TL;DR:
- Default settings on Zoom, Teams, and Google Meet are designed for ease of use, not security — a handful of configuration changes significantly reduce your exposure
- Meeting bombing, unauthorised recording, and accidental sharing of sensitive information are the three most common problems small businesses encounter
- The risks are real but the fixes are straightforward: waiting rooms, password protection, host-controlled recording, and careful screen sharing settings take about 30 minutes to configure
Video calls are now where small businesses have their most sensitive conversations — client negotiations, financial reviews, HR discussions, legal matters. Unlike email, there’s often no written record of what was said, and the person on the other end isn’t always who you think they are. The platforms themselves are broadly secure, but the default configurations prioritise frictionless access over security. That’s a reasonable trade-off for casual use; it’s the wrong one for a business call.
This guide covers the settings that matter on the three dominant platforms — Zoom, Microsoft Teams, and Google Meet — and what can go wrong if you leave them at defaults.
The Three Real Risks
Meeting bombing — uninvited participants joining a call, either by guessing a meeting ID or obtaining a shared link. In 2020 this was a novelty; now it’s occasionally deliberate, especially for calls where the link was shared publicly or forwarded carelessly.
Unauthorised recording — participants recording your meeting without your knowledge. The platforms typically notify everyone when recording starts, but third-party tools and screen-recording software can capture audio and video silently.
Information leakage — the wrong document appearing on a screen share, a whiteboard with confidential figures visible in the background, or a participant accidentally sharing their entire screen (including open tabs and notifications) rather than just the application.
None of these require a sophisticated attacker. Most happen through carelessness or misconfiguration.
Zoom: Settings That Matter
Log into your Zoom account at zoom.us, go to Settings → Security and Settings → In Meeting (Basic).
Enable Waiting Room for all meetings. New participants land in a holding room where the host manually admits them. This is the single most effective control against uninvited guests. It’s not the default on all account types — check and enable it. For team meetings with known participants, you can use the “Allow participants to join before host” setting sparingly.
Require a passcode for all meetings. Under Settings → Security, enable “Require passcode for all meetings scheduled going forward.” Existing recurring meeting links don’t automatically inherit this — review them. Passcodes embedded in the join URL are fine for convenience; the key is that random scanning of meeting IDs won’t work.
Disable join before host. If a participant joins before you start the meeting, they can talk amongst themselves — or, more problematically, you may not realise the call is already running when you have a pre-call conversation. Under Settings → In Meeting (Basic), disable “Allow participants to join before host.”
Control screen sharing. Set “Who can share?” to “Host only” as the default. Individual participants can be granted sharing rights during the call. This prevents a participant from accidentally (or deliberately) sharing their screen. Under Settings → In Meeting (Basic), set Screen sharing → “Who can share?” to “Host only.”
Lock the meeting once everyone has joined. During a call, use Manage Participants → More → Lock Meeting once all expected participants are in. This prevents anyone else from joining even if they have the link and passcode.
Recording controls. Under Settings → Recording, disable “Local recording” to prevent participants from saving recordings to their own machines without your knowledge. Cloud recording under your control is preferable — you have a record and control who can access it.
Microsoft Teams: Settings That Matter
Teams configuration is split between the Teams Admin Center (admin.teams.microsoft.com, for account owners) and individual meeting options (set per-meeting by organisers).
Lobby settings. In the Teams Admin Center → Meetings → Meeting policies, set “Who can bypass the lobby?” to “Only organizers and co-organizers” or “Only invited users.” This is the equivalent of Zoom’s waiting room — participants wait in the lobby until admitted. The default (“People in my organization and guests”) may be appropriate for internal meetings but is too permissive for external client calls.
Set meetings to not allow external forwarding. In meeting options, disable “Allow forwarding.” This prevents participants from forwarding the meeting link to others without your knowledge.
Recording permissions. In the Teams Admin Center → Meetings → Meeting policies, configure “Who can record” to “Organizers and co-organizers.” This prevents all participants from initiating recordings. Meeting transcription (via Copilot and Teams Premium) should be reviewed separately — automatic transcription may capture sensitive content you didn’t intend to record.
Disable anonymous join. In the Teams Admin Center, set “Allow anonymous users to join a meeting” to Off for external-facing meetings. Anonymous users appear with no identity in the participant list — you can’t verify who they are.
Screen sharing. In meeting options for sensitive calls, set “Who can present?” to “Specific people” and select only those who need to present. This prevents accidental sharing.
Google Meet: Settings That Matter
Google Meet is administered through the Google Admin Console (admin.google.com) for Workspace accounts. Individual meeting hosts also have options during calls.
Knock before entering (the Meet equivalent of a waiting room). In Google Admin Console → Apps → Google Workspace → Google Meet → Safety settings, enable “Require host approval to join.” Participants outside your organisation see a “Knock” button and wait for host approval. This is equivalent to Zoom’s waiting room and Teams lobby.
Prevent participants from rejoining after removal. In Safety settings, enable “Prevent removed participants from rejoining.” Without this, a removed participant can simply rejoin.
Host management. By default, only the meeting host and co-hosts can mute or remove participants, end the meeting for all, or lock the meeting. Under the meeting’s safety settings (lock icon during the call), confirm these controls are host-only.
Recording permissions. In the Admin Console under Meet settings, configure “Allow recording” to restrict who can record. For Google Workspace Business Starter, recording requires manual initiation — consider who in your organisation should have this permission and remove it from those who don’t need it.
Limit external participants. For sensitive internal meetings, you can restrict joining to people within your organisation. In Admin Console → Google Meet → Safety settings, enable “Only people in [your domain] can join meetings.” Apply this as a policy for meetings created in your domain.
Practical Habits That Matter More Than Settings
Use calendar invites, not persistent room links. Tools like “My Personal Meeting Room” with a fixed URL are convenient but risky — anyone who’s ever had the link can join at any time. Use scheduled meetings with unique IDs for anything sensitive.
Verify identity before discussing confidential matters. If you receive a call request from someone unexpected, call them back on a known number before proceeding. Impersonation of suppliers, clients, or colleagues is a documented fraud vector.
Brief participants on recording. Before starting any recording, confirm all participants know and consent. This isn’t just good practice — in the UK, recording a conversation without all parties’ knowledge may violate GDPR and data protection obligations.
Be aware of your background. A whiteboard with figures, documents on a desk, or a second screen visible to a camera can leak information. Use virtual backgrounds for external calls or ensure your physical environment is clear of sensitive materials.
Review recurring meetings. Many businesses have recurring meeting links that have accumulated over years, with dozens of historical participants who may no longer need access. Audit and regenerate these links periodically.
A 30-Minute Configuration Audit
If you’re responsible for security in your business, block 30 minutes to:
- Log into each platform’s admin console and check the organisation-wide defaults against the settings above
- Review any recurring meeting series and update their security settings
- Ensure your most sensitive recurring meetings (board calls, financial reviews, client account calls) all have waiting rooms/lobbies enabled and are using unique meeting IDs
The platforms are fundamentally secure. Most video conferencing incidents come from misconfiguration or careless link sharing — both of which are straightforward to address.