Compliance Recording in Microsoft Teams: What It Really Takes and How to Choose

Michael Levy, CEO of recording vendor Numonix, explains what separates compliance-grade recording from Teams' native convenience recording, how Microsoft's compliance recording certification programme actually works, and the engineering effort needed to keep up with Teams API changes such as bot gro

Compliance Recording in Microsoft Teams: What It Really Takes and How to Choose

Prefer audio?

Who should listen: Microsoft 365 service owners, UC architects and compliance or risk teams in regulated sectors who are selecting, renewing or troubleshooting a certified Teams compliance recording platform.

Guest: Michael Levy — CEO, Numonix

Michael Levy, CEO of recording vendor Numonix, explains what separates compliance-grade recording from Teams' native convenience recording, how Microsoft's compliance recording certification programme actually works, and the engineering effort needed to keep up with Teams API changes such as bot grouping and delta roster. Tom Arbuthnot also presses him on the practical questions buyers should ask when comparing certified solutions.

Key insights

  • Convenience recording sits with the user — it lands in their OneDrive and they can stop, edit or delete it. Compliance recording is admin-policy driven, centrally encrypted, role-based access, and includes a strict mode where Teams blocks the user from making or receiving calls if the recording platform is unavailable. ▶ 3:36
  • Convenience recording only works if you are from the domain that organised the meeting — join an external meeting and the record button is greyed out. Compliance recording bots follow the targeted user into any meeting, because the policy is attached to the person, not the meeting. ▶ 4:38
  • A filter that only records when external participants are present will fire on internal-only meetings if anyone starts the native Teams recording, because Microsoft's convenience recording bot is counted as a party external to the tenant. ▶ 5:10
  • No regulator certifies a recorder as MiFID II or HIPAA compliant — vendors provide the features (encryption, role-based playback, deletion workflows) that let the organisation achieve compliance. What can be verified is the platform's SOC 2 (Type 2 means an annual full audit of maintained controls) or ISO, which Levy says removes 30–40% of the friction in enterprise security reviews. ▶ 6:43
  • Microsoft's compliance recording certification requires a financial commitment, a mandatory premier support agreement (without it, tickets won't reach the engineering product team), an M365 security certification of comparable rigour to SOC 2, and third-party functional testing that changes as the SDK evolves. ▶ 10:46
  • Bot grouping and delta roster are both mandatory in this year's certification test plans. Grouping lets up to 100 recorded users from one domain share a bot; delta roster handles the fact that above roughly 70 participants Teams stops sending full roster events, which previously broke video and screen-share capture. ▶ 19:28
  • Before grouping, every recorded user added a participant to the meeting — 150 targeted users in one meeting became 300 participants against the meeting cap. Even with filters that exclude a meeting by title keyword, the bots still get signalled on join, so all-hands meetings create load spikes that platforms must be architected to absorb. ▶ 16:56
  • Check where transcription actually happens, not just where recordings are stored. Numonix uses Microsoft cognitive services so UK media stays in-region; a vendor using a third-party engine or an on-premises data centre component pulls that data — and its physical security controls — into your compliance scope. ▶ 27:08
  • Practical differentiators worth asking about: don't-record filters by meeting title keyword, organiser or Outlook colour category; targeting or excluding specific call queues by UPN so an IVR can route callers who decline recording to a non-recorded queue of the same agents; a native Teams app for record-on-demand, PCI silence insertion and GDPR cancel-and-purge; codec choice from GSM 8kHz (about 9.2 million minutes per terabyte) up to PCM 16 with split RX/TX streams; and SCIM provisioning driven from Entra groups. ▶ 29:39

Insights summarised by AI from the episode transcript, reviewed by the Empowering.Cloud team.

Listen: Apple Podcasts · Spotify · Other platforms