Governance guide

How to govern Zoom

A step-by-step guide to governing Zoom with Rencore: detect with 23 policies, review with 12 reports, and remediate with 2 automations.

Definition

Governing Zoom means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Zoom with 23 pre-built policies, 12 reports, and 2 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.

Steps

  1. Inventory Zoom

    Connect Zoom and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Zoom to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Zoom reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Recommended Zoom policies

Grounded in the Rencore catalog. See the full Zoom catalog on the Zoom connector page.

  • Meeting reachable without host screening

    Meetings without a waiting room admit anyone with the link, raising the likelihood that a weakness is exploited

    Severity: High
  • Meeting joinable with link alone

    Meetings without a passcode are reachable by anyone with the link, raising exploitation likelihood

    Severity: High
  • Recording publicly reachable

    Recordings with a public share URL are reachable by anyone with the link, raising leakage likelihood

    Severity: High
  • User holds administrative privileges

    Admin users have a wide blast radius, raising the likelihood that any weakness is exploited

    Severity: High
  • Zoom meetings without password protection

    Detects scheduled meetings that do not require a passcode to join

    Severity: High
  • Zoom recordings shared externally

    Detects cloud recordings with external/public sharing enabled

    Severity: High
  • Zoom user disabled in Entra ID

    Detects Zoom users whose corresponding Entra ID account is disabled

    Severity: Medium
  • Unused Zoom licensed users

    Detects licensed users with no login activity in the last 30 days

    Severity: Medium
  • Stale Zoom recordings older than 90 days

    Detects cloud recordings older than 90 days

    Severity: Medium
  • External participants in Zoom meetings

    Detects meeting participants who are not internal users

    Severity: High
Explore the full Zoom governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern