Skip to content

Zoom configuration hardening security checks

Vendor-recommended secure defaults, patch levels and housekeeping settings that drift as tenants grow and admins change.

On Zoom, Black Cat runs 20 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Zoom connector needs.

Checks (20)

severity: high No Meeting Password Required fix difficulty: easy #

Enable meeting password requirements in Zoom Meeting Security settings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Meeting tab and go to the Security section
  4. Enable Require a password when scheduling new meetings
  5. Save changes and lock the setting if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Waiting Room Disabled fix difficulty: easy #

Enable the Waiting Room feature in Zoom Meeting Security settings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Meeting tab and go to the Security section
  4. Enable the Waiting Room toggle
  5. Save changes and optionally lock the setting for all users

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Unauthenticated Join Allowed fix difficulty: easy #

Restrict meeting joins to authenticated users only in Zoom Meeting Security settings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Meeting tab and go to the Security section
  4. Enable Only authenticated users can join meetings
  5. Save changes and lock the setting if required

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Local Recording Enabled fix difficulty: easy #

Disable local recording in Zoom Recording settings to prevent unauthorised local storage

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Recording tab
  4. Disable the Local Recording toggle
  5. Save changes and lock the setting to prevent user override

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Cloud Recording No Auto-Delete fix difficulty: easy #

Enable auto-deletion of cloud recordings to limit long-term data retention exposure

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Recording tab
  4. Enable Auto delete cloud recordings after a set number of days
  5. Set a retention period aligned with your data policy and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: high Weak Password Policy fix difficulty: easy #

Strengthen the account password policy under Advanced Security settings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Advanced > Security
  3. Locate the Password section
  4. Set minimum length to at least 8 characters and require mixed case, numbers, and special characters
  5. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-32.1b.i HIPAA (SaaS Security) HIPAA-312.d NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Chat File Transfer Enabled fix difficulty: easy #

Disable file transfer in meeting chat to reduce data exfiltration risk

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings
  3. Select the Meeting tab and go to In Meeting (Basic)
  4. Disable the File Transfer toggle
  5. Save changes and lock the setting if needed

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.IP GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Automatic Recording Enabled fix difficulty: easy #

Disable automatic recording so meetings are not recorded without explicit consent

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Recording
  3. Disable the Automatic recording toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Auto Save Meeting Chats fix difficulty: easy #

Disable auto-saving of meeting chats to avoid retaining sensitive information

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Auto saving chats toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Continuous Meeting Chat Enabled fix difficulty: easy #

Disable continuous meeting chat so messages do not persist beyond the session

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Continuous meeting chat toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Email Notification On Join Before Host Disabled fix difficulty: easy #

Enable email notification when participants join before the host

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Notifications
  3. Enable email notification when participants join before host
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Far End Camera Control Enabled fix difficulty: easy #

Disable far end camera control so remote participants cannot control cameras

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Far end camera control toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Host Video On By Default fix difficulty: easy #

Disable host video on by default to avoid exposing video without consent

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Host video toggle under Schedule Meeting
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Guest Participant Identification Disabled fix difficulty: easy #

Enable identification of guest participants to distinguish external attendees

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Enable 'Identify guest participants in the meeting/webinar'
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Participant Video On By Default fix difficulty: easy #

Disable participant video on by default to avoid exposing video without consent

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Participants video toggle under Schedule Meeting
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Join/Leave Sound Disabled fix difficulty: easy #

Enable a sound when participants join or leave to maintain awareness

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Enable 'Play sound when participants join or leave'
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Remote Control Enabled fix difficulty: easy #

Disable remote control so participants cannot take control of another screen

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > In Meeting (Basic)
  3. Disable the Remote control toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Request To Unmute Not Required fix difficulty: easy #

Require permission to unmute participants

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Enable 'Request permission to unmute participants'
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: medium Screen Sharing Allowed For All Participants fix difficulty: easy #

Restrict screen sharing to the host only

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > In Meeting (Basic)
  3. Under Screen sharing, set 'Who can share?' to Host Only
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

severity: low Screen Share Watermark Disabled fix difficulty: easy #

Enable screen share watermark to attribute shared content

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > In Meeting (Advanced)
  3. Enable the Add watermark toggle
  4. Save changes

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.e.4 DORA (SaaS Security) DORA-9.10

More Zoom checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial