Purview, Exchange Online, Teams and SharePoint

Microsoft 365 E-DiscoveryHolds, Compliance Search, Exports and Audit Log Analysis

Microsoft 365 holds the mail, files, chats and meeting records that most corporate matters turn on. Elite Digital Forensics works inside the tenant with counsel and information technology to place eDiscovery holds, run defensible compliance searches across Exchange Online, OneDrive, SharePoint and Teams, export with metadata intact, and analyze the unified audit log to establish who accessed, shared, forwarded, downloaded or deleted what.

Updated August 2026 · Reviewed by Elite Digital Forensics examiners · Remote and on site service nationwide

Part of our nationwide E-Discovery services

Holds firstAn eDiscovery hold preserves mailbox and site content even when a user deletes it.
Unified logThe unified audit log is the tenant wide record of access, sharing, export and deletion events.
License boundRetention length and advanced audit events vary by license, so capability is verified up front.
No downtimeHolds, searches and exports run server side without interrupting users.

Quick answer. Microsoft 365 E-Discovery uses the tenant's own compliance tooling to preserve and collect electronically stored information defensibly. eDiscovery holds preserve mailboxes, OneDrive accounts, SharePoint sites and Teams chats regardless of user deletion or retention policy. Compliance search locates responsive items by custodian, date, keyword and location, and export delivers the results with server side metadata. The unified audit log records access, sharing, download, rule creation, export and deletion activity and is the primary source for proving conduct rather than content. Audit and hold capability, and log retention length, depend on the tenant's license tier and should be verified before a protocol is negotiated.

Common questions, answered in one line

QuestionShort answer
What does a hold cover?Mailboxes, OneDrive accounts, SharePoint sites and Teams chat content in the specified scope.
Does a hold stop user deletion?Yes. Deleted items are retained in a preservation location the user cannot reach.
What is collected from Teams?Channel messages, chats, meeting records, shared files and membership changes.
Where do chat files live?In OneDrive and SharePoint, so chat collection must include those locations.
How long are audit logs kept?It depends on license and configuration; assume limited retention and preserve immediately.
Can you prove mass download?Often, using file access, sync and sharing events in the unified audit log.
What about a departing employee?Preserve before the license is reclaimed, or the mailbox and drive may be removed.
Is the export defensible?Yes, when search criteria, results and hash verification are documented.

eDiscovery Holds and Retention

A hold is the single most important early step in a Microsoft 365 matter. Once applied, content in the held locations is preserved even if a user deletes it, a retention policy would otherwise remove it, or the mailbox is later cleaned out. The user experience does not change, which matters when notifying a custodian is premature.

What a hold covers

  • Exchange Online mailbox content, including items the user deletes and recoverable items
  • OneDrive for Business files and version history
  • SharePoint site content within scope, including document libraries and lists
  • Teams chat and channel messages, which are stored in the underlying mailbox and site structures
  • Optionally a query based scope, though full location holds are easier to defend

Hold pitfalls we check for

  • A hold applied to the mailbox but not to the OneDrive account where the files actually live
  • Teams content missed because chat files reside in OneDrive and channel files in SharePoint
  • A departing employee's license reclaimed before the hold was verified, removing the mailbox and drive
  • Retention policies edited after the duty to preserve attached, which is itself a documentable event
  • A hold configured but never confirmed as active, which is discovered at the worst possible time
  • Shared and resource mailboxes overlooked because they are not tied to a named custodian

We document the hold: scope, accounts, date applied, who applied it and verification evidence. That record is what supports a reasonable steps argument under Rule 37(e).

Unified Audit Log Analysis

The unified audit log is the tenant wide activity record. In data theft, account compromise and spoliation matters it usually carries more weight than the documents, because it establishes conduct.

File access and download

File accessed, downloaded, synced and copied events, with account, timestamp and network address, identify bulk collection of company data.

Sharing and permissions

Sharing link creation, anonymous link generation, guest invitations and permission grants show data moving outside the organization.

Mailbox rules and forwarding

New inbox rules, auto forwarding to external addresses and delegate grants often predate a departure by weeks.

Sign in activity

Authentication records show location, client, device and success or failure, which identifies access after termination or from a competitor's network.

Deletion and purge

Hard and soft delete events, recycle bin activity and retention policy edits document removal and who performed it.

Administrative actions

Compliance search, export, role assignment and configuration changes, including insider use of eDiscovery tooling.

Audit retention varies by license and configuration. Where log preservation is urgent, we extract and hash the relevant date range immediately rather than relying on the tenant to keep it.

Collecting Microsoft Teams Correctly

Teams looks like one application and behaves like several storage locations. Chat messages and channel messages are retained through the mailbox and group mailbox structures, files shared in a private chat land in the sender's OneDrive, and files shared in a channel land in the team's SharePoint site. A collection that targets only the mailbox will miss the attachments, and a collection that targets only SharePoint will miss the conversation.

  • One to one and group chat messages, with participants, timestamps and edit or delete indicators
  • Channel conversations, including replies and reactions where retained
  • Files shared in chats and channels, collected from OneDrive and SharePoint with version history
  • Meeting artifacts including invitations, chat, recordings and transcripts where recording is enabled
  • Membership and team lifecycle changes, including team deletion and archival
  • Retention policy configuration, since Teams content is frequently subject to short retention

Teams productions also need presentation work. A raw export is difficult to read, so we typically deliver a threaded, time normalized report alongside the native export and load file set.

Departing Employee Scenarios in Microsoft 365

SituationAction before anything else
Resignation with suspicion of data theftApply a hold to mailbox, OneDrive and any owned sites, and extract the audit log for the preceding months
License needed for a replacementPreserve or export the account first; reclaiming the license can remove the mailbox and drive
Account already deletedCheck for the recoverable soft deleted state immediately, as the recovery window is short
Suspected external sharingPull sharing link and permission events, then review guest access on relevant sites
Suspected forwardingPull rule creation and forwarding configuration events and compare against message trace data
Device also at issueCollect the endpoint forensically as well, so sync, USB and local file artifacts corroborate the cloud record

Cloud and endpoint evidence corroborate each other. A file access event in the audit log paired with a USB insertion and a matching local file path on the laptop is a far stronger showing than either artifact alone.

How Elite Digital Forensics Helps

We begin by verifying the tenant's license, hold and audit capability, then apply holds to every relevant location and extract the audit log range that matters. Compliance searches are scoped with counsel and fully documented, exports are hashed and reconciled on receipt, and content is processed and produced in the format the protocol requires. Where conduct is contested, we analyze the audit record, corroborate it with endpoint forensics and provide written findings and testimony.

About Elite Digital Forensics

Elite Digital Forensics is an independent digital forensics firm providing nationwide E-Discovery services, computer and mobile device forensics, cloud and email investigations and expert witness testimony. Our examiners include former law enforcement forensic examiners and court qualified expert witnesses. We work for law firms on both sides of the docket, for corporations and in house legal departments, and for insurers. When retained through counsel, our work is generally treated as attorney work product prepared in anticipation of litigation.

Frequently asked questions

What is a Microsoft 365 eDiscovery hold and what does it preserve?

It is a preservation setting applied to specified locations, typically Exchange Online mailboxes, OneDrive accounts, SharePoint sites and the storage that backs Teams chat. Once active, content in those locations is retained even if the user deletes it or a retention policy would otherwise remove it. The user experience is unchanged, and the preserved copies are accessible to authorized administrators and examiners rather than the custodian.

Will users know a hold or a search has been applied?

Not from the platform itself. Holds and compliance searches operate server side with no user facing notification and no change to the mailbox or drive experience. Whether to notify custodians is a legal decision for counsel; the tooling does not force disclosure either way.

How long does Microsoft retain audit log data?

Retention depends on the license and the audit configuration, and higher tiers retain longer and record additional event types. Because retention is limited relative to most litigation timelines, the safe assumption is that log data will expire before discovery matures. We extract and hash the relevant date range early rather than relying on the tenant to preserve it.

Can you prove that a departing employee downloaded files?

Frequently, yes. The unified audit log records file access, download and sync activity, sharing link creation, permission changes and export events, with the account, timestamp and often the network address. Those records are strongest when correlated with endpoint forensics on the employee's computer, where USB history, link files and local paths corroborate the cloud events.

What happens if the employee's account was already deleted?

Act immediately. A deleted account and its associated mailbox and drive typically enter a short soft deleted state before permanent removal, and recovery within that window is often possible. Once the window closes, the mailbox and OneDrive content may be unrecoverable. Preserving before license reclamation is far more reliable than recovery afterwards.

Does collecting Teams require anything special?

Yes. Teams content is spread across storage locations: chat and channel messages are retained through mailbox structures, files shared in private chats live in the sender's OneDrive, and channel files live in the team's SharePoint site. A defensible Teams collection covers all of them, plus meeting artifacts and membership changes, and then presents the result as a threaded, time normalized report because raw exports are difficult to review.

Is a Purview export by itself a defensible collection?

The export is a good foundation, but defensibility comes from documentation. We record the search criteria and syntax, the locations searched, item and volume statistics, export configuration, hash values on receipt, item count reconciliation and any exceptions the platform reported. That record allows the collection to be explained, reproduced or challenged on the merits.

Can you work inside our tenant without administrative credentials being shared?

Yes. In many engagements a client administrator performs the configuration steps under our written direction and on a recorded session, with our examiner defining scope, verifying results and documenting the process. Where the client prefers, a scoped compliance role can be assigned to our examiner instead. Either approach is documented for the record.

References and authoritative sources

  1. Federal Rule of Civil Procedure 26, duty to disclose and general provisions governing discovery. law.cornell.edu
  2. Federal Rule of Civil Procedure 34, producing documents and electronically stored information. law.cornell.edu
  3. Federal Rule of Civil Procedure 37(e), failure to preserve electronically stored information. law.cornell.edu
  4. Federal Rules of Evidence 902(13) and 902(14), self authentication of electronic records and hash verified copies. law.cornell.edu
  5. Microsoft, eDiscovery and Purview documentation for holds, searches and exports. learn.microsoft.com
  6. Microsoft, search the audit log in the Microsoft Purview compliance portal. learn.microsoft.com
  7. National Institute of Standards and Technology, SP 800-86, Guide to Integrating Forensic Techniques into Incident Response. csrc.nist.gov
  8. The Sedona Conference, Principles Addressing Electronic Document Production. thesedonaconference.org
  9. EDRM, the Electronic Discovery Reference Model framework. edrm.net

#DigitalForensics #ComputerForensics #CellPhoneForensics #ExpertWitness #DigitalForensicExperts #EliteDigitalForensics #ForensicInvestigation #EDiscovery #EDiscoveryServices #ESI #ElectronicDiscovery #ChainOfCustody #ForensicCollection #LitigationSupport #ESIPreservation

This content is for educational and informational purposes only and does not constitute legal advice. Elite Digital Forensics provides independent digital forensic and E-Discovery services and expert witness testimony; we do not provide legal representation. Every case is fact specific; outcomes depend on the evidence, jurisdiction, and counsel. Retain qualified legal counsel for advice about your matter.

Assistant Icon Elite Digital Forensics Assistant
πŸ‘‹ Live Chat Now!
Free Virtual Consultation 24/7
Chat Now!

By submitting this form, you consent to be contacted by email, text, or phone. Your information is kept secure and confidential. Reply Stop to opt out at anytime.Β 

IMPORTANT: Please remember to check your spam or junk folder