Overview
The Zoom integration uses the Zoom Reports API and Operation Logs API to ingest:
- User sign-in attempts and SSO activity
- Account, user, and group setting changes
- Meeting and webinar configuration changes
- App marketplace installations and authorizations
Prerequisites
- A Zoom Pro, Business, Education, or Enterprise account.
- Account Admin or Owner privileges to create a Server-to-Server OAuth app.
Step 1: Create a Server-to-Server OAuth app in Zoom
- Sign in to the Zoom App Marketplace at https://marketplace.zoom.us.
- Click Develop → Build App → Server-to-Server OAuth → Create.
- Name it
Atatus SIEM. - On the App Credentials page, copy the Account ID, Client ID, and Client Secret.
- On the Scopes page, add (read-only):
report:read:adminuser:read:adminaccount:read:admin
- Activate the app.
Step 2: Connect Zoom in Atatus
- In Atatus, go to Security → Cloud SIEM → Integrations.
- Locate the Zoom card and click Connect.
- Fill in the form:
| Field | Description | Example |
|---|---|---|
| Account ID | Zoom Account ID from the app credentials. | abcDEF123... |
| Client ID | OAuth Client ID. | abc123... |
| Client Secret | OAuth Client Secret. | •••••••• |
| Poll Interval (minutes) | How often to fetch new events. | 5 |
| Enabled | Turn collection on. | true |
- Click Connect.
Verification
- The Zoom card shows Configured.
- Audit events appear in Security → Cloud SIEM → Audit Logs → Events with source
zoom.
+1-415-800-4104