Microsoft Teams: Meeting Participant Detail audit records will be available in all participating (non-organizer) tenants
🚨 The Signal: Microsoft Teams audit logs will now include participant details for users in your tenant, even when meetings are hosted externally. This improves visibility for cross-tenant meeting activity and enhances investigation capabilities.
The Impact
Security teams and M365 administrators are affected, gaining improved visibility into external meeting participation, reducing blind spots.
- Security Teams: Reduced blind spots for external meeting participation.
- M365 Administrators: Enhanced audit data for investigations.
- Compliance Officers: Better audit trails for regulatory requirements.
The Action
- Review existing Microsoft Purview Audit policies to ensure appropriate retention for new audit records.
- Update security incident response playbooks to leverage the new cross-tenant meeting audit data.
- Communicate the enhanced auditing capabilities to security operations centre (SOC) personnel.
Domain: Purview · Impact: medium · Workload: Microsoft Purview