cancel
Showing results for 
Search instead for 
Did you mean: 

Disallow bots to enter meetings

bobmagrega
Newcomer
Newcomer

Hi! I'd like to know if it's possible to disallow programmed participants to join meetings? I've been experiencing frequent bot attack on my meetings. I think allowing participants to join only through zoom app would be preferable it this case.

4 REPLIES 4

lancetlc
Zoom Employee
Zoom Employee

Hey @bobmagrega,

 

Thanks for sharing your concern. Please follow this helpful guide in securing your meetings: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0063018 

osintmi
Newcomer
Newcomer

Have you come up with any solutions?  We hold daily meetings with over 100 participants and while not frequent we have had several bot attacks.  We experience the chat bombing, bots getting in from the waiting room without a cohost letting them in,  videos, and a loss of control when security cohosts are using their mouse and keyboard.  The mouse is very sluggish, and when clicking on remove a participant nothing happens or it takes a long time for it too happen.  I appreciate any tips you might have learned.

Check out my other comment

 

TL;DR: Ask Zoom Support to block SDK Keys.

marafinom
Contributor I
Contributor I

Edit: I've seen other people say that the waiting room is ineffective against some of these bots, so definitely prioritize banning the SDK key.

 

I know this is old, but I wanted to shed some light for anyone else who may need help. Here's the issue: a lot of these bots can just accept a Zoom link and join as a guest, meaning that it can bypass passwords, domain bans, Marketplace approval, CAPTCHA and Outlook blocks. 

 

While waiting rooms have caught a few bots, the best way to prevent this going forward is by having Zoom Support delete the SDK Key of the apps going forward, something that cannot be done by a standard account admin. Support has gone back and forth on whether or not they need a specific example instance of the bot, but here is the info I usually provide when blocking: 

 

Bot Company, Website, Display Name(s), Client, Meeting ID, Date, Join Time

 

With these new technologies, this is always going to be a game of whack-a-mole, but I hope these tips help.