Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I had a need to search through and check which live lessons had been recorded on Teams. I couldn't find a way to to discover which meetings were recorded in the Unified Audit Log so I looked at Stream instead and then the groups that had been given access to the video.

 

Thought I'd post the powershell incase anyone else needs it, it's certainly not perfect but gets another job done.

 

# Reference Materials:
# https://docs.microsoft.com/en-us/stream/audit-logs#actions-logged-in-stream

$creds = Get-Credential 

# Connect to Azure AD
Connect-AzureAD -Credential $creds

# Connect to Exchange Online
Connect-ExchangeOnline -Credential $creds

# variables...
$domain = "schoolname.co.uk"
$license = "[MSOL License SKU ID goes here"
$folder = "C:\Cache\"

# Search range (American date formate M/D/YYYY)
$startdate = "1/18/2021 1:00 AM"
$enddate = "1/21/2021 1:00 AM"

# Get a list of staff meeting the criteria
$stafflist = $null
$stafflist = Get-AzureADUser -All $true -Filter "AccountEnabled eq true" | Where-Object {($_.AssignedLicenses).SkuId -contains $license}

# Set the log file destination
$wtf = $folder+$domain+".csv"

Write-Host ("Starting...")

foreach ($staff in $stafflist) {

   if ($staff.UserPrincipalName -like "*$domain") {
       
       # Search for events where a StreamVideo has been created by the user.
       $teams = Search-UnifiedAuditLog -StartDate $startdate -EndDate $enddate -UserIds $staff.UserPrincipalName -RecordType MicrosoftStream -Operations StreamCreateVideo

       # Search for permission change events for Stream Videos
       $perms = Search-UnifiedAuditLog -StartDate $startdate -EndDate $enddate -UserIds $staff.UserPrincipalName -RecordType MicrosoftStream -Operations StreamEditVideoPermissions | Select-Object -ExpandProperty AuditData | ConvertFrom-Json

       # Investigate each individual event where a video was created
       foreach ($lesson in $teams) {
           
           # Move the audit details to a workable object
           $lessondata = $lesson.AuditData | ConvertFrom-Json
           
           # Flag to determine is a recording was found
           $recorded = $false

           # Loop through the list of permission changes that have happened for the user
           foreach ($perms_event in $perms) {
               
               # Extract the permissions change event from the audit data
               $action = $perms_event | Select-Object -ExpandProperty OperationDetails | ConvertFrom-Json | Select-Object -ExpandProperty Added
               
               # Check if the action was to assign a Viewer to the video
               if ($action.Role -eq "Viewer") {

                   # Extract the ResourceID of the permissions change event
                   $perms_operation = $perms_event | Select-Object -ExpandProperty OperationDetails | ConvertFrom-Json | Select -ExpandProperty ResourceID

                   # Does the Permission event relate to the Lesson?
                   if ($lessondata.ResourceUrl -like "*$perms_operation") {

                       # The action matches the Lesson

                       # Return the GroupID associated with the Video
                       $groupID = $action.PrincipalIds
                       $group_name = Get-AzureADObjectByObjectId -ObjectIds $groupID

                       # Found a recording and the group to match, update the recording flag
                       $recorded = $true

                       Write-Host $lessondata.UserId"-"$group_name.DisplayName"-"$lessondata.CreationTime"-"$lessondata.ResourceTitle

                   }
               }
           }
       }

   } else {
       # Do nothing
   }
}

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...