Table of Contents
- Before You Begin
- Scenario 1: General Public Invited to Join a Zoom Meeting
- Scenario 2: Meetings for Notre Dame Participants
- Scenario 3: Meeting with Notre Dame and Non-Notre Dame Participants
- Scenario 4: Hosting a Large Zoom Meeting
- Scenario 5: What to Do If You're Being Zoom-bombed
- Scenario 6: Protect Privacy and Intellectual Property
- Scenario 7: Sensitive and Regulated Data in Zoom
- Scenario 8: End-to-End Encryption in Zoom
Before You Begin
Zoom includes several security features to help prevent unwanted access and meeting disruption. For an overview of these features, see Managing Risk of Disruption in Zoom Meetings.
The scenarios below explain when to use common security settings, what to enable, and where to find the related instructions.
Scenario 1: General Public Invited to Join a Zoom Meeting
When to use this
Use this setup when you are hosting a public event and anyone may be invited to attend.
Recommended setting
- Require registration for the Zoom meeting.
- If you do not have technical support to help manage a public event, consider ND Studio’s Zoom Webinar Service.
Steps
- Sign in to zoom.nd.edu.
- Schedule a Zoom meeting.
- In the meeting settings, select Required next to Registration.
- Before the meeting starts, review the Zoom Security button so you are ready to manage participants during the event.
Scenario 2: Meetings for Notre Dame Participants
When to use this
Use this setup when only Notre Dame participants should be allowed to join the meeting or course.
Recommended setting
- Require participants to sign in with their Notre Dame NetID and password before joining.
Reference
For step-by-step instructions, see Create Zoom Meeting Restricted to Notre Dame Participants.
Scenario 3: Meeting with Notre Dame and Non-Notre Dame Participants
When to use this
Use this setup when most attendees are from Notre Dame, but you also need to allow a guest lecturer or a small number of non-Notre Dame participants.
Recommended setting
- Require participants to authenticate with Sign in to Zoom.
- Notre Dame participants can sign in with SSO.
- Other participants can sign in with Zoom, Google, or SSO if their institution allows it.
- Requiring sign-in helps reduce the risk of unwanted participants.
Steps
- Follow Create Zoom Meeting Restricted to Notre Dame Participants.
- In Step 3, select Sign in to Zoom instead of Notre Dame Only (Okta).
Scenario 4: Hosting a Large Zoom Meeting
When to use this
Use this setup when you are hosting a large Zoom meeting and want to reduce the chance of disruption.
Recommended setting
- Use the settings and practices in Recommended Settings for Hosting a Large Zoom Meeting and Best Practices for Hosting a Large Zoom Meeting.
- If you need tighter controls, such as hiding participant names, forcing participant audio and video off, or preventing participants from turning them back on, consider ND Studio’s Zoom Webinar Service.
References
- Recommended Settings for Hosting a Large Zoom Meeting
- Best Practices for Hosting a Large Zoom Meeting
- ND Studio’s Zoom Webinar Service
Scenario 5: What to Do If You’re Being Zoom-bombed
When to use this
Use these actions if someone is disrupting your meeting.
Recommended action
- Be familiar with the Zoom Security button before the meeting starts.
Steps
-
If a participant is sharing inappropriate content:
- Use the Zoom Security button to turn off participants’ ability to share their screen.
- Remove the participant if needed.
- Under normal settings, participants cannot share their screen without host permission.
-
If a participant is making inappropriate noise:
- Mute all participants.
- Turn off participants’ ability to unmute themselves.
- Remove the participant if needed.
-
If a participant is using chat inappropriately:
- Use the Zoom Security button to turn off participants’ ability to chat.
- Remove the participant if needed.
-
If a participant renamed themselves to something inappropriate:
- Use the Zoom Security button to turn off participants’ ability to rename themselves.
- Remove the participant if needed.
Scenario 6: Protect Privacy and Intellectual Property
When to use this
Use this guidance when you want to protect meeting privacy, reduce the chance of unauthorized recording, and help identify leaked meeting content.
Recommended setting
- Do not record audio or screen content without the host’s permission.
- As a Zoom participant, do not use software or devices outside of Zoom to record audio or screen displays.
- Do not share recorded content outside the meeting participants without the host’s explicit permission and, if the host requires it, permission from the attendees.
- If you need added protection, consider Zoom’s audio watermark feature.
Steps
- Sign in to zoom.nd.edu.
- Review Zoom’s Audio Watermark guide and enable the feature by following Zoom’s current instructions.
- If the meeting should be limited to Notre Dame participants, follow Create Zoom Meeting Restricted to Notre Dame Participants.
Scenario 7: Sensitive and Regulated Data in Zoom
When to use this
Use this guidance if your Zoom meeting may include University data.
Important restrictions
- Zoom is not approved for transmitting, displaying, or discussing data classified by the University as Highly Sensitive Information (HSI).
- Data classified by the University as Sensitive should not be transmitted, displayed, or discussed if any attendee, including Notre Dame participants, may not be authorized to access that data. If your meeting will include Sensitive data, you must have explicit permission from the appropriate Data Steward(s).
- Data classified by the University as Internal may be transmitted, displayed, or discussed only if all attendees are Notre Dame participants. If non-Notre Dame participants will attend, you must have explicit permission from the appropriate Data Steward(s) to include Internal data.
- Zoom offers specific products for some regulated use cases, such as HIPAA and FEDRAMP.
- If you need to use Zoom with these data types, contact Notre Dame Information Security.
Recommended settings
Host account settings
- Turn on Require a passcode when scheduling new meetings.
- Turn off Auto saving chats.
- Turn off File transfer.
- Set Data Center regions for meetings/webinars hosted by your account to United States only.
- Turn off Allow live streaming meetings.
Host meeting settings
- Use a generated meeting ID instead of your Personal Meeting ID (PMI).
- Turn on Require meeting passcode.
- Set Audio to Computer Audio.
- Turn off Join before host.
- Turn on Waiting Room.
- Turn on Only authenticated users can join.
- Use Notre Dame SSO if all attendees are Notre Dame participants.
- Use Sign in to Zoom if participants outside Notre Dame need to join.
- Do not record the meeting.
- End-to-end encryption is available. See Scenario 8 and KB0021824.
In the meeting
- Make sure the host knows how to use the Security button.
- Once everyone has arrived, lock the meeting.
- Use headphones to reduce the chance that others can overhear the discussion.
- Meet in a private location to reduce the risk of shoulder surfing.
Scenario 8: End-to-End Encryption in Zoom
When to use this
Use end-to-end encryption (E2EE) when you need added privacy and data protection and can accept some feature limits.
Recommended setting
- Enable E2EE only if all participants can join from the Zoom desktop client, mobile app, or Zoom Rooms.
Steps
- Review KB0021824 for instructions on how to enable E2EE.
- Confirm that all participants can join from a supported Zoom app or device before you turn it on.
- Review the feature limits below before using E2EE for a meeting.
Feature limits
Enabling E2EE disables these features:
- Join before host
- Cloud recording
- Live streaming
- Live transcription
- Breakout Rooms
- Polling
- Meeting reactions*
- 1:1 private chats*
*Note: As of version 5.5.0 for desktop, mobile, and Zoom Rooms, these features are supported in E2EE meetings.
Users cannot join by telephone, SIP/H.323 devices, on-premise configurations, the Zoom web client, third-party clients leveraging the Zoom SDK, or Lync/Skype clients because those endpoints cannot be encrypted end to end.
Additional End-to-End Encryption (E2EE) info
See Additional End-to-End Encryption (E2EE) info:
- Zoom’s E2EE uses public key cryptography. The keys for each meeting are generated by participants’ machines, not by Zoom’s servers. Encrypted data relayed through Zoom’s servers cannot be read by Zoom because Zoom’s servers do not have the decryption key.
- E2EE is best when you want stronger privacy and added protection for meeting content. However, some Zoom features are limited when E2EE is enabled, so you should decide whether you need those features before turning it on.
- By default, Zoom meetings and webinars use AES 256-bit GCM encryption for audio, video, and application sharing in transit between Zoom applications, clients, and connectors. In meetings without E2EE, audio and video are not decrypted until they reach recipients’ devices, but the meeting keys are generated and managed by Zoom’s servers. In meetings with E2EE enabled, nobody except the participants has access to the encryption keys used for the meeting.