Must Have Security Settings in Zoom

Zooms main target audience has been corporate customers who use it predominantly for internal meetings - this means we consider Zoom meetings generally “safe” as they are between trusted parties. With the recent huge uptake in Zoom during the Covid-19 pandemic, Zoom has gotten a lot of negative press. I’m still sticking with them as I believe they have responded to the critisism faster than most companies could and their product is becoming an even better one as a result. That being said here are some MUST HAVE SECURITY SETTINGS that you absolutely should set if you are running any Zoom meetings outside of the intended scope - i.e. public meetings, Meetups, chapter meetings, etc.

For this case we are considering external facing meetings where I am inviting a large amount of external parties as unsafe.

These are what I consider secure for my context - please use common sense when adapting this to yours.

Meeting Settings

Schedule Meeting

FeatureDescriptionSetting
Host videoStart meetings with host video onOFF
Participants videoStart meeting with participant video onOFF
Join before hostThis has to be off for waiting room to be onON
Require a password when scheduling new meetingsAll meetings should require a password - lock this at Admin levelON (Locked)
Require a password for instant meetingsAll meetings should require a password - lock this at Admin levelON (Locked)
Require a password for Personal Meeting ID (PMI)All meetings should require a password - lock this at Admin levelON (Locked)
Only meetings with Join Before Host enabled / All meetings using PMIAll meetings should require a password - lock this at Admin levelON (Locked)
Embed password in meeting link for one-click jointhis is the ?pwd= portion in the Zoom invite linkAS REQUIRED (ON for me)
Require password for participants joining by phoneAll meetings should require a password - lock this at Admin levelON (Locked)

In Meeting (Basic)

FeatureDescriptionSetting
Require Encryption for 3rd Party Endpoints (H323/SIP)If you have supported 3rd party endpoints lock this to onON (Locked)
ChatAllow meeting participants to send a message visible to all participantsAS REQUIRED (ON for me)
File transferHosts and participants can send files through the in-meeting chatAS REQUIRED (ON for me)
Co-hostAllow the host to add co-hosts. Co-hosts have the same in-meeting controls as the hostAS REQUIRED (ON for me)
Screen sharingAllow screen sharing - with the introduction of the Security button this can now be toggled in the meetingON
Who can share?Host Only
Who can start sharing when someone else is sharing?Host Only
Disable desktop/screen share for usersAS REQUIRED (OFF for me)
AnnotationAllow participants to use annotation tools to add information to shared screensAS REQUIRED (ON for me)
WhiteboardAllow participants to share whiteboard during a meetingAS REQUIRED (ON for me)
Remote controlDuring screen sharing, the person who is sharing can allow others to control the shared contentOFF (Locked)
Nonverbal feedbackEnable non-verbal feedbackAS REQUIRED (Locked ON for me)
Allow removed participants to rejoinParticipants can be removed from the participants panel - this sets if they can re-joinOff
Allow participants to rename themselvesThis can also be controlled during the meeting via the Security button - it can allow innapropriate namesAS REQUIRED (ON for me)

In Meeting (Advanced)

FeatureDescriptionSetting
Breakout RoomAllow the host to split meeting participants into separate, smaller rooms.AS REQUIRED (ON for me)
Allow host to assign participants to breakout rooms when schedulingAS REQUIRED (ON for me)
Remote supportUnless you use Zoom for support I would leave this off. Or create a dedicated group to have this on. Has to be off if using Breakout RoomsAS REQUIRED (OFF for me)
Far end camera controlUnless you need this for Zoom Rooms I would leave it offAS REQUIRED (Locked OFF for me)
Waiting roomTo ensure you know who is joining this should be onON (Locked)
Choose which participants to place in the waiting roomThis will only place people not in your domain or not logged in into the waiting roomGuest Particitpants Only
Allow internal participants to admit guests from the waiting room if the host is not presentThis can be on as we have a higher level of trust in authenticated internal usersYes
Show a “Join from your browser” linkThis allows joining from the browser versionAS REQUIRED (ON for me)

Other

FeatureDescriptionSetting
Blur snapshot on task switcherON (Locked)

Recording

FeatureDescriptionSetting
Only authenticated users can view cloud recordingsset to your domainON (Locked)
Require password to access shared cloud recordingsalways require passwordsON (Locked)
Recording disclaimerIf you are recording sessions it’s probably a good idea to have this onAS REQUIRED (Locked ON for me)
Ask participants for consent when a recording startsAS REQUIRED (Locked ON for me)
Ask host to confirm before starting a recordingAS REQUIRED (Locked ON for me)
Multiple audio notifications of recorded meetingAS REQUIRED (Locked ON for me)