- Nationwide Digital Forensic & Cyber Investigation Services
Microsoft 365 holds the mail, files, chats and meeting records that most corporate matters turn on. Elite Digital Forensics works inside the tenant with counsel and information technology to place eDiscovery holds, run defensible compliance searches across Exchange Online, OneDrive, SharePoint and Teams, export with metadata intact, and analyze the unified audit log to establish who accessed, shared, forwarded, downloaded or deleted what.
Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Remote and on site service nationwide
Quick answer. Microsoft 365 E-Discovery uses the tenant's own compliance tooling to preserve and collect electronically stored information defensibly. eDiscovery holds preserve mailboxes, OneDrive accounts, SharePoint sites and Teams chats regardless of user deletion or retention policy. Compliance search locates responsive items by custodian, date, keyword and location, and export delivers the results with server side metadata. The unified audit log records access, sharing, download, rule creation, export and deletion activity and is the primary source for proving conduct rather than content. Audit and hold capability, and log retention length, depend on the tenant's license tier and should be verified before a protocol is negotiated.
| Question | Short answer |
|---|---|
| What does a hold cover? | Mailboxes, OneDrive accounts, SharePoint sites and Teams chat content in the specified scope. |
| Does a hold stop user deletion? | Yes. Deleted items are retained in a preservation location the user cannot reach. |
| What is collected from Teams? | Channel messages, chats, meeting records, shared files and membership changes. |
| Where do chat files live? | In OneDrive and SharePoint, so chat collection must include those locations. |
| How long are audit logs kept? | It depends on license and configuration; assume limited retention and preserve immediately. |
| Can you prove mass download? | Often, using file access, sync and sharing events in the unified audit log. |
| What about a departing employee? | Preserve before the license is reclaimed, or the mailbox and drive may be removed. |
| Is the export defensible? | Yes, when search criteria, results and hash verification are documented. |
A hold is the single most important early step in a Microsoft 365 matter. Once applied, content in the held locations is preserved even if a user deletes it, a retention policy would otherwise remove it, or the mailbox is later cleaned out. The user experience does not change, which matters when notifying a custodian is premature.
We document the hold: scope, accounts, date applied, who applied it and verification evidence. That record is what supports a reasonable steps argument under Rule 37(e).
Compliance search runs server side across selected locations using custodian, date range, keyword, Boolean and property based criteria. The value for litigation is repeatability: the criteria, the locations searched and the result statistics can be recorded, reviewed and rerun.
| Step | What we record |
|---|---|
| Scope definition | Custodians, locations, date ranges and any protocol driven limits |
| Search criteria | Exact query syntax, keyword lists and property filters used |
| Statistics | Item and volume counts per location, and hit counts by term |
| Refinement | Iterations made and why, so the final criteria are explainable |
| Export configuration | Format, deduplication and metadata options selected |
| Verification | Hash values on receipt, item count reconciliation and exception review |
Exported mail and file content is then processed conventionally: containers expanded, attachments extracted, duplicates removed across custodians, conversations threaded, time zones normalized and text extracted for search and review.
The unified audit log is the tenant wide activity record. In data theft, account compromise and spoliation matters it usually carries more weight than the documents, because it establishes conduct.
File accessed, downloaded, synced and copied events, with account, timestamp and network address, identify bulk collection of company data.
Sharing link creation, anonymous link generation, guest invitations and permission grants show data moving outside the organization.
New inbox rules, auto forwarding to external addresses and delegate grants often predate a departure by weeks.
Authentication records show location, client, device and success or failure, which identifies access after termination or from a competitor's network.
Hard and soft delete events, recycle bin activity and retention policy edits document removal and who performed it.
Compliance search, export, role assignment and configuration changes, including insider use of eDiscovery tooling.
Audit retention varies by license and configuration. Where log preservation is urgent, we extract and hash the relevant date range immediately rather than relying on the tenant to keep it.
Teams looks like one application and behaves like several storage locations. Chat messages and channel messages are retained through the mailbox and group mailbox structures, files shared in a private chat land in the sender's OneDrive, and files shared in a channel land in the team's SharePoint site. A collection that targets only the mailbox will miss the attachments, and a collection that targets only SharePoint will miss the conversation.
Teams productions also need presentation work. A raw export is difficult to read, so we typically deliver a threaded, time normalized report alongside the native export and load file set.
| Situation | Action before anything else |
|---|---|
| Resignation with suspicion of data theft | Apply a hold to mailbox, OneDrive and any owned sites, and extract the audit log for the preceding months |
| License needed for a replacement | Preserve or export the account first; reclaiming the license can remove the mailbox and drive |
| Account already deleted | Check for the recoverable soft deleted state immediately, as the recovery window is short |
| Suspected external sharing | Pull sharing link and permission events, then review guest access on relevant sites |
| Suspected forwarding | Pull rule creation and forwarding configuration events and compare against message trace data |
| Device also at issue | Collect the endpoint forensically as well, so sync, USB and local file artifacts corroborate the cloud record |
Cloud and endpoint evidence corroborate each other. A file access event in the audit log paired with a USB insertion and a matching local file path on the laptop is a far stronger showing than either artifact alone.
This page is part of the Elite Digital Forensics E-Discovery services hub. Related coverage:
We begin by verifying the tenant's license, hold and audit capability, then apply holds to every relevant location and extract the audit log range that matters. Compliance searches are scoped with counsel and fully documented, exports are hashed and reconciled on receipt, and content is processed and produced in the format the protocol requires. Where conduct is contested, we analyze the audit record, corroborate it with endpoint forensics and provide written findings and testimony.
Elite Digital Forensics is an independent digital forensics firm providing nationwide E-Discovery services, computer and mobile device forensics, cloud and email investigations and expert witness testimony. Our examiners include former law enforcement forensic examiners and court qualified expert witnesses. We work for law firms on both sides of the docket, for corporations and in house legal departments, and for insurers. When retained through counsel, our work is generally treated as attorney work product prepared in anticipation of litigation.
It is a preservation setting applied to specified locations, typically Exchange Online mailboxes, OneDrive accounts, SharePoint sites and the storage that backs Teams chat. Once active, content in those locations is retained even if the user deletes it or a retention policy would otherwise remove it. The user experience is unchanged, and the preserved copies are accessible to authorized administrators and examiners rather than the custodian.
Not from the platform itself. Holds and compliance searches operate server side with no user facing notification and no change to the mailbox or drive experience. Whether to notify custodians is a legal decision for counsel; the tooling does not force disclosure either way.
Retention depends on the license and the audit configuration, and higher tiers retain longer and record additional event types. Because retention is limited relative to most litigation timelines, the safe assumption is that log data will expire before discovery matures. We extract and hash the relevant date range early rather than relying on the tenant to preserve it.
Frequently, yes. The unified audit log records file access, download and sync activity, sharing link creation, permission changes and export events, with the account, timestamp and often the network address. Those records are strongest when correlated with endpoint forensics on the employee's computer, where USB history, link files and local paths corroborate the cloud events.
Act immediately. A deleted account and its associated mailbox and drive typically enter a short soft deleted state before permanent removal, and recovery within that window is often possible. Once the window closes, the mailbox and OneDrive content may be unrecoverable. Preserving before license reclamation is far more reliable than recovery afterwards.
Yes. Teams content is spread across storage locations: chat and channel messages are retained through mailbox structures, files shared in private chats live in the sender's OneDrive, and channel files live in the team's SharePoint site. A defensible Teams collection covers all of them, plus meeting artifacts and membership changes, and then presents the result as a threaded, time normalized report because raw exports are difficult to review.
The export is a good foundation, but defensibility comes from documentation. We record the search criteria and syntax, the locations searched, item and volume statistics, export configuration, hash values on receipt, item count reconciliation and any exceptions the platform reported. That record allows the collection to be explained, reproduced or challenged on the merits.
Yes. In many engagements a client administrator performs the configuration steps under our written direction and on a recorded session, with our examiner defining scope, verifying results and documenting the process. Where the client prefers, a scoped compliance role can be assigned to our examiner instead. Either approach is documented for the record.
#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #EDiscovery #EDiscoveryServices #ESI #ElectronicDiscovery #ChainOfCustody #ForensicCollection #LitigationSupport #ESIPreservation
This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic and E-Discovery services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.
Elite Digital ForensicsΒ is a Professional Digital Forensics and Cyber Consulting Company that provides services nationwide.Β
Elite Digital Forensics Assistant
By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β
IMPORTANT: Please remember to check your spam or junk folder
We use cookies for site functionality and, only with your permission, analytics and advertising. See our Privacy Policy for details. California residents have the right to Do Not Sell or Share My Personal Information.