Zoom Admin Logs Integration
Overview
Zoom provides video conferencing and collaboration with admin activity and operation logs. KYRA MDR collects Zoom admin logs via the Reports API for monitoring account security and compliance. Supports Zoom Business, Enterprise, and Education plans.
Prerequisites
- A KYRA MDR Collector installed and running
- Zoom account with Admin or Owner role
- Server-to-Server OAuth app created in Zoom Marketplace
- Zoom Business plan or higher
Configuration
Configure Zoom Server-to-Server OAuth app:
- Go to Zoom App Marketplace > Develop > Build App
- Select Server-to-Server OAuth app type
- Configure scopes:
report:read:admin,dashboard:read:admin,user:read:admin - Note the Account ID, Client ID, and Client Secret
- Configure the KYRA MDR collector:
sources: - type: zoom account_id: <account-id> client_id: <client-id> client_secret: <client-secret> poll_interval: 300s- Restart the collector service
Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Sign-in/Sign-out | User authentication events | Access monitoring |
| Account Operations | Account setting changes | Security policy auditing |
| User Operations | User creation, deletion, role changes | Identity management |
| Meeting Operations | Meeting creation and settings | Meeting security monitoring |
| Webinar Operations | Webinar management events | Event auditing |
| Recording | Recording access and download events | Data access monitoring |
Troubleshooting
No reports available: Zoom Reports API data is available with a 1-day delay.
Insufficient permissions: Ensure the Server-to-Server OAuth app has the required scopes and is activated.
Rate limiting: Zoom API has strict rate limits. Set the poll interval to 300 seconds or more.
Contact kyra@seekerslab.com for support.