Fix Teams Audit Log Does Not Show a Meeting Event for a Recorded Meeting
🔍 WiseChecker

Fix Teams Audit Log Does Not Show a Meeting Event for a Recorded Meeting

When you record a Teams meeting, you expect the audit log to capture that event. But sometimes the audit log shows no meeting event at all. This leaves compliance officers and IT admins without a record of who recorded what and when. The cause is usually a misconfigured audit log retention policy or a missing license assignment. This article explains the exact steps to find the missing event and adjust your settings so future recordings appear in the log.

The audit log relies on the Microsoft 365 Purview compliance portal. If the recording was made by a user whose license does not include the required audit plan, the event is suppressed. Also, the default retention period for audit logs is 90 days. If you are looking for an event older than that, it may have been purged. This article covers both scenarios and shows you how to verify each one.

Key Takeaways: Fix Missing Teams Meeting Audit Events

  • Microsoft 365 Purview compliance portal > Audit > Search: Use the Search tab to filter for MeetingRecorded and related activities.
  • Microsoft 365 admin center > Users > Active users > Licenses: Assign an E5 or A5 license to users who must have audit events recorded.
  • Purview compliance portal > Audit > Retention: Set the audit log retention to 10 years if you need long-term compliance records.

ADVERTISEMENT

Why Teams Audit Log Does Not Show a Meeting Event After Recording

The audit log records actions that happen in Teams, including when a user starts or stops a recording. The event name is MeetingRecorded. This event appears in the audit log when a user clicks Record in a meeting. If the event is missing, one of three conditions is true.

First, the user who recorded the meeting may not have a license that includes the audit log. The standard audit log requires an E3, A3, or G3 license. But the full audit log with advanced features, such as recording events, requires E5, A5, or G5. Without the right license, the system does not generate the event.

Second, the audit log search may be using the wrong date range or activity filter. The default view in the Purview portal shows only the last 90 days. If the recording happened more than 90 days ago, you will not see it unless you change the retention policy.

Third, the audit log might not be enabled for your tenant. In some organizations, the audit log is turned off by default. You must enable it in the Purview portal before any events are collected.

The Role of the Audit Log Retention Policy

The retention policy determines how long audit events are stored. The default is 90 days. You can change it to 10 years if your organization needs longer retention. The policy applies to all audit events, not just Teams meetings. If you have not changed the policy, events older than 90 days are automatically deleted.

Steps to Diagnose and Fix the Missing Meeting Event in the Audit Log

Follow these steps in order. Each step verifies a different possible cause.

  1. Check the audit log is enabled
    Go to Microsoft Purview compliance portal. Sign in with an account that has the Audit Log role. In the left navigation, select Audit. If you see a banner that says auditing is not enabled, click Start recording user and admin activity. Wait 24 hours for the setting to take effect.
  2. Verify the user has the correct license
    Open the Microsoft 365 admin center. Go to Users > Active users. Select the user who recorded the meeting. Click the Licenses and apps tab. Confirm the user has a license that includes Microsoft 365 E5 or an equivalent. If not, assign a trial or purchased E5 license.
  3. Run a broad audit search
    In the Purview portal, go to Audit > Search. Set the date range to cover the day of the recording. Leave the Activities field blank to see all events. Click Search. Look for the activity name MeetingRecorded. If you do not see it, the event was not generated.
  4. Check the Teams admin center for recording policies
    Go to Teams admin center. Select Meetings > Meeting policies. Click the policy assigned to the user. Under Recording, confirm that Cloud recording is set to On. If it is off, no recording event will be generated.
  5. Extend the audit log retention period
    In the Purview portal, go to Audit > Retention. Select a custom retention period of 10 years. Click Save. This change applies to new events. Existing events that were already purged cannot be recovered.

ADVERTISEMENT

If Teams Still Does Not Log the Meeting Event

Teams Shows a Recording in the Chat But No Audit Event

This can happen when the user has a license that supports recording but does not have an audit license. The recording is stored in OneDrive or SharePoint, but the audit event is not generated. Check the user’s license again and assign an E5 license if needed.

Audit Search Returns No Results for Any Teams Activity

If the audit log is empty for all Teams activities, the audit log was never enabled. Follow step 1 again. Also, make sure you are searching in the correct tenant. If you have multiple tenants, sign in to the tenant where the meeting took place.

The Meeting Event Appears but With a Different Name

In some cases, the event is logged as MeetingParticipantDetail or MeetingEnded. Use the filter Recorded in the activity picker to narrow results. If you still cannot find the event, check the Recordings tab in the meeting chat. The recording file itself contains the timestamp of when it was made.

Teams Audit Log Search Options Compared

Item Basic Audit (E3) Advanced Audit (E5)
Retention period 90 days 1 year or 10 years
MeetingRecorded event Not available Available
Search interface Purview portal Purview portal

The table shows the key differences between the two audit tiers. If your organization needs compliance records for meetings, you must have an E5 license for every user who records.

After you complete the steps above, the audit log will show the MeetingRecorded event for new recordings. Test this by recording a short test meeting. Then search the audit log for that event. If it appears, your configuration is correct. For ongoing compliance, set up a scheduled search that runs weekly and exports the results to a CSV file. Use the Export button in the audit search page to automate this process.

ADVERTISEMENT