Zoom access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Zoom, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Zoom connector needs.
Checks (8)
severity: medium Inactive User fix difficulty: easy #
Deactivate or remove inactive users in Zoom User Management
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to User Management > Users
- Search for and select the inactive user
- Click Deactivate or Delete to revoke access
- Confirm the action
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Admins fix difficulty: medium #
Reduce admin role members by demoting unnecessary administrators to standard roles
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to User Management > Role Management
- Open the Admin or Owner role and review the member list
- Select members that do not require admin privileges
- Change their role to a standard member role and save
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high SSO Not Enforced fix difficulty: medium #
Enable SSO sign-in enforcement under Advanced Security settings
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Advanced > Security
- Locate the Sign In Methods section
- Enable the SSO enforcement toggle
- Save changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Encryption Not Required For Third-Party Endpoints fix difficulty: easy #
Require encryption for 3rd party endpoints (H.323/SIP)
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > Meeting
- Enable 'Require encryption for 3rd party endpoints (H.323/SIP)'
- Save changes
Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high Password Embedded In Join Link fix difficulty: easy #
Stop embedding the meeting passcode in the join link
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > Security
- Disable 'Embed passcode in invite link for one-click join'
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Join Before Host Allowed fix difficulty: easy #
Disable join before host so participants cannot enter meetings unattended
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > Meeting
- Disable the Join before host toggle
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high No Password For Instant Meetings fix difficulty: easy #
Require a passcode for instant meetings
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > Security
- Enable 'Require a passcode for instant meetings'
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: high No Password For PMI Meetings fix difficulty: easy #
Require a passcode for Personal Meeting ID (PMI) meetings
- Log in to the Zoom admin portal at https://zoom.us/account
- Navigate to Account Management > Account Settings > Security
- Enable 'Require a passcode for Personal Meeting ID (PMI)'
- Save changes
Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2