Earlier this week I noticed a message in the Message center about Auditing in Microsoft Teams being rolled out.
The following events should now all appear within your audit log:
- Added Bot to Team
- Removed Bot from Team
- Added Tab
- Removed Tab
- Added Connector
- Removed Connector
- Added Channel
- Deleted Channel
So I visited https://protection.office.com to make sure that audit logging had been enabled.
then I went to https://protection.office.com to search my audit logs for Miocrosoft teams event:
So there are actually a lot more events:
- Create team
- Delete Team
- Change Organisation Setting
- Change Team Setting
- Change Channel Setting
- Change Setting(legacy)
- User signed in to teams
- Added Bot to Team
- Removed Bot from Team
- Added Tab
- Removed Tab
- Added Connector
- Removed Connector
- Added Channel
- Deleted Channel
So I selected all teams events in my Audit log. Note that it can take a while for Auditing to be logged and be searchable. So don’t expect some results straight away.
In the meanwhile I will have a look at all those events that are available.
Some missing events in the above list are:
- added external user to team
- removed external user to team
- external user logged in
When looking at auditing I would like to see some events related to my external users included.
How about guests?
First I enabled both guest permissions available. So that my guest account can add and remove some channels.
and then I added a channel as the external user:
Then after a while (up to 24 hours) when my auditing started working I got the results back.
Time to look at this in a bit more details. I can now see that I logged in with my guest account:
And the more information drop down gives the following information.
So it is possible to recognize the guest users by their email address.
Going through the log though:
Issues
Did I really sign in every 56 minutes last night? I don’t think so. It looks like the background process running on your windows PC does the login for your every 56 minutes.
An additional issue that I found is that internal user’s IP address is recorded in the logs, however for guest users this doesn’t happen.