Set network port range for Zoom Mesh parent-child node communication
Verified with Zoom 7.1.5 — updated on July 12, 2026
Supported on: Microsoft Windows XP SP2 or later
Path in the GPO console
Computer Configuration\Administrative Templates\Zoom Meetings\Zoom Meetings Settings Description
Default policy is empty. If this policy is a valid port range address, the client will use this range to set up listen sockets for connection requests between Mesh parents and children nodes. The nodes will also use this range to send signals and media data. If this policy is invalid or empty, the client will use "18801-19800" as the default port range. The format of this string should be "port-port", for example: "18801-19800". For Zoom Mesh Windows Firewall rules, the configured range must start at port 2000 or higher and span fewer than 5120 ports; otherwise, the firewall rule will not be added. If this policy is not set, client will use the default setting.
Registry
Software\Policies\Zoom\Zoom Meetings\Meetings Export Builder
BETAConfigure the state, scope and options, then generate .reg, PowerShell, Intune and SCCM outputs — or add the setting to a multi-setting collection.
These exports write the registry — this is not a managed GPO. ⓘ
.reg file
Windows Registry Editor Version 5.00
; Exported from gporais.com
; Policy: Set network port range for Zoom Mesh parent-child node communication
; State: Enabled
; Supported on: Microsoft Windows XP SP2 or later
[HKEY_LOCAL_MACHINE\Software\Policies\Zoom\Zoom Meetings\Meetings]
"MeshListenPortRange"="" More formats (PowerShell, Intune, SCCM)
PowerShell
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
$path = 'HKLM:\Software\Policies\Zoom\Zoom Meetings\Meetings'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MeshListenPortRange' -Value '' -Type String Intune XML
No direct Policy CSP / OMA-URI mapping for this policy. Use the Intune Remediation tab, or ingest the ADMX in Intune. Intune Remediation
# === Detection script ===
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Zoom\Zoom Meetings\Meetings' -Name 'MeshListenPortRange' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
$path = 'HKLM:\Software\Policies\Zoom\Zoom Meetings\Meetings'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MeshListenPortRange' -Value '' -Type String SCCM scripts
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
# SCCM Configuration Item guidance:
# Create a Configuration Item of type "Setting: Script".
# Discovery script: use the Detection script below.
# Remediation script: use the Remediation script below.
# Compliance rule: the Discovery script output equals 'Compliant'.
# === Detection script ===
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
function Test-RegistryValue {
param(
[Parameter(Mandatory = $true)][string]$Path,
[Parameter(Mandatory = $true)][string]$Name,
[object]$Expected,
[ValidateSet('String', 'DWord', 'MultiString')][string]$Kind = 'String',
[switch]$Absent
)
try {
$item = Get-ItemProperty -LiteralPath $Path -Name $Name -ErrorAction Stop
} catch {
return $Absent.IsPresent
}
if ($Absent.IsPresent) { return $false }
$actual = $item.$Name
if ($Kind -eq 'DWord') { return ([int64]$actual) -eq ([int64]$Expected) }
if ($Kind -eq 'MultiString') {
$actualValues = @($actual)
$expectedValues = @($Expected)
if ($actualValues.Count -ne $expectedValues.Count) { return $false }
for ($i = 0; $i -lt $expectedValues.Count; $i++) {
if ([string]$actualValues[$i] -ne [string]$expectedValues[$i]) { return $false }
}
return $true
}
return [string]$actual -eq [string]$Expected
}
$checks = @(
(Test-RegistryValue -Path 'HKLM:\Software\Policies\Zoom\Zoom Meetings\Meetings' -Name 'MeshListenPortRange' -Expected '' -Kind String)
)
if ($checks -notcontains $false) {
Write-Output 'Compliant'
exit 0
}
Write-Output 'Non-compliant'
exit 1
# === Remediation script ===
# Exported from gporais.com
# Policy: Set network port range for Zoom Mesh parent-child node communication
# State: Enabled
# Supported on: Microsoft Windows XP SP2 or later
$path = 'HKLM:\Software\Policies\Zoom\Zoom Meetings\Meetings'
New-Item -Path $path -Force | Out-Null
Set-ItemProperty -Path $path -Name 'MeshListenPortRange' -Value '' -Type String Building a multi-setting collection? Add this setting and generate combined .reg / PowerShell / GPO scripts.