When you try to sign in, your primary mode will be the default mode for authentication.

To set security key as primary MFA mode:
  1. Sign in at accounts.zoho.com .
  2. Click Multi-Factor Authentication in the left menu.
  3. Click MAKE PRIMARY next to security key.
  4. Click Confirm .

How to sign in using security key?

If security key is your primary MFA mode, follow the steps to sign in:
  1. Go to the Zoho sign-in page .
  2. Enter your email address, then click NEXT .
  3. Enter your password, then click SIGN IN .
  4. If you are signing in on a computer:
    1. Insert it into the USB port of your computer.
    2. Click Next .
    3. Wait for the security key to blink, then tap its disc.
    If you are signing in on a mobile device, you can connect your security key either via device's port or through NFC. Follow the on-screen instructions to connect and authenticate.
If you have set up multi-mode MFA with another MFA mode as your primary mode, see how to sign in using security key .
NotesNote : If you are using a mail client, you may have issues signing in to it once you enable MFA (in most cases, "incorrect password" error will be shown). This is because your mail client doesn't support MFA. In this case, you can use application-specific passwords to bypass MFA and sign in to your mail client.

How to recover account if security key is not accessible?

If you can't sign in to your account due to issues with your security key, then you can recover access to your account using your previously-generated backup verification codes .

See how to use backup codes to recover your account . Once you get access, make sure to re-configure security key with your account or a different MFA mode.
    • Related Articles

    • Security

      Change Password If you want to change your account password, you can change it by signing in to accounts.zoho.com. However, if you've forgotten your password and unable to sign in, then you will need to reset your password. Note: By default, Zoho ...
    • Multi-Mode MFA

      Introduction Multi-mode MFA is an option wherein you can enable more than one MFA mode for your Zoho account. Zoho provides four modes to choose from: OneAuth, SMS-based OTP, app-based OTP (authenticator apps), and Security key. To enable multi-mode ...
    • Introduction to multi-factor authentication (MFA)

      Multi-factor authentication is used as an extra layer of security while signing in to your account. When you enable MFA, all your future sign-ins will require you to verify your identity to ensure that your account isn't accessed by unknown users. ...
    • Sign-in modes

      Zoho offers various modes to sign in to your Zoho account, from the conventional method of signing in using only a password to the more secure method of signing in without using a password at all (passwordless sign-in). You can choose your preferred ...
    • Announcement pages for Zoho account

      Select the announcement you want help with: Account confirmation Confirm your location Review your account details Manage your domains Renew your domains Add your mobile number Confirm your email address/mobile number Terms of Service and Privacy ...