Prevent Zoombombing Using Advanced Privacy and Security Features

Zoom at St. Mary’s offers several features and options that can help you maintain the security and privacy of your Zoom classroom or meeting. Use the following tips to help prevent “Zoombombing,” where uninvited users enter your Zoom meeting and use the screen share feature to display inappropriate content.

Note: If you plan to use Zoom to host meetings that involve any type HIPAA-regulated personal health information (Telehealth), whether or not the meetings are recorded, you must use Zoom HIPAA-level security. Please contact the tsc@stmarytx.edu and request a HIPAA sub account if needed.

 

Incident Reporting:
Report instances of Zoombombing to the St. Mary’s Information Services Technical Support Center (TSC) by emailing the tsc@stmarytx.edu.

Table of Contents


Overview

Zoom is a web collaboration tool available to all St. Mary’s University students, faculty, and staff. Zoom provides high-quality audio and video, intuitive sharing and co-annotation tools, breakout rooms, whiteboarding tools, the ability to easily add content to meetings “on the fly”, and the option to download meeting recordings as MP4 files. Standard Zoom meetings support up to 300 simultaneous participants. Licenses for large meetings (up to 500 participants) and webinars (up to 3,000 participants) are available to faculty and staff by request from the St. Mary’s Zoom administrators. For more, see About Zoom at St. Mary’s.

Zoom at St. Mary’s offers several features and options that can help you maintain the integrity of your Zoom meeting or webinar. Use the following tips to help prevent Zoombombing, where uninvited users enter your Zoom meeting and use the screen share feature to display inappropriate content.

Important:
  • You shouldn’t record meetings that may involve critical data or FERPA protected information (for example, advising sessions or individual discussions with students regarding their education records, including grades). Meetings involving FERPA-protected student information and Protected Health Information (PHI) should not be stored on the Zoom cloud service or on Kaltura. If you have a requirement to record a meeting that will involve FERPA or critical institutional information, consult with Academic Technology Services on storage and retention requirements.
  • If you plan to use Zoom to host meetings that involve any type

    HIPAA-regulated personal health information (PHI), whether or not the meetings are recorded, you must use a Zoom Health account. For more information about Zoom HIPAA features, please contact Jeff Schomburg, Exec. Dir. of Academic Technology Services.

What You Can Do Before the Meeting

Before your meeting begins, consider the below options to reduce the likelihood of unwelcome or disruptive participants joining your event.

Generate a Unique Meeting ID

To join a meeting, participants provide a 9- or 10-digit ID number unique to said meeting. If one of your previous meetings was compromised, a similar disruption could happen again if you use the same ID. Consider using unique IDs instead. Although they are less convenient than using a recurring meeting ID or your personal Zoom room, unique IDs make it harder for previous disruptive participants to join future meetings. If you are posting about a meeting on a public resource (for example, a departmental website), UITS recommends generating a unique ID. To do so:

  1. Log into https://stmarytx.zoom.us.
  2. Click Schedule a New Meeting.
  3. Provide all details for your meeting.
  4. Do not select Recurring meeting, even if your meeting is part of a series.
  5. Click Save. The page will reload, and the ID should be listed to the right of “Meeting ID”.
Note:
If your meeting is part of a series, then you’ll need to schedule a new meeting for each session. You cannot change an existing meeting’s ID.

Back to top

Require Participants to Register

You can configure your meeting so individuals can’t attend unless they have registered. Participants register for meetings through a custom URL that Zoom generates for you. To register, participants must provide their first name, last name, and email address. Participants won’t be able to join unless their name and email address matches the information they initially provided when registering.

  1. Log into https://stmarytx.zoom.us.
  2. Click the name of the desired meeting.
  3. Click Edit this meeting.
  4. Scroll to the “Registration” section.
  5. Check Required.
  6. Click Save. The page will then refresh.
  7. In the “Invite Attendees” section, you should see a registration URL. To copy a default invitation template message that includes the registration URL, click Copy the invitation. In the resulting window, select Copy Meeting Invitation. You can then paste the message into an email message, Canvas announcement, etc.
    Back to top

Require a Password

  1. Log into https://stmarytx.zoom.us.
  2. Click the name of the desired meeting.
  3. Click Edit this meeting.
  4. Check Require meeting password. In the resulting text field, enter the desired password.
    Note:

    When creating meeting passwords, keep in mind that some videoconferencing equipment can only enter numbers. If some participants might connect from videoconferencing hardware instead of a computer or mobile device, set a numerical password to ensure that they can connect without issue.

  5. Click Save.
    Back to top

Require a Password for Participants Joining Via Telephone

You can require that telephone participants supply a password before joining your meeting:

  1. Log into https://stmarytx.zoom.us.
  2. Click Settings.
  3. Scroll down to find “Require password for participants joining via phone”, and then click the corresponding toggle button to enable this feature.
Note:
When you enable this feature, it is enabled for all of your meetings.

Require Participants to be Logged into a Zoom Account

You can require all participants to be logged into their Zoom accounts before accessing your Zoom meeting room. While this setting does not discriminate between institutions providing Zoom accounts (that is, it cannot restrict the meeting to accounts provided by St. Mary’s University), this is an additional precaution you can take to restrict access to your meeting.

To enable this setting:

  1. Log into https://stmarytx.zoom.us.
  2. Click Meetings.
  3. Click Upcoming Meetings (or Personal Meeting Room).
  4. If you clicked Upcoming Meetings, select the desired meeting.
  5. Click Edit this Meeting.
  6. Check the box to the left of Only authenticated users can join. After you check the box, “Sign into Zoom” will appear to the right of “Only authenticated users can join”.
  7. Click Save.
    Back to top

Turn Off Participant Video Upon Entry

You can configure your meeting room so that every participant’s video feed is disabled when first joining. However, unless you have manually disabled the user’s video feed (see Stop the participant’s video), these participants can enable their video feed once they’ve joined. To do this:

  1. Log into https://stmarytx.zoom.us.
  2. Click the name of the desired meeting.
  3. Click Edit this meeting.
  4. Scroll to the “Video” section. To the right of “Participant”, click off.
    Back to top

Mute Participants Upon Entry

You can configure your meeting room so that every participant’s audio feed is disabled when first joining. However, unless you have manually disabled the user’s audio feed (see Mute the participant), these participants can enable their audio feed once they’ve joined. To do this:

  1. Log into https://stmarytx.zoom.us.
  2. Click Meetings.
  3. Click the name of the desired meeting.
  4. Click Edit this meeting.
  5. Check Mute participants upon entry.
  6. Click Save.
Note:
If you are running a webinar, your participants won’t be able to unmute themselves.

Enable the Waiting Room

If you enable the waiting room, participants won’t be able to join the meeting until you admit them individually. This option works best for meetings with fewer numbers of attendees. To enable the waiting room:

  1. Log into https://stmarytx.zoom.us.
  2. Click Meetings.
  3. Click the name of the desired meeting.
  4. Click Edit this meeting.
  5. Check Enable waiting room.
  6. Click Save.
    Back to top

Ensure File Transfers are Disabled

  1. Log into https://stmarytx.zoom.us.
  2. Click Settings.
  3. In the “In Meeting (Basic)” section, ensure that File transfer is toggled off.
    Back to top

Ensure Removed Participants are Unable to Rejoin Meetings

  1. Log into https://stmarytx.zoom.us.
  2. Click Settings.
  3. In the “In Meeting (Basic)” section, ensure that Allow removed participants to rejoin is toggled off.
    Back to top

What You Can Do During a Meeting

To secure settings for a meeting that you’ve started, or if you need to handle a disruption (if someone has interrupted the session, for example), you have several options.

Note:

If you’re using a Windows, macOS, or Linux Zoom desktop client, you can use Zoom’s Security feature in your meeting controls to quickly set some options for a meeting you’ve started; these include locking the meeting, enabling a waiting room, disabling screensharing, and more. For details, see In-meeting security options .

zoom icon that looks like a shield and has the word security below it

Designate a Co-Host

Depending on the size of your meeting, it may be difficult to both run your session and moderate your participants. One or more co-hosts can help with these responsibilities while you conduct your meeting. For details about what co-hosts can and cannot do, see Enabling and adding a co-host .

To promote a participant to co-host:

  1. In the Zoom meeting window, click Manage Participants. A tab called Participants should appear on the right.
  2. Hover over the name of the desired co-host and select More.
  3. Click Make Co-Host.
    Back to top

Prevent Participants from Screen Sharing

  1. In the Zoom meeting room window, click the arrow next to “Share Screen”, and then select Advanced Sharing Options.
  2. Under “Who can share?”, select Only Host.
    Back to top

Mute the Participant

To mute a participant:

  1. In the Zoom meeting room window, click Manage Participants. A tab called Participants should appear on the right.
  2. Hover over the name of the desired participant and select More.
  3. Click Mute.
    Back to top

Stop the Participant’s Video

To disable a participant’s video feed:

  1. In the Zoom meeting room window, click Manage Participants. A tab called Participants should appear on the right.
  2. Hover over the name of the desired participant and select More.
  3. Click Stop Video.
    Back to top

Remove the Participant

To remove a participant from the meeting:

  1. In the Zoom meeting room window, click Manage Participants. A tab called Participants should appear on the right.
  2. Hover over the name of the desired participant and select More.
  3. Click Remove.
    Back to top

Lock the Meeting

Once a meeting is locked, no one else can join. To lock your meeting:

  1. In the Zoom meeting room window, click Manage Participants. A tab called Participants should appear on the right.
  2. Click More in the bottom right.
  3. Click Lock Meeting.
    Back to top

Note: Some of these materials are derivatives from Indiana University’s “Keep Teaching” resource, as well as other universities’ shared content.  We deeply thank everyone for their contribution. Use and reuse of content are under a Creative Commons Attribution-NonCommercial 4.0 International License.