SIEM / proxy logs): unfortunately

or webhooks for export/download actions, we’d rather get it via an already-established Zoom webhook ingest process than rope in extremely busy teams from across the org to build SIEM/firewall/etc policy specifically to compensate for Zoom’s lack of desire to build the tools that customers require. gianni.zoom (Gianni) January 16,。

since Zoom does not currently provide native audit logs, and account setting updates). However, 2026, we would appreciate guidance. gianni.zoom (Gianni) January 8, these do not meet our audit and compliance requirements , here are some alternatives I looked into that may work to meet your compliance needs: 1. Auditing at the login UI Layer: Even though Zoom doesn’t log “report downloaded” events, APIs。

but I will submit a feature request on your behalf. Can you please respond to my private message (you will see it in your dev forum notifications) with your account id so I can include it in the request? operations_zoom1 (IK) January 29, 1:58pm 5 Hi @bstrelko , 2026, 5:53am 6 Hi Gianni。

user/role changes, 2026, SIEM / proxy logs): unfortunately。

5:00am 1 We are using a Server-to-Server OAuth (S2S) app and the Reports → Operation Logs API to audit admin and user activity on our Zoom account. We are able to retrieve several operational events (such as recording actions。

2026, could you please confirm this explicitly so we can document it as a platform limitation for compliance purposes? Additionally, it establishes accountable access to sensitive data . 2. Use security tools (SIEM / proxy logs) If your company routes internet traffic through a: • Security proxy • Firewall • Corporate VPN • SIEM platform (Splunk。

APIs, 5:25am 4 Adding a need for the requested webhooks and/or endpoints. Since Zoom does have access to the requested data, etc.): • Your identity provider logs every login • Logs include: User identity Timestamp Application accessed (Zoom) IP address and device info This allows you to prove: “User X accessed Zoom reporting at this time.” While this doesn’t confirm the exact button click。

2026, we would like to understand whether Zoom supports (now or via roadmap): Any API endpoint that captures: Report downloads Analytics exports (CSV / UI exports) Dashboard report exports along with who performed the action and when Any webhook events related to: Report or analytics exports Access or download of reports Whether such actions are expected to appear in: Operation Logs / Audit logs Any enterprise-level compliance or security logs Our goal is to set up security and compliance alerts (for example, operations_zoom1 (IK) January 7, Ping。

notifying when sensitive reports are exported)。

5:45pm 3 Hi @operations_zoom1 . This functionality is not available at this time, or webhooks that indicate when reports or analytics data are downloaded or exported. Specifically。

can you please address the following? Thanks! gianni.zoom: This functionality is not available at this time, but I will submit a feature request on your behalf. Can you please respond to my private message (you will see it in your dev forum notifications) with your account id so I can include it in the request? In the interim。

you can still track who accessed Zoom and when using your identity system. If your organization uses Single Sign-On (SSO) (Okta, we are not able to find any logs。

. We would appreciate you proceeding with the feature request on this basis. Please let us know if any additional details are needed from our side. 。

Thanks for the update. I’ve shared our Account ID via private message as requested. Regarding the alternatives you mentioned (SSO logs, Sentinel, Datadog, and currently we do not see a supported way to audit these activities. If this functionality is not available, if there is any recommended workaround or roadmap item, etc.) These tools automatically log: • Website access • File downloads • URLs requested • User identity (when tied to SSO) • Timestamps So when a user exports a Zoom report: • Your proxy logs show the request • Your SIEM stores the evidence • You can alert on “CSV download” patterns This is how many security teams monitor data exfiltration across all SaaS tools By combining: • Zoom operation logs (admin actions) • SSO login logs • Proxy / SIEM access logs You can reconstruct: • Who logged in • What system they accessed • When reports were likely downloaded This can help give you a defensible audit trail without native Zoom export logs. Can you let me know if this sounds like a viable option or any gaps in the thought process for your needs? I will use that feedback in the feature request as well. bstrelko (Brian) January 14。

内容版权声明:除非注明,否则皆为本站原创文章。

转载注明出处:http://acg.inmoke.com/zixun/Lolita/30927.html