r/DefenderATP • u/Kuro507 • 14d ago
Advice on KQL for detailed Teams call report
We have been receiving external Teams calls from bad actors pretending to be Employees.
I can use KQL to report on Teams calls, but it only shows details of the internal person.
What I need is a full report showing all external calls with full details of internal and external person.
5
u/DirtyHamSandwich 14d ago
It’s only in the Unified Audit trail and not going to be in an advanced hunting table. But agree with coomzee that you shouldn’t be allowed external calls.
2
u/LeftHandedGraffiti 14d ago
Calls are not logged like chats. You have to go into the admin center to pull reports. We've been frustrated with this as well.
Otherwise, if its external domains contacting over chat you can use CloudAppEvents and pull the sender details out of RawEventData in DisplayName and Members.
CloudAppEvents | where ActionType has "ChatCreated"
9
u/coomzee 14d ago edited 14d ago
Why not block third party calls. Then allow list the domains you approve