Microsoft Teams: Meeting Participant Detail audit records will be available in all participating (non-organizer) tenants

🚨 The Signal: Microsoft Teams audit logs will now include participant details for users in your tenant, even when meetings are hosted externally. This improves visibility for cross-tenant meeting activity and enhances investigation capabilities.

The Impact

Security teams and M365 administrators are affected, gaining improved visibility into external meeting participation, reducing blind spots.

  • Security Teams: Reduced blind spots for external meeting participation.
  • M365 Administrators: Enhanced audit data for investigations.
  • Compliance Officers: Better audit trails for regulatory requirements.

The Action

  1. Review existing Microsoft Purview Audit policies to ensure appropriate retention for new audit records.
  2. Update security incident response playbooks to leverage the new cross-tenant meeting audit data.
  3. Communicate the enhanced auditing capabilities to security operations centre (SOC) personnel.

Domain: Purview · Impact: medium · Workload: Microsoft Purview