How to govern Zoom
A step-by-step guide to governing Zoom with Rencore: detect with 23 policies, review with 12 reports, and remediate with 2 automations.
Governing Zoom means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Zoom with 23 pre-built policies, 12 reports, and 2 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.
Steps
-
Inventory Zoom
Connect Zoom and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Zoom to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Zoom reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Recommended Zoom policies
Grounded in the Rencore catalog. See the full Zoom catalog on the Zoom connector page.
-
Meeting reachable without host screening
Meetings without a waiting room admit anyone with the link, raising the likelihood that a weakness is exploited
Severity: High -
Meeting joinable with link alone
Meetings without a passcode are reachable by anyone with the link, raising exploitation likelihood
Severity: High -
Recording publicly reachable
Recordings with a public share URL are reachable by anyone with the link, raising leakage likelihood
Severity: High -
User holds administrative privileges
Admin users have a wide blast radius, raising the likelihood that any weakness is exploited
Severity: High -
Zoom meetings without password protection
Detects scheduled meetings that do not require a passcode to join
Severity: High -
Zoom recordings shared externally
Detects cloud recordings with external/public sharing enabled
Severity: High -
Zoom user disabled in Entra ID
Detects Zoom users whose corresponding Entra ID account is disabled
Severity: Medium -
Unused Zoom licensed users
Detects licensed users with no login activity in the last 30 days
Severity: Medium -
Stale Zoom recordings older than 90 days
Detects cloud recordings older than 90 days
Severity: Medium -
External participants in Zoom meetings
Detects meeting participants who are not internal users
Severity: High