Skip to content

Zoom access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Zoom, Black Cat runs 8 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Zoom connector needs.

Checks (8)

severity: medium Inactive User fix difficulty: easy #

Deactivate or remove inactive users in Zoom User Management

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to User Management > Users
  3. Search for and select the inactive user
  4. Click Deactivate or Delete to revoke access
  5. Confirm the action

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-308.a3 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Admins fix difficulty: medium #

Reduce admin role members by demoting unnecessary administrators to standard roles

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to User Management > Role Management
  3. Open the Admin or Owner role and review the member list
  4. Select members that do not require admin privileges
  5. Change their role to a standard member role and save

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high SSO Not Enforced fix difficulty: medium #

Enable SSO sign-in enforcement under Advanced Security settings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Advanced > Security
  3. Locate the Sign In Methods section
  4. Enable the SSO enforcement toggle
  5. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high Encryption Not Required For Third-Party Endpoints fix difficulty: easy #

Require encryption for 3rd party endpoints (H.323/SIP)

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Enable 'Require encryption for 3rd party endpoints (H.323/SIP)'
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.24 SOC 2 Type II CC6.7 CIS Controls v8 CIS-03.10 NIST CSF 2.0 PR.DS-02 GDPR (SaaS Security) GDPR-32.1a HIPAA (SaaS Security) HIPAA-312.e NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

Stop embedding the meeting passcode in the join link

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Security
  3. Disable 'Embed passcode in invite link for one-click join'
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Join Before Host Allowed fix difficulty: easy #

Disable join before host so participants cannot enter meetings unattended

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Meeting
  3. Disable the Join before host toggle
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high No Password For Instant Meetings fix difficulty: easy #

Require a passcode for instant meetings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Security
  3. Enable 'Require a passcode for instant meetings'
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: high No Password For PMI Meetings fix difficulty: easy #

Require a passcode for Personal Meeting ID (PMI) meetings

  1. Log in to the Zoom admin portal at https://zoom.us/account
  2. Navigate to Account Management > Account Settings > Security
  3. Enable 'Require a passcode for Personal Meeting ID (PMI)'
  4. Save changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.8.9 SOC 2 Type II CC6.1 CIS Controls v8 CIS-04.1 NIST CSF 2.0 PR.AA-01 GDPR (SaaS Security) GDPR-25.1 HIPAA (SaaS Security) HIPAA-308.a1 NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Zoom checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial