Skip to content

Zoom Admin Logs Integration

Overview

Zoom provides video conferencing and collaboration with admin activity and operation logs. KYRA MDR collects Zoom admin logs via the Reports API for monitoring account security and compliance. Supports Zoom Business, Enterprise, and Education plans.

Prerequisites

  • A KYRA MDR Collector installed and running
  • Zoom account with Admin or Owner role
  • Server-to-Server OAuth app created in Zoom Marketplace
  • Zoom Business plan or higher

Configuration

Configure Zoom Server-to-Server OAuth app:

  1. Go to Zoom App Marketplace > Develop > Build App
  2. Select Server-to-Server OAuth app type
  3. Configure scopes: report:read:admin, dashboard:read:admin, user:read:admin
  4. Note the Account ID, Client ID, and Client Secret
  5. Configure the KYRA MDR collector:
collector-config.yaml
sources:
- type: zoom
account_id: <account-id>
client_id: <client-id>
client_secret: <client-secret>
poll_interval: 300s
  1. Restart the collector service

Collected Log Types

Log TypeDescriptionSecurity Use
Sign-in/Sign-outUser authentication eventsAccess monitoring
Account OperationsAccount setting changesSecurity policy auditing
User OperationsUser creation, deletion, role changesIdentity management
Meeting OperationsMeeting creation and settingsMeeting security monitoring
Webinar OperationsWebinar management eventsEvent auditing
RecordingRecording access and download eventsData access monitoring

Troubleshooting

No reports available: Zoom Reports API data is available with a 1-day delay.

Insufficient permissions: Ensure the Server-to-Server OAuth app has the required scopes and is activated.

Rate limiting: Zoom API has strict rate limits. Set the poll interval to 300 seconds or more.

Contact kyra@seekerslab.com for support.