One package, one set of switches, and Zoom lands on a thousand computers already configured: single sign-on, auto-update, the security team's bans. The user opens the app and works.
Zoom Workplace for Windows ships as an MSI package that is installed and configured from the command line or by a software distribution system. Zoom describes three ways: MSI with switches, an Active Directory administrative template for group policies, and direct registry keys. Packages come in 64-bit, 32-bit, ARM64 and a separate VDI build, all from the admin portal.
There are two kinds of switch. zConfig sets a setting and locks it: the user cannot change it. zRecommend sets a default and leaves the right to change it. If one parameter is given both ways, zConfig wins. One package therefore describes both the mandatory rules and the sensible defaults.
macOS takes the same approach: a plist file with settings and an installer for IT administrators. Phones and tablets get their settings through MDM or MAM. Above all of it stands Zoom Device Manager: a setting locked there outranks both GPO and MSI.
A hundred computers can still be installed by hand. Configuring them identically and keeping them identical cannot.
The package goes out through SCCM, Intune or a group policy. On Monday the user sees a ready Zoom with sign-in through the corporate directory.
The security team's bans are baked in with zConfig switches. They cannot be removed from the settings menu and do not depend on an employee's care.
Enterprise Auto Update policies set when and which versions are installed. The fleet does not drift, and a new version is tested before the mass update.
Packages, switches, channels and the order of priority
64-bit, 32-bit, ARM64 and a VDI package. All are downloaded from the Zoom admin portal and installed with the same switches.
Mandatory settings: disable sign-in with third-party accounts, forbid remote control, set the proxy. The user does not see them as a choice.
Defaults that can be changed: audio auto-adjust, the default device, behaviour at start-up. A sensible start without coercion.
The zSSOHost switch with your account address, and the app goes straight to corporate sign-in. No Zoom passwords for employees.
Zoom no longer supports the old silent-update switches. In their place are Enterprise Auto Update policies aligned with Zoom's release schedule.
Disabling remote control, annotation and whiteboard, default audio and camera devices, hardware acceleration. All in one package.
Proxy, ports, bandwidth limits. The package knows about your network before the first launch.
An administrative template for group policies, deployment through SCCM, and for Intune Zoom documents a step-by-step procedure.
When settings conflict they apply in this order: ZDM locked, GPO zConfig, MSI zConfig, portal restrictions, user choice, ZDM unlocked, GPO zRecommend, MSI zRecommend, portal. Zoom advises managing each setting by one method.
The MSI build of the Zoom Workplace app for Windows from the admin portal, administrator rights on the computers. No separate licence: this is a way of installing, not a product.
Wherever there are more computers than engineers
A thousand desktops, single sign-on, security bans. The package is built and tested on a pilot group, then rolled out through SCCM.
One package for every site. Network and proxy settings differ, switches differ, the installation is the same.
Remote control, file transfer, sign-in with personal accounts are closed with zConfig. The auditor sees the package switches, not promises.
Sales with the full set, the call centre with a reduced one, meeting rooms with their own. Three sets of switches, one installer.
A new version goes to a pilot group first under the auto-update policy, then to everyone. Rollback by the same mechanism.
Collecting requirements from IT and security, building the switch set, testing on a pilot, documenting the package, handing over to the administrator. Then support in Russian.
The Zoom client had to be deployed and configured on more than 50,000 workstations on schedule.
We'll give you a remote demo Monday to Friday, 10:00–16:00 Moscow time, answer all your questions and provide trial access so you can explore the system yourself.
Please note: we work with legal entities only.