Microsoft 365Detection & ResponseRetrospectives

Detecting Meeting Hijacking: Defender XDR and Sentinel Hunting Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from April 2020, written in 2026 with the benefit of hindsight.

Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting activity in Microsoft Teams.

Signals worth watching

  • Anonymous or external participants joining internal-only meetings.
  • Meetings with unusually large numbers of anonymous participants.
  • External participants joining recurring sensitive meetings (board, HR, M&A).
  • Meeting recordings accessed or downloaded by unexpected users.
  • Changes to tenant-wide meeting policies.

Where the data lives

  • Teams audit events in the Microsoft 365 unified audit log (meeting participant detail and policy changes).
  • Teams admin center usage and meeting reports.
  • Defender for Cloud Apps activity logs for Teams.

A starting approach

Monitor for changes to meeting policies, which can silently weaken controls:

OfficeActivity
| where Workload == "MicrosoftTeams"
| where Operation has "Policy" or Operation has "TeamsTenantSettingChanged"
| project TimeGenerated, UserId, Operation, ModifiedProperties

For participant-level detail, review meeting participant audit events for high-sensitivity meetings and correlate with your list of approved external domains.

Response

  1. If a sensitive meeting was accessed by an unexpected participant, inform the organizer and assess what was discussed or shared.
  2. Revoke shared links and reissue invitations.
  3. Apply stricter meeting policies or templates for that group.
  4. Review recordings and transcripts for distribution.
detect meeting hijackingZoom-bombing / meeting security2020

More on this story