Docs

BaseLock for Zoom

How to add BaseLock to your Zoom account, what it checks, and how to remove it.

BaseLock Security Advisor watches the accounts you already use and tells you, in plain words, when something leaves you open. For Zoom, it checks whether your meeting settings let someone who only has the link, or only the meeting number, into your meetings.

It only ever reads. BaseLock asks Zoom for two read-only permissions and never for permission to change a setting, so it cannot turn anything on or off in your Zoom account, and nor could anyone who stole its access.

The Zoom connection is available on every BaseLock plan, including the free Advisor plan, and checking it does not use your Advisor allowance.

Adding the app

You connect Zoom from BaseLock, not from the Zoom App Marketplace.

  1. Sign in to BaseLock and open Advisor Connectors from your dashboard.
  2. Find Zoom, by searching or under the Meetings category, and select it. The panel that opens lists what BaseLock reads.
  3. Choose Connect Zoom. You are taken to Zoom, where you sign in if you are not already.
  4. Zoom shows the permissions the BaseLock Security app asks for:
    • user:read:settings, to read your own meeting settings;
    • user:read:user, to read your Zoom profile, which BaseLock uses only to label the connection with the account it belongs to.
    Choose Allow.
  5. You return to the Connectors page, and the Zoom card reads Connected.

Using the app

There is nothing to do day to day. BaseLock checks on its own.

Once connected, BaseLock reads your Zoom meeting settings automatically, once a day. It looks at four settings, each one a way for someone who has only the link or the meeting number to get in:

  • Waiting Room: whether it is off, so people join without being let in.
  • Meeting passcode: whether new meetings you schedule can be joined without a passcode.
  • Join before host: whether people can open your meeting before you arrive.
  • Personal Meeting ID: whether your scheduled meetings all reuse your Personal Meeting ID, which never changes.

BaseLock reads your own user settings. It does not read the settings an administrator sets for a whole Zoom account, and it never reads your meetings, recordings, chats or contacts.

When a setting is risky, BaseLock tells you the way your other BaseLock alerts reach you, by email or text, and records it in your notifications. It tells you once per setting, not on every check. When you change the setting in Zoom, the next check sees that it is fixed.

What a finding looks like

Each finding says what is wrong and the one change that fixes it.

Your Zoom waiting room is off

Anyone who has the link to one of your meetings joins it straight away, without you letting them in.

What to do: In Zoom, open Settings, then Meeting, and turn Waiting Room on.

Your new Zoom meetings do not require a passcode

Meetings you schedule from now on can be joined with the meeting number alone, and meeting numbers get forwarded, posted and guessed.

What to do: In Zoom, open Settings, then Meeting, and turn on Require a passcode when scheduling new meetings.

People can start your Zoom meetings without you

Join before host is on, so anyone with the link can open the meeting and be in the room before you arrive.

What to do: In Zoom, open Settings, then Meeting, and turn Join before host off.

Your Zoom meetings all use your personal meeting room

Scheduled meetings use your Personal Meeting ID, which never changes. Anyone who has been in one meeting with you has the link to every meeting you hold.

What to do: In Zoom, open Settings, then Meeting, and turn off Use Personal Meeting ID when scheduling meetings.

A text is shorter and never includes anything from your Zoom account, for example: "BaseLock: your Zoom waiting room is off, so anyone with the link joins without being let in. Details: https://getbaselock.com/connectors/"

Removing the app

Either way works. Removing the app from Zoom also deletes what we found. Disconnecting from BaseLock keeps what we found in your alerts until you delete your BaseLock account.

From BaseLock

  1. Open Advisor Connectors and select Zoom.
  2. Choose Disconnect.

BaseLock revokes its access at Zoom, deletes the access token it held, and deletes every finding the Zoom connection produced. It takes effect at once.

From Zoom

  1. Sign in to the Zoom App Marketplace at marketplace.zoom.us.
  2. Open Manage, then Added Apps.
  3. Find BaseLock Security and choose Remove.

Zoom stops BaseLock's access straight away. On BaseLock's next check, within a day, the access no longer works: the Zoom card on the Connectors page reads Needs reconnecting, and we tell you that we have stopped watching that account. To delete the findings as well, choose Disconnect on the Connectors page.

Your data

What BaseLock keeps from Zoom, and for how long.

  • Your settings: read on each check and not stored. BaseLock keeps only the findings described above, until you remove the app from Zoom or delete your BaseLock account.
  • The access Zoom grants: stored encrypted, used only to read the two things above, and revoked and deleted when you disconnect.
  • The account label: the email address of your Zoom account, shown on the Connectors page so you can tell which account is connected.

The Privacy Policy covers connectors in full, including what happens when you delete your BaseLock account.

Get help

Two ways to reach us, both answered by a person.

Chat

The chat bubble on this site and in your dashboard.

Email Support

support@getbaselock.com