Ground Truthfield notes · defensive security

Home›Cloud Security›Purview & governance

Microsoft Purview · Teams governance

Auto-recording Teams meetings, hands-off

A client wanted every scheduled meeting for a set of users recorded — governance-grade, no exceptions, and crucially with nothing for the organiser to remember. The obvious paths all leave a human in the loop. Exactly one mechanism removes it entirely, and it isn't the one you'd reach for first.

The request sounds trivial: "make these people's Teams meetings record automatically." It isn't, because the two mechanisms everyone reaches for first — a Teams meeting policy, or a Teams Premium meeting template — both leave the organiser having to do something every single meeting. Flip a toggle. Pick a template. The moment a busy person forgets once, the recording that legal or the client actually needed doesn't exist. Governance-grade means the human can't be the point of failure.

The key insight

Only a Microsoft Purview sensitivity label, published as the default label for meetings, applies itself to every new meeting and enforces recording with zero user action. A policy unlocks the option; a template offers the option; a label is the decision, made before the organiser touches anything.

01Three mechanisms, one that's actually hands-off

This is the decision that saves the next engineer the most time — the other two look right and quietly aren't.

WHO PRESSES THE BUTTON? MEETING POLICY · AutoRecording unlocks an auto-record option — but it's off by default ✘ organiser ticks it every meeting PREMIUM TEMPLATE · locked auto-records and can't be turned off — once it's chosen ✘ organiser picks the template each time SENSITIVITY LABEL · default for meetings auto-applies to every new meeting and enforces recording ✔ nobody — hands-off
Only the label removes the human. Microsoft confirms a sensitivity label can enforce automatic recording even when the admin policy is off for that organiser — and a label policy can set a default label for meetings so it applies without the organiser choosing anything.

Pick one mechanism — the label outranks the others

Sensitivity labels take precedence over meeting templates and policies. Don't run a label and a template both trying to control recording — the label wins and the template just adds confusion. Keep any pilot policy or template only as a fallback during build, then retire it once the label is proven.

02Prerequisites, and the one check that decides everything

The label enforces recording only when Teams Premium is present on the organiser. Get this wrong and the label applies silently and records nothing.

Four things have to be true before you configure anything: Teams Premium on every in-scope organiser (the auto-record option in the label only enforces with Premium), cloud recording allowed in the organiser's meeting policy (the master switch — if recording is disallowed, the label can't force it), Purview roles to create and publish labels (Information Protection Admin / Compliance Admin), and testing from the Teams desktop app, where behaviour is most reliable. Recordings land in the organiser's OneDrive under Recordings.

Run these read-only checks first. The first confirms the master switch; the second is the make-or-break.

Connect-MicrosoftTeams

# 1 — cloud recording must be allowed (the master switch)
Get-CsTeamsMeetingPolicy |
  Select-Object Identity, AllowCloudRecording, AutoRecording |
  Format-Table -Auto
# 2 — Teams Premium must be present on the target organiser
Get-CsOnlineUser -Identity <organiser-upn> |
  Select-Object -ExpandProperty AssignedPlan |
  Where-Object { $_.Capability -like "TEAMSPRO_*" } |
  Select-Object -ExpandProperty Capability |
  Sort-Object

No TEAMSPRO_* plans, no recording

You must see the TEAMSPRO_* family come back (e.g. TEAMSPRO_MGMT, TEAMSPRO_CUST, TEAMSPRO_PROTECTION). If they're absent, stop — the label will apply but auto-record will never fire, and you'll waste an afternoon wondering why. Assign Premium first, then continue.

03Build the label — and the scope trap

Purview → Information protection → Labels → Create a label. The scope screen has a dependency that catches everyone once.

Give it a clear display name (users see it), then set the scope to Files & other data assets, Emails, and Meetings. In Meeting settings, set Record and transcribe automatically = On, then select and Lock it so organisers can't turn it off. Leave Access control and Content marking as None — label encryption will block download of the recordings, which is the opposite of what you want.

You can't scope it to Meetings only

The Meetings scope depends on Files & other data assets and Email both being selected — try to narrow it to Meetings-only and Purview removes the Meetings option. Accept all three; the side effect is the label also shows up as a file/email classification. Keep Access control and Content marking = None so it never encrypts or watermarks documents, and leave it off as the file/email default (next section) so it isn't stamped on everything.

04Publish it as the default meeting label

The label does nothing until it's published and set as the meeting default. That one setting is the entire trick.

Purview → Information protection → Label policies → Publish label. Add the label, target the organiser(s) — start with one pilot account — then in Policy settings set Default label for meetings to your label. That is the step that removes the manual pick: every new meeting the targeted user schedules is labelled automatically. Leave the file/email default unset (or a different label) so the auto-record label isn't stamped on every document and email.

CREATE LABEL 3 scopes · record auto + locked PUBLISH POLICY target the pilot organiser DEFAULT MEETING LABEL the step that removes the manual pick NEW MEETING auto-labelled, no user action RECORDS Premium enforces; banner shown LABEL → DEFAULT → EVERY MEETING
Build once, then it's automatic forever. The recording banner reads "Started automatically per the meeting organizer's settings" — nobody pressed record, internal and with external attendees present, which don't block it.

Give it up to 24 hours before you call it broken

Purview label-policy changes take up to a day to propagate to the Teams and Outlook clients. Configure it, then walk away — do not test, and definitely do not conclude it failed, before then. This single fact accounts for most "it didn't work" reports.

05What it covers — and what it quietly doesn't

The method is narrower than "record everything." Be explicit with the client about the edges, because the gaps look like bugs otherwise.

06The part that isn't technical

This capability records people automatically. The engineering is the easy half; the half that gets you in trouble is consent, retention, and access.

Before enabling on real users — as opposed to dummy test meetings — get the following confirmed in writing by the client's HR/Legal and recorded on the change ticket. None of this is optional, and none of it is the engineer's call to make alone:

The one-line model

A meeting policy unlocks recording, a template offers it, but only a sensitivity label set as the default for meetings enforces it with no human in the loop — provided Teams Premium is present. The technical build takes an afternoon; the consent-and-retention conversation is the part that actually protects everyone.

07Rollback, and a quick decision guide

To pull it from a user, unpublish or retarget the label policy. Retire any pilot fallback only after the label is confirmed recording.

# unassign a pilot meeting policy (back to Global)
Grant-CsTeamsMeetingPolicy -Identity <upn> -PolicyName $null
Remove-CsTeamsMeetingPolicy -Identity "<pilot-policy>"

# meeting-template removal is portal-only:
# Teams admin center > Meetings > Meeting templates > <template> > Remove
Client wants…UseNotes
Meetings auto-record, fully hands-offSensitivity label (this method)Teams Premium required; scoped per organiser
Meetings auto-record, organiser opts inPremium locked templateCheaper on mindshare; needs a selection each time
Every call + meeting, for investigationsCompliance recording (bot)Third-party, procurement, HR/Legal-led

Sources & further reading

Filed under
Cloud Security › Purview & governance
Browse this part of the knowledge base.
Related

Comments

Questions or corrections welcome. Sign in with GitHub to join the thread.