You're invited to Zoomtopia 2022! Our annual user conference will take place in the Americas on November 8-9 and in APAC, Japan, and EMEA on November 17.
Learn more about our hybrid event experienceEverything you need to work together, all in one place.
Explore Zoom One's Collaboration ToolsConnect virtually from anywhere with Zoom Meetings
Collaborate together with Zoom Chat
Call the world with Zoom Phone
Create and brainstorm with Zoom Whiteboard
Rich conversation analytics to improve sales
Send and receive messages and calendar invitations
Bring fluid interactions to hybrid teams with Zoom Huddles
Innovative video solutions for every meeting space.
Bring meeting spaces online with Zoom Rooms
Conference Room Connector links existing rooms to Zoom
Innovative solutions for every space
Solutions to host impactful virtual and hybrid experiences.
Find a Solution for Every EventHost hybrid and virtual events with Zoom Events
Elevate your brand with single session events powered by Zoom Sessions
Broadcast at scale with Zoom Webinars
Host and attend classes, group events, and more OnZoom
An omnichannel cloud solution optimized for video.
Engage customers with Zoom Contact Center
Deliver intelligent support with conversational AI
Zoom solutions elevate collaboration across vertical use cases.
Discover Zoom Industry SolutionsEnabling exciting new ways to teach, learn, and connect globally
Transforming client engagement and employee experiences
Improving collaboration between agencies, ministries and constituents
Connecting care, collaboration, and medical innovation
Real-time communication, anywhere in the world
Bridging the in-store and online experiences
Expert support and services for all your design, strategy, implementation, event, and hardware needs.
Global Services
Flexible subscription plans for hardware
An open platform that allows developers to build Zoom apps and integrations.
Explore over 1,500 apps in Zoom App Marketplace
Documentation for building on Zoom's platform using APIs, Webhooks, and SDKs
Resources that help developers evaluate & build with our solutions
Post your questions and get help from our developer community
Zoom Partners bring Zoom's communications platform to market through alliance, sales, and service partnerships.
Explore Zoom's technology ecosystem
Find a trusted Partner
Learn about Zoom's Partner Programs
Access marketing & sales resources
Login to the Partner Portal and click 'Learn'
Discover new ways to use Zoom solutions to power your modern workforce.
Access expert-led tutorials on Zoom products and features.
Network with other Zoom users, and share your own product and industry insights.
Get documentation on deploying, managing, and using the Zoom platform.
Keep your Zoom client up to date to access the latest features.
Download CenterDownload hi-res images and animations to elevate your next Zoom meeting.
Browse Backgrounds2022-01-18 11:32 AM
We are using Registration with auto approval in order to capture email addresses of attendees.
Unfortunately Zoom displays the passcode openly after registration, thus defeating the purpose of a passcode.
Can the passcode be removed from the post-registration page so the meeting can still be secure? Otherwise an individual can just fake a registration (use a bogus email) in order to get the passcode of the meeting.
Note that we cannot use manual approval. We specifically need to protect the passcode with Auto Approval.
Please let me know if we can close this security hole.
2022-01-18 02:42 PM
Hi @allisonr thank you for your post here on the Zoom Community! This is an interesting situation since the passcode is typically included in the registration confirmation as a convenience. Should the join URL fail for some reason the meeting ID and passcode are included in plain text so that users have a backup way into the meeting (Click Join through Zoom client, enter Meeting ID, enter Passcode). However, if you want to change the emails you can in the Zoom portal.
Under the Advanced section of the Zoom portal, Branding
Then click the "Emails" tab
Scroll down and you will see the "Registrants Confirmation Email"
This is the email template that goes out to users when they register for meetings. If you edit this template and remove the passcode field, it should remove the passcode from your meeting registration confirmations.
When editing, you can search for the word "passcode" and it will help guide you to the place(s) to remove the passcode. And on the same edit screen there is a "Restore" button on the bottom left in case you want to set things back to default and start over 🙂
Please keep in mind this support article has some information on Branding but we don't really have a way to provide sample code. We do recommend having HTML experience when editing these templates for best results https://support.zoom.us/hc/en-us/sections/200305493-Branding
If this has answered your question to your satisfaction, please click the "Accept as Solution" button below but if not please reply and we can continue the discussion. Thank you!
2022-01-18 03:31 PM
Thanks I really appreciate your response. I agree that the email needs to contain the passcode, but I also believe ONLY the email should have the passcode (so we know we're only showing it to the person who is at that email address). The issue I have is that the passcode is displayed on the webpage after you register - so even if you enter a bogus email address, or someone else's email address, you now have the passcode and we don't know who you are.
I would like to protect the passcode and not display it on the Registration Approved page.
2022-01-18 03:39 PM
@allisonr I see your point there and I appreciate you explaining how it would help with security. Our product team reviews all feature requests submitted via our feedback form https://zoom.us/feed. If you could take a few minutes to post your feedback I would highly encourage you to submit this feature!
2022-03-31 05:38 AM
I totally agree with this issue ...
As has been said in this post, if you have a Business or Enterprise account you can (through 'Branding') hide the passcode on the emails. BUT with a Free or Pro account you cannot.
So, to recap, in the email that gets sent to a participant, the ID AND the passcode are included. And this means if the email is forwarded onto others, they can simply 'Join a meeting' and manually enter the ID and passcode - and they are straight into the meeting.
And they completely bypass the normal registration process.
Note:
One way I found to stop this loophole (and I appreciate this is getting a bit complicated) is to turn 'Approval' in Registration settings to 'Manually Approve' before the meeting starts (and before anyone is in the Waiting Room).
Then, when someone tries to Join with ID and passcode they are forced to fill out the normal registration form and will only receive a confirmation email with a link IF you manually approve them.
For this to work, either you must be monitoring the list of Registrants (and refreshing your screen regularly) OR (more simply) let people know they must register before a certain time.
And an alternative to monitoring by refreshing the list of Registrants is to also turn on this ...