Fix Teams Audit Log Does Not Show a Meeting Event in a Private Channel
🔍 WiseChecker

Fix Teams Audit Log Does Not Show a Meeting Event in a Private Channel

You open the Microsoft Purview audit log and search for a meeting that took place in a private channel, but the event is missing. This happens because Teams only records audit events for standard channels and chat meetings by default, while private channel meetings are logged under a different activity name. In this article, you will learn why the audit log omits private channel meeting events, how to adjust your search to find them, and what to do if the event still does not appear.

Key Takeaways: Finding Private Channel Meeting Events in the Audit Log

  • Microsoft Purview > Audit > Search > Activities > Meeting started: This is the exact activity name that records private channel meeting events.
  • Search by User and Date Range: Filter by the meeting organizer and the exact meeting time to reduce false negatives.
  • Export audit log to CSV: Use the Export button to download results and verify that the event exists even if the UI does not display it.

ADVERTISEMENT

Why the Audit Log Misses Private Channel Meeting Events

Teams audit logging captures a limited set of activities for private channels. When a user creates a meeting in a standard channel, Teams logs the event as Meeting created. For a private channel, the same meeting is logged under a different activity name: Meeting started. This naming difference is the primary reason your search returns no results.

Another factor is that private channel meetings are stored in the channel’s SharePoint site, not in the main team site. The audit log records the meeting event at the tenant level, but the activity name and the site location differ from standard channel meetings. If you search for the common activity Meeting created, the private channel event will not appear.

Finally, audit log retention policies can affect availability. Microsoft 365 retains audit records for 90 days by default, but your organization may have a shorter retention period. If the meeting is older than the retention window, the event is permanently deleted and cannot be recovered.

How Audit Logging Works for Private Channels

Private channels have their own SharePoint site collection. When a meeting is scheduled in a private channel, Teams creates a meeting event in the channel’s calendar, which is separate from the main team calendar. The audit log entry for this event uses the Meeting started activity, which is also used for one-on-one and group calls. This overlap means you need to filter by the specific user and time to isolate the private channel meeting.

Steps to Find and Fix the Missing Audit Event

Follow these steps to locate the audit event for a private channel meeting. If the event is present but not visible, the export step will confirm its existence.

  1. Open the Microsoft Purview portal
    Go to Microsoft Purview at purview.microsoft.com. Sign in with an account that has the Audit Logs role or global administrator permissions.
  2. Start a new audit search
    In the left navigation, select Audit under Solutions. Then click Search to open the audit log search page.
  3. Set the date range
    In the Start date and End date fields, enter the exact date of the meeting. Include a buffer of one day before and after to account for time zone differences.
  4. Select the correct activity
    Click Activities and filter by Meeting and calling. Scroll and select Meeting started. Do not select Meeting created, because private channel meetings do not use that activity.
  5. Add the meeting organizer
    In the Users field, type the email address of the person who scheduled the meeting. This narrows the results to events generated by that user.
  6. Run the search
    Click Search to run the query. Wait for the results to load. If the event appears, you can click it to see the full details.
  7. Export the results
    If the event does not appear, click Export and choose Download all results. Open the CSV file in Excel and filter the Activity column for Meeting started. This step often reveals the event even when the UI shows no results.
  8. Check the audit retention policy
    If the export also shows no event, verify your audit retention policy. Go to Microsoft Purview > Audit > Retention to see the current retention period. If the meeting is older than the retention period, the event is gone and cannot be recovered.

ADVERTISEMENT

If the Audit Event Still Does Not Appear

Teams Shows No Audit Event for a Private Channel Meeting

If you followed the steps above and still see no event, check whether the meeting was actually created in the private channel. Sometimes users schedule a meeting in the main channel and then move it to a private channel, which does not generate a new audit event. To verify, open Teams and go to the private channel’s Files tab. Check the meeting recording or the channel calendar for the meeting entry.

Audit Log Shows the Event but the Recording Is Missing

The audit log may show Meeting started but the meeting recording does not appear in the channel. This happens when recording is not enabled for the meeting policy. Ask the meeting organizer to check the recording settings in Teams admin center > Meetings > Meeting policies. The Cloud recording setting must be On for the user’s assigned policy.

Audit Log Search Returns No Results for Any Meeting

If your audit log search returns no results for any meeting, the audit log might be disabled. In Microsoft Purview, go to Audit and check the Status at the top of the page. If it says Turn on auditing, click it to enable audit logging. Wait up to 24 hours for new events to start appearing.

Standard Channel vs Private Channel Meeting Audit Events

Item Standard Channel Meeting Private Channel Meeting
Activity name Meeting created Meeting started
Storage location Team site Private channel SharePoint site
Search filter Activities > Meeting created Activities > Meeting started
Recording availability Channel Files tab Private channel Files tab
Audit retention impact Same as tenant policy Same as tenant policy

Now you can locate audit events for private channel meetings by using the correct activity name and export method. Start by running a search with Meeting started and the organizer’s email. If the event is missing, export the results to CSV to confirm. Then check the audit retention policy to rule out data loss. For advanced troubleshooting, enable audit logging in Microsoft Purview and verify the meeting policy for cloud recording.

ADVERTISEMENT