Like other services in the Microsoft 365 suite, Microsoft Teams generates audit entries that can be reviewed in the Security & Compliance Center.
Detailed audit logging for Teams depends on enabling the unified audit log, which can be enabled the first time you access the audit log search in the Security & Compliance Center or via PowerShell with the following command:
Set-AdminAuditLogConfig -UnifiedAuditLogIngestionEnabled $true
To access the audit log and search for Microsoft Teams-related events, follow this process:
- Launch the Security & Compliance Center (https://protection.office.com), expand Search, and select Audit log search:

- Click the Activities box, and then scroll to the Microsoft Teams events. Select the Microsoft Teams category to highlight all Teams events or select individual events:

- After you've made...