Graph app-only: onlineMeetings transcripts and recordings suddenly return 403 "UnknownError" mid-day, while meeting metadata on the same meeting returns 200

Santosh Chintapally 0 Reputation points
2026-10-09T15:07:14.26+00:00

Application-permission access to Teams meeting transcripts and recordings stopped working in our tenant part-way through a single day. It had been working daily for the previous two weeks. Meeting metadata for the very same meetings, requested with the same token seconds apart, still returns 200.

I have already checked everything in the standard guidance, so I would appreciate help working out what else evaluates these two endpoints.

{

"error": {

"code": "Forbidden",

"message": "UnknownError",

"innerError": {

  "date": "2026-10-09T14:07:18",

  "request-id": "3386e034-88d0-488f-8619-1d661c1d6ff8",

  "client-request-id": "3386e034-88d0-488f-8619-1d661c1d6ff8"

}

}

}


Succeeding (200) — same token, same meeting, same minute:

GET /v1.0/users/{organizerId}/onlineMeetings/{meetingId} -> 200

GET /v1.0/users/{organizerId}/onlineMeetings/{meetingId}/attendanceReports -> 200

GET /v1.0/users/{organizerId}/events and /calendarView -> 200


## It worked earlier the same day

2026-10-09 07:33:15Z GET .../transcripts/{id}/content?$format=text/vtt 200 OK

2026-10-09 07:34:17Z (our pipeline then emailed the meeting summary normally)

    ---- access lost somewhere in this gap, no change on our side ----

2026-10-09 09:22:32Z GET .../transcripts/{id} 403 Forbidden

2026-10-09 14:07:17Z still 403


## Already verified — please don't stop at these

1. **Application permissions.** The issued access token's `roles` claim contains `OnlineMeetingTranscript.Read.All`, `OnlineMeetingRecording.Read.All` and `OnlineMeetingArtifact.Read.All`. Admin consent is in place. I decoded the JWT to confirm this, rather than trusting the portal.

2. **Application access policy.** `Get-CsApplicationAccessPolicy` shows the **Global** policy with `AppIds {our-app-id}`, plus a named policy with the same AppId. The AppId is the application (client) ID, not the service principal object ID.

3. **The new July 2026 tenant control.** `Get-CsTeamsMeetingConfiguration` reports:

   - `EnableGraphTranscriptAccess : True`

   - `EnableAttributedTranscripts : True`

   I know this control exists and is off by default. If it were the cause, the documented response is `403` with inner-error **`GraphAccessToTranscriptsDisabled`** and the message "Graph API access to transcripts is disabled for this tenant". We get neither — our message is the generic `UnknownError` with no inner code.

1What else, besides Graph application permissions, the application access policy, and `EnableGraphTranscriptAccess`, can cause **403 `Forbidden` / `UnknownError` with no inner-error code** specifically on `/transcripts` and `/recordings` while `/onlineMeetings/{id}` and `/attendanceReports` on the same meeting return 200 with the same token?

## Graph request-ids (all 2026-10-09, UTC)

Failing:

14:07:17Z transcripts organizer A 403 request-id 3386e034-88d0-488f-8619-1d661c1d6ff8

14:07:19Z recordings organizer A 403 request-id 32f2983d-54ce-4405-b623-e639aa07a3a8

14:07:20Z transcripts organizer B 403 request-id 2768f0ff-bb79-477c-ad0f-847d2cd6574c

14:07:21Z recordings organizer B 403 request-id 92ba0a0b-9339-4ea5-a290-1e41994b92fc


Thanks — happy to run any specific request and share the `request-id`, or provide tenant and app IDs privately.
Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.