The playbook
Deploy noise suppression company-wide
“Company-wide” is the operative word. Any employee can turn on a noise filter for themselves; your job is to make clean call audio the state a machine is in when it leaves provisioning, the state it returns to after re-imaging, and the state nobody has to think about in between. That is a deployment project — small, as deployment projects go, but a real one, with layers, packaging, a pilot and a budget line. This page is the whole arc.
What you're actually deciding
Strip away the vendor noise and there are only three decisions:
- Which platform levers do we turn on? Teams and Zoom ship noise processing already. Their admin surfaces are real but narrower than most people assume. Cost: zero.
- Do we add a dedicated suppression layer? A tool that sits at the OS audio level and cleans every application at once. Cost: per-seat licensing, plus deployment effort.
- How does it reach the fleet? Intune, GPO, MDM, and identity plumbing. Cost: your time, once — or continuously, if you skip the automation.
Most rollouts fail by answering question two first, spending the budget, and never getting to question three. Run them in order.
Three decisions, asked in this order
- Platform leversTeams and Zoom ship noise processing alreadyCostzero
- A dedicated suppression layerOS-level, cleans every application at onceCostper-seat licensing, plus deployment effort
- Reaching the fleetIntune, GPO, MDM and identity plumbingCostyour time, once — or continuously, if you skip the automation
Layer one: turn the free levers first
Neither Microsoft nor Zoom pays us anything, and this section is still first, because it should be. If your organization lives inside one meeting platform, the built-in processing — properly policy-managed — may end the project by itself, and the only honest way to find out is to configure it and measure.
Microsoft Teams
The admin story is more limited than the marketing suggests, which is exactly why it needs an admin-eye view. As of our 20 September 2026 check of Microsoft's policy documentation: you can govern voice isolation per policy group (-VoiceIsolation, default Enabled), govern the voice enrollment it depends on (-EnrollVoice, -PassiveVoiceEnrollment), and control the newer dial-in participant suppression from the Meeting policies → Audio & video pane. What you cannot do is pin every desktop user's noise-suppression level from the admin center — no meeting-policy setting does that today. The full parameter-by-parameter breakdown, with PowerShell, is on our Teams policy page.
Zoom
Zoom's desktop client exposes four suppression levels (Auto, Low, Medium, High), and — unlike Teams — Zoom documents a way to set that level administratively: the SetSuppressBackgroundNoiseLevel policy key in its mass-deployment kit, pushed by MSI switch, GPO or MDM. Portal-side, account and group settings with admin locks govern the surrounding meeting-audio features. Details and exact key values are on the Zoom admin audio page.
No affiliate relationship exists between this site and Microsoft or Zoom. We recommend their built-in levers because they're free and already licensed — the strongest possible starting position.
Layer two: when a dedicated layer earns its seats
The free levers share one structural limit: they live inside their own applications. The moment your fleet's voice traffic spreads beyond a single meeting client, per-app processing turns into per-app configuration drift. A dedicated layer — Krisp is the one with genuine enterprise plumbing — installs as a virtual microphone and speaker at the operating-system level, so one managed install cleans the meeting client, the softphone, the ATS's built-in interview caller, and whatever your revenue teams adopt next quarter without a ticket.
Here's the decision table we actually use. Score yourself honestly; three or more “yes” answers and the paid layer is worth a pilot. Fewer, and you should probably stop at platform policy and spend the money elsewhere.
| Question | Why it moves the needle |
|---|---|
| Does voice traffic run through 3+ applications? | Per-app settings can't be centrally held in sync; an OS-level layer configures once. |
| Do customer-facing teams (sales, support, recruiting) live on calls? | Audio quality is revenue-adjacent there; these teams also generate the loudest complaints. |
| Is a meaningful slice of the fleet remote or hybrid? | You don't control their rooms. Software is the only lever you hold. |
| Do you need SSO, SCIM and audit trails on every tool? | Only enterprise-productized vendors clear this bar; it's also the tier where consoles get useful. |
| Is “call audio” already a recurring, unattributable complaint? | You have demand. A managed layer converts a vague grievance into a closed project. |
| Would you deploy it silently, not ask users to install it? | If the answer is “we'd just email a download link,” adoption will be partial and the spend won't defend itself. |
Score the six questions
- 3+ voice apps
- Customer-facing calls
- Remote or hybrid
- SSO, SCIM, audit trails
- A recurring complaint
- Silent deployment
0–2 yeses Stop at platform policy; spend the money elsewhere.
3–6 yeses The paid layer is worth a pilot.
The enterprise reality check on Krisp
Marketing pages say “enterprise-ready”; deployment reality is a checklist. Here is where Krisp stood when we verified on 20 September 2026:
- A real MSI, from a real console. The Windows MSI ships from Krisp's Admin Portal, installs silently, and accepts install-time parameters — including an SSO slug (
KP_sso_slug) so machines come up already pointed at your identity provider. Full commands on the MSI & silent-install page. - macOS bulk install. Documented terminal/scripted installation for exactly the MDM workflow you'd expect; see macOS MDM.
- Admin Portal. Seat and user management, update control, and usage visibility — the feedback loop that tells you which seats are idle before renewal.
- Identity. SSO with an Entra ID gallery app; SSO/SCIM provisioning sits in the Enterprise tier. Our SSO & SCIM page covers the order of operations.
- Compliance furniture. SOC 2 compliance is listed across the paid tiers; the Enterprise tier is where HIPAA support with BAA signing for teams of 100+ seats, a super-admin role, and on-device private transcription sit — alongside SSO and SCIM.
Packaging and distribution: where rollouts live or die
The tool choice gets the meetings; the distribution plan decides the outcome. Whatever you selected above has to arrive silently, configure itself from parameters, and survive re-imaging. The pattern:
- Windows, modern management: wrap the MSI as an Intune Win32 app (or push it as a line-of-business app when your parameter needs are simple), detect on product code, assign by ring group. Walkthrough: Intune deployment.
- Windows, classic estate: GPO software installation or SCCM where that's still the house machinery — plus the honest list of things GPO does badly at, on the GPO & SCCM page.
- macOS: a pkg install through your MDM, with one Apple-specific trap: no MDM payload can pre-approve microphone access. Apple reserves that consent for the user; you can deny it by policy but never grant it. Plan your comms around that one unavoidable click — details on macOS MDM.
- Identity before installers: configure SSO first, pass the slug at install time, and turn on SCIM if you're at the tier that has it, so offboarding reclaims seats without a human remembering. See SSO & SCIM.
Identity first, then three roads to the fleet
Identity, first
Configure SSOSlug passed at install timeSCIM, if your tier has it
Windows, modern
MSIIntune Win32 app (LOB if parameters are simple)Detect on product codeAssign by ring groupFleet
Windows, classic
MSIGPO software installation or SCCMFleet
macOS
A pkg install through your MDMOne microphone prompt the user must allowFleet
Stage it in rings — even though it's “just audio”
An audio layer touches every real-time call in the company, which means the blast radius of a bad interaction (a driver conflict, a CPU spike on old hardware, a softphone that hates virtual devices) is every meeting happening that hour. That's why we stage even this small deployment:
- Ring 0 — IT and the champions (a week): your own team plus a handful of volunteers who live on calls. Goal: catch the mechanical failures.
- Ring 1 — the noisiest real team (two weeks): support, inside sales, recruiting. Goal: prove the outcome on people with the problem, and harvest quotes for the CAB.
- Ring 2 — everyone else: by department, watching the console's adoption numbers as you go.
Three rings, widening
- Ring 0 · a weekIT and the championsCatch the mechanical failures
- Ring 1 · two weeksThe noisiest real teamProve the outcome; harvest quotes for the CAB
- Ring 2 · by departmentEveryone elseWatch the console’s adoption numbers
Exit criteria, comms templates and the rollback plan are written out on the pilot rollout page. The short version of the rollback plan: because you deployed by policy and package, you can also retreat by policy and package. Ad-hoc rollouts don't get rollbacks; that alone justifies doing this properly.
The seat math, briefly
Numbers below are computed from the verified per-seat prices (script in our repo, not hand-typed): 100 seats on Krisp Core run $9,600/year billed annually — or $19,200/year if someone forgets to flip annual billing, the single most expensive checkbox in this project. The Advanced-over-Core delta at 100 seats is $8,400/year, which you should only pay for the features you'll actually govern with. At 250 seats, Core annual is $24,000/year ($96 per seat per year). The full tables at 25–1,000 seats, plus the questions that shrink the bill (who actually needs a seat, what the trial proves, when Enterprise custom pricing starts making sense), live on the license-costs page.
100 seats, for one year
At 250 seats, Core billed annually: $24,000 a year — $96 a seat.
Prove it worked
A rollout without measurement is a purchase. Three loops close the case:
- Console adoption: seats active in the vendor console vs. seats paid. Anything under ~80% ninety days in means your assignment groups are wrong or your comms were skipped.
- The ticket category you created: before ring 0, add a “call audio” category to the helpdesk. You can't show a decline in a category that doesn't exist. (Why this category is chronically invisible: the ticket nobody owns.)
- A blunt one-question pulse: “In the last month, how often did background noise disrupt a call?” — asked before ring 0 and again at +60 days. Unscientific, cheap, and exactly the chart your CFO will remember.
The playbook on one screen
- Configure Teams voice-isolation policy and Zoom's suppression policy key. Free. Today.
- Run the decision table. Under three yeses → stop here, monitor the pulse question, done.
- Three-plus yeses → 7-day Krisp trial as ring 0, pilot on the noisy team as ring 1.
- SSO first, then MSI/MDM packages with the slug parameter baked in.
- Annual billing, seats scoped to people who talk for a living, calendar reminder 30 days before renewal.
- Measure adoption, tickets, pulse. Reclaim idle seats. Close the ticket.
Ready to run ring 0?
Krisp's 7-day trial needs no card and no procurement conversation — which makes it the cheapest possible way to find out whether the paid layer earns a place in your stack. Put your own team on it this week; if the trial doesn't obviously beat your configured platform baseline, close the project with a clear conscience and a paper trail.
Referral link, declared: when an organization licenses Krisp after clicking this button, Krisp pays RolloutDesk a fee, and the quote you receive is the one you would get going direct. The playbook above — including the advice to try the free levers first — is identical either way.
Questions we get from other admins
Can't I just tell everyone to turn on their app's noise setting?
You can, and some will, briefly. Settings drift, laptops get re-imaged, new hires never see the email. If a control matters, it ships as policy or a package; that's the entire thesis of this site.
Do I need the paid layer if we're 100% on one meeting platform?
Often not — that's the “fewer than three yeses” outcome, and it's common. Configure the platform levers, create the ticket category, and revisit only if the complaints persist with evidence attached.
What about the people who refuse to install anything?
Silent deployment exists precisely so there is nothing to refuse. The only genuine consent gate in the whole project is the macOS microphone prompt, which Apple reserves for the user — budget one line of comms for it.
Does a suppression layer add latency or eat laptops?
Any real-time DSP costs some CPU; on hardware from the last several years it's rarely noticeable, but “rarely” is what ring 0 is for. Put your oldest supported laptop in the pilot deliberately. We publish no fabricated benchmark numbers — measure on your own fleet, where the answer actually matters.