"Unrelated people entered after a meeting URL was shared," "External partners can join without approval"—reports of such security incidents in Google Meet have been increasing alongside the entrenchment of hybrid work.
For Google Workspace administrators, Meet security settings are not a binary choice between "meetings anyone can enter" and "meetings nobody can enter." By correctly combining the three features of Quick Access, knocking (join requests), and waiting rooms, you can significantly mitigate unauthorized access risks without sacrificing convenience.
In this article, we explain the latest configuration methods from the Admin Console for administrators, including the new host management controls added in June 2025.
The three features comprising Google Meet join controls
Participant approval in Google Meet functions through three tiered features. Accurately understanding the role of each is a prerequisite for proper configuration.
Quick Access
When Quick Access is on, users from the same organization can join meetings without host approval. When turned off, all participants—including internal organization members—require host approval. Administrators can set the default state (on/off) of Quick Access across the entire domain via the Admin Console.
Knocking (join requests)
External participants who did not receive a calendar invite, or users attempting to join when Quick Access is off, must "knock." They cannot enter the meeting until approved by the host. Following the June 2025 update, hosts can now turn off the "Anyone with the link can knock" option exclusively when the access type is set to "Trusted" or "Restricted." This allows you to restrict join requests solely to users who received calendar invitations.
Waiting Room
The waiting room is a feature that temporarily holds participants prior to approval. Hosts can send messages to participants in the waiting room, and participants can check meeting details. Enabling or disabling the waiting room as a default setting can be managed from the Admin Console.
Settings available in the Admin Console
The Meet security settings that administrators can manage from the Admin Console (admin.google.com) are as follows.
1. Video call safety settings
Settings path: Admin Console → Apps → Google Workspace → Google Meet → Meet safety settings
| Setting | Recommended value | Benefit |
|---|---|---|
| Only users in your organization can start meetings | Enabled | Prevents external users from creating rooms on their own |
| Require external participants to knock | Enabled | Blocks automatic joining by external users |
These settings apply domain-wide. It may take up to 24 hours for changes to take effect.
2. Quick Access default value
Settings path: Admin Console → Apps → Google Workspace → Google Meet → Meet settings → Video calling
You can standardize the default Quick Access state (on/off) across your organization. If security is prioritized, setting it to "Off" is recommended. However, since turning it off increases the host's approval burden, decide based on the nature of the meetings (such as internal routine meetings versus external sales calls).
The default value set by administrators can be overridden by organizers via "Video call options" in Calendar. If you want to keep it strictly enforced, you need to establish separate operational guidelines for users.
3. Waiting room settings
Settings path: Admin Console → Apps → Google Workspace → Google Meet → Waiting room settings
You can set whether the waiting room is on or off as a domain default. When the waiting room is enabled, participants who knock are held in a temporary holding area until approved by the host.
Added June 2025: New host management controls
With the new host management controls rolled out starting June 12, 2025, organizers can now restrict who can knock solely to calendar invitees, exclusively when the meeting access type is set to "Trusted" or "Restricted."
Configuration steps (organizer action):
- Open the meeting invite screen in Google Calendar
- Click "Video call options" (gear icon)
- Under "Host management," change "Meeting access type" to "Trusted" or "Restricted"
- Uncheck "Anyone with the meeting link can knock"
At present, this setting cannot be enforced at the organizational level by administrators and must be configured individually by organizers. As an administrator, it is important to formulate setup guidelines and communicate them to users.
Recommended configurations by scenario
Here are recommended configurations based on organizational requirements.
Pattern A: Organizations focused internally with few external participants
- Quick Access: On (smooth joining for internal members)
- Knock for external participants: Enabled
- Waiting room: Optional
This is a standard configuration where only external participants require approval. Internal members can join routine meetings friction-free, while maintaining security during business discussions with external partners.
Pattern B: Organizations with frequent meetings handling confidential information
- Quick Access: Off
- Knock for external participants: Enabled
- Waiting room: Enabled
- Access type: Restricted
This is the strictest configuration, requiring approval for all participants. It is suitable for meetings with high information leak risks, such as legal, HR, or executive strategy sessions.
Pattern C: External webinars and large-scale events
- Quick Access: Off
- Waiting room: Enabled
- Set up multiple co-hosts
When participant counts are large, appointing co-hosts to divide the approval workload is essential. Be sure to also utilize batch approvals from the waiting room.
Common configuration mistakes and solutions
"We enabled knocking for external participants, but they still enter without approval"
If Quick Access is enabled, external users may still join without knocking under certain conditions. Please configure both "Require external participants to knock" and "Quick Access: Off" together.
"Settings configured in the Admin Console are not taking effect"
Admin Console configuration changes can take up to 24 hours to propagate. Furthermore, new defaults do not apply to meetings that users have already started, so test behavior in newly created meetings after making changes.
"Organizers change settings from Calendar on their own"
Currently, Google does not provide a feature allowing administrators to completely prohibit organizers from changing Quick Access settings. This must be addressed through operational rules and user training.
Related settings to review alongside Google Meet recording and meeting management
Meet security settings are also closely tied to recording and meeting attendance controls. Default settings for recording features are covered in detail in the following articles.
- How to Configure Google Meet Recordings to Download by Default
- Managing Hybrid Work in 2026 Using Google Chat's Meeting Section
Conclusion
Understanding the three-tiered structure of Quick Access, knocking, and waiting rooms allows you to configure Google Meet participant approvals flexibly according to your organization's security policies.
The June 2025 update added a new option to narrow down who can send join requests. However, because certain settings cannot be enforced by administrators at the organizational level, managing Meet securely requires pairing policy development with user training.
If you are facing difficulties with Google Workspace administrative settings or want to determine the optimal configuration for your security policy, please feel free to consult GleamHub.
Consult us about Google Workspace implementation and configuration









