Settings before the start, the Security menu during the meeting, co-host rights, what to do about an intruder, reports and the dashboard afterwards.
The host of a Zoom meeting decides who joins, who speaks, who shares the screen and who records. There are three sets of tools. Before the meeting: account settings, the waiting room, a passcode, sign-in for authenticated users only. During the meeting: the "Security" menu in the bottom bar and the participants list. There anyone can be muted, renamed, sent to the waiting room or removed. After the meeting: reports on who was there and for how long. On Business and above there is also the dashboard.
One rule: a closed meeting is protected before it starts, not when an intruder is already inside. Below, in order.
| Action | Host | Co-host | Participant |
|---|---|---|---|
| Admit from the waiting room, remove participants | yes | yes | no |
| Mute and stop video for others | yes | yes | no |
| Allow or forbid screen sharing | yes | yes | no |
| Lock the meeting | yes | yes | no |
| Appoint a co-host | yes | no | no |
| Allow a participant to record locally | yes | no | no |
| Open breakout rooms | yes | yes, if allowed | no |
| Record to the cloud | yes | yes | no |
| End the meeting for all | yes | no | no |
A co-host is needed at any meeting of more than ten people. While the host speaks, the co-host admits latecomers. Mutes someone's humming microphone. Reads the chat. Appointed during the meeting: participants list, name, "More → Make co-host". In advance, before the meeting, an alternative host is appointed: they can start the meeting if the host is absent.
If an assistant schedules meetings for a manager, they do not need their own licence: that is what scheduling privilege is for.
Most parameters are set when scheduling the meeting in the account on zoom.us, section "Meetings", or in the app by clicking "Schedule".
The host's Personal Meeting ID is permanent. Whoever learned it once will join any next meeting. For external meetings choose "Generate automatically".
On by default and embedded in the link, so the participant enters nothing. If the link may leak, switch off embedding the passcode in the link in the account settings: then the code has to be typed by hand.
The participant lands in a waiting area. The host admits them by hand, one by one or all at once. You can send only guests to the waiting room, that is those not from your domain. How it looks is in the waiting room article.
Only those signed in to a Zoom account are admitted. On Business the list can be narrowed to your company's domains. Works on Pro and above. The most reliable way for internal meetings.
Otherwise participants start the meeting without you, and there is no one to protect it.
for meetings with an external audience: you see applications before the start and approve them by hand.
How to fill in the scheduling form step by step is in the meeting scheduling guide. The security settings at scheduling are covered in more detail in Security in Zoom conferences. Part 1.
In the bottom bar the host and co-host have a button with a shield, "Security". Behind it are all the actions needed when something has gone wrong.
| Menu item | What it does | When it is needed |
|---|---|---|
| Lock meeting | No one else joins, even with the link and passcode | Everyone expected has arrived |
| Enable waiting room | New participants wait for admission | The link went wider than planned |
| Hide profile pictures | Names instead of avatars | An external meeting, other people's pictures |
| Allow participants to: share screen | Switches sharing on or off for everyone | Off by default at external meetings |
| Allow participants to: chat | Whom they can write to: everyone, the host only, no one | A large meeting where the chat turns into a forum |
| Allow participants to: rename themselves | Forbids changing the name | You need to see real names |
| Allow participants to: unmute and start video | Participants cannot switch themselves on | A lecture, a talk |
| Allow participants to: annotate on shared content | Drawing over the screen | Off if strangers are drawing |
| Suspend participant activities | Switches everything off at one click: video, audio, chat, sharing, rooms; the meeting is locked | An intruder is already inside |
| Remove participant | The participant leaves and cannot return by the same link | A troublemaker |
| Report | A complaint to Zoom about a participant with a screenshot attached | After removing a troublemaker |
The items do not cancel each other; they can be switched on one at a time. The usual order for an external meeting: screen sharing for the host only, chat for everyone, waiting room on. When everyone expected has gathered, the meeting is locked.
The "Participants" button opens the list. At the bottom are two buttons for everyone at once: "Mute all" and "More". Under "More" are "Ask all to unmute", "Play sound when someone joins or leaves" and a ban on participants unmuting themselves. Hover over a name, and a menu for one person opens:
Someone else's microphone cannot be switched on, only requested.
For example, add the company to an external participant's name.
The person is not removed but temporarily out of the meeting. For example, while something they are not supposed to hear is being discussed.
There is one host. After handing over the role you become a participant.
Locally, to the participant's computer, for one meeting. Cloud recording is never available to participants. How recording works is in the recording guide.
Pinning changes the view only for you; spotlight puts the person in the main window for everyone.
The participant leaves and cannot return by this link. In the account settings you can allow removed participants to rejoin.
For group work there are breakout rooms: the host distributes participants among rooms, moves between them and brings everyone back at one click.
A procedure for one minute, no more.
Everything goes dark: video, audio, chat, sharing, rooms. The meeting is locked.
through the participants list or in the same dialog.
them to Zoom with a screenshot attached; Zoom blocks such accounts.
switch video and audio on, open the chat again.
change the link: do not hold the next meeting under the same ID, switch on the waiting room or authenticated users only.
The intruder did not "hack" Zoom. They got the link. It was forwarded, posted in an open chat or published on a social network together with the invitation. That is why protecting a closed meeting starts before it begins, in the first section. How it works during the meeting step by step is in Security in Zoom conferences. Part 2.
At a webinar attendees have neither video nor a microphone, and an intruder does less harm there. The question is different: how to keep out those who have not registered, and how to stop the link being passed on. Ordinary registration does not protect against this. What protects is sign-in for authenticated users only through the company's single sign-on server: one invitation, one sign-in. How to set it up is in the article on controlling webinar attendees, and the whole webinar preparation procedure in the webinar guide.
Everything that travels between participants and Zoom is encrypted by default, and the host needs to do nothing for it: how encryption by default works. For meetings whose content must not be accessible even to Zoom there is end-to-end encryption: the keys live on the participants' devices. The price: in such a meeting cloud recording, transcription, joining from a browser and by phone do not work. Participants join only from the app.
Against leaks by screenshot there are watermarks. Visible: the viewer's email is shown over the shared screen. Audio: an inaudible participant mark is embedded in the recording. They are switched on by the administrator in the account settings.
In the account on zoom.us, section "Reports", the account owner and administrator on any paid plan can see how the company uses Zoom. Details of a meeting appear within half an hour of its end.
| Report | What it shows | Who finds it useful |
|---|---|---|
| Usage | Every meeting: host, date, duration, number of participants | The manager |
| Meeting participants | Who joined, when, when they left, how many minutes they stayed | Training, HR, acceptance of work |
| Active and inactive hosts | Who uses the licence and who does not | Whoever pays for the licences |
| Registrations and polls | Answers to the registration form, poll results | Marketing |
| Cloud recordings | How much space is used, which recordings were created | The administrator |
| Operation logs | Which administrator changed what in the settings | The security team |
| Sign-in and sign-out | Who signed in to the account and from which device | The security team |
The participants report answers the question "who was at the meeting". It is more accurate than memory. The report types are covered in more detail in the article on statistics and reports.
The dashboard, also called the admin dashboard, is available on the Business, Enterprise and Education plans. It shows not what was, but what is happening now. Which meetings are running, how many participants are in them, what connection quality each one has: latency, packet loss, CPU load. The company's support team sees whose meeting is "freezing". Earlier than that person writes.
The same place has usage graphs by day: users, meetings, minutes, Zoom Rooms meeting rooms and webinars. The dashboard is described separately on the Management & Dashboard page.
The host protects their own meeting. The company's administrator sets rules for all meetings at once. This is done in the account settings on zoom.us, and every rule can be locked against changes by users:
Single sign-on and managed domains are available on Business and above. Which plan your company needs is on the buying page. During rollout we set these rules together with your IT department rather than leaving them at the defaults: a box ticked by default rarely matches the company's policy.
A recorded meeting does not only protect against distortion in retelling, the subject of our old note on recording negotiations. It itself becomes a document that has to be protected: where it lies, who sees it, when it is deleted. That is covered separately, and how permissions on a cloud recording work is in the recording guide.
The "Security" button in the bottom bar, "Lock meeting". Available to the host and co-host.
Participants list, hover over the name, "More → Remove". Or "Security → Remove participant". A removed person cannot return by the same link.
Participants list, the "Mute all" button. There you can also forbid participants from unmuting themselves.
During the meeting: participants list, name, "More → Make co-host". There can be several co-hosts.
A place where a participant waits until the host admits them. Switched on when scheduling the meeting or during it in the "Security" menu.
Not through Zoom: local recording is allowed by the host, and cloud recording is not available to participants. Recording with a third-party program is not technically blocked by Zoom, so for sensitive meetings watermarks are switched on.
Account on zoom.us, "Reports → Usage", the meeting, "Participants". Names, join and leave times and duration are shown.
The administrator's section on Business and above: running meetings, each participant's connection quality in real time, usage statistics by day.
Yes: "Security → Allow participants to → Share screen", untick it. Only the host and co-host will be able to share.
Yes, if the meeting is protected: a unique ID, a waiting room or authenticated users only, locking once everyone has gathered, and if needed end-to-end encryption and watermarks.
We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.
Please note: we work with legal entities only.