# Google Meet Security Best Practices for Google Workspace Admins > A CISO and Workspace admin guide to locking down Google Meet: Quick access and knocking, authenticated and same-org joins, moderation, dial-in, recording and Drive retention, Context-Aware Access, MFA, and audit logs. Source: https://playciso.com/blog/google-meet-security-best-practices · Published: 2026-09-10 · Publisher: PlayCISO (https://playciso.com) --- Google Meet is where a lot of sensitive conversation now happens — board updates, incident bridges, vendor negotiations, HR calls. Because it launches from a browser link, it feels casual, and casual is exactly how uninvited guests, over-shared recordings, and rogue dial-ins slip in. This guide walks a CISO or Workspace admin through the controls that actually reduce risk, from the per-meeting host settings your people touch every day to the Admin console policies that make the safe path the default. ## Start with host management and the "Quick access" gate Every Meet call has a host, and the single most valuable habit you can build is turning off **Quick access** for meetings that carry sensitive content. With Quick access on, anyone in your organisation who has the link joins directly, and external guests reach the meeting the moment the host is present. With it off, the host must admit each participant — the "knocking" prompt — so an unexpected name never lands mid-conversation. - Turn Quick access off for confidential meetings so every non-invited join has to knock and be admitted. - Use Host management to name co-hosts before the call starts, so admitting people and moderating is not a single point of failure if the primary host drops. - Remember that people on the calendar invite are trusted and skip the knock; anyone not invited (including external guests when Quick access is off) must be let in explicitly. - Treat the waiting room as a decision point, not a formality — admit only names you recognise, and challenge anonymous or "guest" entries. ## Restrict who can join at all Knocking controls admission per meeting, but the stronger control is limiting who is even eligible. Google Meet and the Workspace Admin console let you require that participants sign in and, optionally, that they belong to your own organisation. - Require participants to be signed in to a Google account so anonymous, unauthenticated joins are blocked outright — this also means every attendee is attributable in the logs. - For internal-only meetings, restrict joining to users in your organisation so a leaked link cannot be used by an outside party at all. - Watch the external participant labels Meet shows: guests from outside your domain are flagged, and non-Google or anonymous users are marked distinctly. Train hosts to read those labels before sharing anything sensitive. - Set a Workspace policy on whether users may join meetings hosted by other organisations, and whether external guests may be invited to yours — decide this centrally rather than leaving it to each host. ## Moderate the live meeting Once people are in, the host and co-hosts hold a set of moderation controls that contain the blast radius of a disruptive or curious participant. These are the levers to reach for the moment something feels off. - Lock the meeting once expected attendees have arrived so no further joins are possible, even by invited users. - Use host controls to decide who can share their screen, who can send chat messages, and whether attendees can turn on their microphone or camera — restrict sharing to hosts for briefings. - Mute disruptive participants, and remove anyone who should not be there; removal can be paired with a report to Google for abuse. - Enable "Mute all" and, for large sessions, hold cameras off by default to reduce accidental exposure of screens and surroundings. - Be aware of companion mode and breakout rooms — moderation settings should follow into breakouts, so confirm sharing and chat limits still apply there. ## Dial-in security Phone dial-in is convenient and is also the easiest way for an untracked participant to appear as a bare phone number. Treat it as a deliberate choice, not an always-on default. - Disable phone dial-in for meetings that must stay internal or authenticated — a PSTN caller cannot be an authenticated Workspace user. - If dial-in is needed, remember that phone participants show only as a partial number; hosts should verify who they are before continuing sensitive discussion, and can mute or remove unknown callers. - Control dial-in availability at the Admin console level so it is not silently enabled for every meeting in the domain. ## Recording controls, Drive storage, and retention A recording turns an ephemeral conversation into a durable, forwardable, discoverable file. Recordings, transcripts, and generated notes save to the organiser's **Google Drive**, which means Drive sharing and retention policy — not Meet — governs who can reach them afterwards. - Restrict who can record (and who can start transcripts or "take notes for me") via the Admin console; do not leave recording open to every user. - Know that recordings land in the organiser's Drive (in a Meet Recordings folder) and inherit that account's sharing — audit those folders and avoid broad "anyone with the link" access. - Apply Google Vault retention and, where needed, holds to Meet recordings and chat so they are kept or purged in line with policy rather than living forever by accident. - Meet notifies participants that recording is on, but you should still set the expectation in policy about when recording is permitted and how the file is protected. ## Workspace-level admin controls Per-meeting hygiene only scales if the Admin console makes the secure configuration the default. This is where a CISO gets leverage across thousands of meetings at once. - Use Context-Aware Access to gate Meet (and the rest of Workspace) on conditions such as corporate device, managed browser, IP range, or geography — so credentials alone are not enough from an unmanaged endpoint. - Enforce device management and device policies for the accounts that join sensitive meetings: screen lock, encryption, minimum OS, and the ability to remotely wipe. - Set organisation-unit-level defaults for Quick access, external joining, recording, and dial-in so high-sensitivity groups are locked down without relying on individual hosts. - Turn on endpoint verification so you have an inventory of the devices accessing Workspace and can feed that signal into Context-Aware Access rules. ## Identity: 2SV, phishing-resistant keys, and audit Every Meet control assumes the account joining is really its owner. Harden that assumption first. - Mandate 2-Step Verification (2SV/MFA) for all users, and for admins and executives require phishing-resistant security keys or passkeys rather than SMS or one-time codes. - Enrol privileged accounts in Advanced Protection where warranted — it enforces hardware keys and stricter checks. - Review the Meet audit logs in the Admin console: who hosted, who joined (including external and phone participants), meeting duration, and device and network endpoints — wire these into your SIEM for alerting. - Correlate Meet logs with login and Drive access logs so an odd join and a subsequent recording download surface as one story, not three. ## Actionable checklist - Turn Quick access off for confidential meetings so every uninvited join must knock. - Require attendees to be signed in; restrict internal meetings to same-organisation users. - Train hosts to read external participant labels before sharing sensitive content. - Assign co-hosts and use host controls to limit screen share and chat to hosts for briefings. - Lock the meeting once everyone expected has joined. - Disable phone dial-in unless it is explicitly required, and verify any phone caller. - Limit who can record; audit the organiser's Drive Meet Recordings folder sharing. - Apply Vault retention/holds to recordings, transcripts, and chat. - Deploy Context-Aware Access and device policies so unmanaged endpoints cannot join sensitive meetings. - Turn on endpoint verification and maintain a managed-device inventory. - Enforce 2SV everywhere and phishing-resistant keys/passkeys for admins and executives. - Ship Meet audit logs to your SIEM and review external and dial-in joins regularly. ## Frequently asked questions **What is the difference between Quick access and locking a meeting?** Quick access controls admission before and during the call — off means everyone not on the invite must knock and be admitted by the host. Locking is a stronger, later action: once the expected attendees are in, locking stops all further joins, including invited users, so no one can slip in late. **Can I stop anonymous or external people from joining entirely?** Yes. Require participants to be signed in to a Google account to block anonymous joins, and restrict joining to users in your organisation for internal meetings. External guests are flagged with labels, and Admin console policy decides whether they can be invited at all. **Where do Google Meet recordings go and who can see them?** Recordings, transcripts, and generated notes save to the meeting organiser's Google Drive in a Meet Recordings folder. Access follows that Drive file's sharing, so audit those folders, avoid "anyone with the link", and apply Google Vault retention or holds to control how long they persist. **How do I secure the account, not just the meeting?** Enforce 2-Step Verification for all users and require phishing-resistant security keys or passkeys for admins and executives. Layer Context-Aware Access and device policies so a valid password from an unmanaged or out-of-policy device still cannot join sensitive meetings. **What can I actually see in the Meet audit logs?** The Admin console records who hosted and joined each meeting, including external and phone participants, join and leave times, meeting duration, and device and network endpoint details. Forward these to your SIEM to alert on unexpected external or dial-in joins and to correlate with login and Drive activity.