Like other services in the Microsoft 365 suite, Microsoft Teams generates audit entries that can be reviewed in the Security & Compliance Center.
Detailed audit logging for Teams depends on enabling the unified audit log, which can be enabled the first time you access the audit log search in the Security & Compliance Center or via PowerShell with the following command:
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
To access the audit log and search for Microsoft Teams-related events, follow this process:
- Launch the Security & Compliance Center (https://protection.office.com), expand Search, and select Audit log search:
![](https://static.packt-cdn.com/products/9781838987732/graphics/assets/74b7d1a8-7bef-48ac-b91d-a7d2957d36d8.png)
- Click the Activities box, and then scroll to the Microsoft Teams events. Select the Microsoft Teams category to highlight all Teams events or select individual events:
![](https://static.packt-cdn.com/products/9781838987732/graphics/assets/0f5a7979-fceb-444a-a10e-34347f69626a.png)
- After you've made...