A cloud-based identity and access management service for securing user authentication and resource access
Graph app-only: onlineMeetings transcripts and recordings suddenly return 403 "UnknownError" mid-day, while meeting metadata on the same meeting returns 200
Application-permission access to Teams meeting transcripts and recordings stopped working in our tenant part-way through a single day. It had been working daily for the previous two weeks. Meeting metadata for the very same meetings, requested with the same token seconds apart, still returns 200.
I have already checked everything in the standard guidance, so I would appreciate help working out what else evaluates these two endpoints.
{
"error": {
"code": "Forbidden",
"message": "UnknownError",
"innerError": {
"date": "2026-10-09T14:07:18",
"request-id": "3386e034-88d0-488f-8619-1d661c1d6ff8",
"client-request-id": "3386e034-88d0-488f-8619-1d661c1d6ff8"
}
}
}
Succeeding (200) — same token, same meeting, same minute:
GET /v1.0/users/{organizerId}/onlineMeetings/{meetingId} -> 200
GET /v1.0/users/{organizerId}/onlineMeetings/{meetingId}/attendanceReports -> 200
GET /v1.0/users/{organizerId}/events and /calendarView -> 200
## It worked earlier the same day
2026-10-09 07:33:15Z GET .../transcripts/{id}/content?$format=text/vtt 200 OK
2026-10-09 07:34:17Z (our pipeline then emailed the meeting summary normally)
---- access lost somewhere in this gap, no change on our side ----
2026-10-09 09:22:32Z GET .../transcripts/{id} 403 Forbidden
2026-10-09 14:07:17Z still 403
## Already verified — please don't stop at these
1. **Application permissions.** The issued access token's `roles` claim contains `OnlineMeetingTranscript.Read.All`, `OnlineMeetingRecording.Read.All` and `OnlineMeetingArtifact.Read.All`. Admin consent is in place. I decoded the JWT to confirm this, rather than trusting the portal.
2. **Application access policy.** `Get-CsApplicationAccessPolicy` shows the **Global** policy with `AppIds {our-app-id}`, plus a named policy with the same AppId. The AppId is the application (client) ID, not the service principal object ID.
3. **The new July 2026 tenant control.** `Get-CsTeamsMeetingConfiguration` reports:
- `EnableGraphTranscriptAccess : True`
- `EnableAttributedTranscripts : True`
I know this control exists and is off by default. If it were the cause, the documented response is `403` with inner-error **`GraphAccessToTranscriptsDisabled`** and the message "Graph API access to transcripts is disabled for this tenant". We get neither — our message is the generic `UnknownError` with no inner code.
1What else, besides Graph application permissions, the application access policy, and `EnableGraphTranscriptAccess`, can cause **403 `Forbidden` / `UnknownError` with no inner-error code** specifically on `/transcripts` and `/recordings` while `/onlineMeetings/{id}` and `/attendanceReports` on the same meeting return 200 with the same token?
## Graph request-ids (all 2026-10-09, UTC)
Failing:
14:07:17Z transcripts organizer A 403 request-id 3386e034-88d0-488f-8619-1d661c1d6ff8
14:07:19Z recordings organizer A 403 request-id 32f2983d-54ce-4405-b623-e639aa07a3a8
14:07:20Z transcripts organizer B 403 request-id 2768f0ff-bb79-477c-ad0f-847d2cd6574c
14:07:21Z recordings organizer B 403 request-id 92ba0a0b-9339-4ea5-a290-1e41994b92fc
Thanks — happy to run any specific request and share the `request-id`, or provide tenant and app IDs privately.