Overview

The Zoom integration uses the Zoom Reports API and Operation Logs API to ingest:

  • User sign-in attempts and SSO activity
  • Account, user, and group setting changes
  • Meeting and webinar configuration changes
  • App marketplace installations and authorizations

Prerequisites

  • A Zoom Pro, Business, Education, or Enterprise account.
  • Account Admin or Owner privileges to create a Server-to-Server OAuth app.

Step 1: Create a Server-to-Server OAuth app in Zoom

  1. Sign in to the Zoom App Marketplace at https://marketplace.zoom.us.
  2. Click Develop → Build App → Server-to-Server OAuth → Create.
  3. Name it Atatus SIEM.
  4. On the App Credentials page, copy the Account ID, Client ID, and Client Secret.
  5. On the Scopes page, add (read-only):
    • report:read:admin
    • user:read:admin
    • account:read:admin
  6. Activate the app.

Step 2: Connect Zoom in Atatus

  1. In Atatus, go to Security → Cloud SIEM → Integrations.
  2. Locate the Zoom card and click Connect.
  3. Fill in the form:
Field Description Example
Account ID Zoom Account ID from the app credentials. abcDEF123...
Client ID OAuth Client ID. abc123...
Client Secret OAuth Client Secret. ••••••••
Poll Interval (minutes) How often to fetch new events. 5
Enabled Turn collection on. true
  1. Click Connect.

Verification

  • The Zoom card shows Configured.
  • Audit events appear in Security → Cloud SIEM → Audit Logs → Events with source zoom.