Microsoft Purview eDiscovery
Microsoft Purview eDiscovery identifies, preserves, collects, reviews, analyses, and exports
content across Microsoft 365 (Exchange, SharePoint, OneDrive, Teams, Copilot interactions) for
legal cases, regulatory requests, and internal investigations - following the EDRM workflow with
defensibility at every step.
When to use
Responding to litigation, regulatory, or HR/investigation requests requiring defensible content
preservation and production from Microsoft 365.
Do not use this skill for routine audit-log searches without a legal/investigation matter
(use purview-audit) or for retention policy design (use purview-data-lifecycle).
Pick the right matter type
| Matter |
Approach |
| Litigation with named custodians |
Full case: custodians on hold, collection, review set, export |
| Regulatory request, broad scope |
Non-custodial data sources + searches + review set |
| HR investigation, single user |
Lightweight case with targeted hold + collection (no review set if simple) |
| Quick fact-finding, no preservation duty |
purview-audit instead |
Rule of thumb: if there is any preservation duty, open a case and apply a hold before you
search - searches without holds risk spoliation if a custodian deletes content during triage.
Approach
- Create a case - Organise the matter in an eDiscovery case; assign role-scoped reviewers
(eDiscovery Manager vs Reviewer) and record matter metadata.
Verify: the case appears in the eDiscovery solution and only assigned users can open it.
- Add custodians and non-custodial sources - Identify people and locations in scope;
non-custodial sources cover sites/mailboxes not tied to a person.
Verify: custodian status shows hold pending or applied.
- Apply legal holds - Place custodians/data sources on hold before any collection;
confirm hold receipt where required.
Verify: hold status is Active for all custodians and shows source coverage (mailbox, OneDrive, sites, Teams).
- Build searches - Run draft searches with keywords, conditions, date ranges, and locations;
review statistics and refine before committing to a collection.
Verify: search statistics show estimated item count and size; top locations look sensible.
- Commit to a collection and review set - Commit refined results to a review set; use
analytics (near-duplicate, email threading, themes) and tagging to cull.
Verify: review set indexing completes and analytics tiles populate.
- Review and tag - Reviewers tag responsive/privileged/etc.; redact where supported; track
reviewer progress.
Verify: tagging history is auditable per reviewer.
- Export and produce - Export reviewed content in a defensible format with a load file
suitable for downstream review platforms.
Verify: export package includes load file, native files, and a manifest with hashes.
Guardrails
- Apply holds before searching/collecting to ensure defensibility - a search without a hold
can be argued away.
- The current unified eDiscovery experience consolidates prior Standard and Premium - confirm
feature availability against your licensing (advanced features like review sets, analytics,
and Copilot interaction collection require E5 / E5 Compliance / eDiscovery Premium add-on).
- Scope access tightly; eDiscovery can reach highly sensitive content, including content sensitivity
labels would otherwise restrict - use role groups and case-level membership, not tenant-wide grants.
- Hold notification, custodian acknowledgements, and chain-of-custody records belong outside Purview
(matter management system) - eDiscovery is the technical tool, not the legal record.
- Test export against your review platform's load-file expectations before the deadline.
Common anti-patterns
- Running a tenant-wide content search and skipping the hold step "to save time".
- Granting eDiscovery Manager broadly instead of per-case Reviewer assignment.
- Forgetting to add Teams chat / Copilot interaction locations when scoping.
- Exporting from a search instead of from a reviewed review set (no defensible review trail).
- Closing the case (and releasing holds) before legal confirms the matter is concluded.
Example prompts
Create an eDiscovery case with legal hold to preserve content.
Collect and review content for litigation in a review set.
How do I export evidence and manage custodians?
Run search and hold across Microsoft 365 for an investigation.
Apply analytics and near-duplicate detection to cull a large review set.
Microsoft Learn
1---2name: purview-ediscovery3description: Guidance for Microsoft Purview eDiscovery (unified experience consolidating prior Standard and Premium) - identifying, preserving, collecting, reviewing, analysing, and exporting content across Microsoft 365 for legal cases, regulatory requests, and investigations. Covers cases, custodians, legal holds, searches, review sets, analytics, and export. WHEN: eDiscovery, legal hold, preserve content, collect for litigation, review set, export evidence, eDiscovery case, custodian, search and hold Microsoft 365, legal investigation, EDRM workflow, defensible collection.4license: MIT5---67# Microsoft Purview eDiscovery89Microsoft Purview eDiscovery identifies, preserves, collects, reviews, analyses, and exports10content across Microsoft 365 (Exchange, SharePoint, OneDrive, Teams, Copilot interactions) for11legal cases, regulatory requests, and internal investigations - following the EDRM workflow with12defensibility at every step.1314## When to use15Responding to litigation, regulatory, or HR/investigation requests requiring defensible content16preservation and production from Microsoft 365.1718Do not use this skill for routine audit-log searches without a legal/investigation matter19(use `purview-audit`) or for retention policy design (use `purview-data-lifecycle`).2021## Pick the right matter type22| Matter | Approach |23|---|---|24| Litigation with named custodians | Full case: custodians on hold, collection, review set, export |25| Regulatory request, broad scope | Non-custodial data sources + searches + review set |26| HR investigation, single user | Lightweight case with targeted hold + collection (no review set if simple) |27| Quick fact-finding, no preservation duty | `purview-audit` instead |2829Rule of thumb: if there is any preservation duty, open a case and apply a hold **before** you30search - searches without holds risk spoliation if a custodian deletes content during triage.3132## Approach331. **Create a case** - Organise the matter in an eDiscovery case; assign role-scoped reviewers34 (eDiscovery Manager vs Reviewer) and record matter metadata.35 *Verify: the case appears in the eDiscovery solution and only assigned users can open it.*362. **Add custodians and non-custodial sources** - Identify people and locations in scope;37 non-custodial sources cover sites/mailboxes not tied to a person.38 *Verify: custodian status shows hold pending or applied.*393. **Apply legal holds** - Place custodians/data sources on **hold** before any collection;40 confirm hold receipt where required.41 *Verify: hold status is Active for all custodians and shows source coverage (mailbox, OneDrive, sites, Teams).*424. **Build searches** - Run draft searches with keywords, conditions, date ranges, and locations;43 review statistics and refine before committing to a collection.44 *Verify: search statistics show estimated item count and size; top locations look sensible.*455. **Commit to a collection and review set** - Commit refined results to a **review set**; use46 analytics (near-duplicate, email threading, themes) and tagging to cull.47 *Verify: review set indexing completes and analytics tiles populate.*486. **Review and tag** - Reviewers tag responsive/privileged/etc.; redact where supported; track49 reviewer progress.50 *Verify: tagging history is auditable per reviewer.*517. **Export and produce** - Export reviewed content in a defensible format with a load file52 suitable for downstream review platforms.53 *Verify: export package includes load file, native files, and a manifest with hashes.*5455## Guardrails56- Apply holds **before** searching/collecting to ensure defensibility - a search without a hold57 can be argued away.58- The current unified eDiscovery experience consolidates prior Standard and Premium - confirm59 feature availability against your licensing (advanced features like review sets, analytics,60 and Copilot interaction collection require E5 / E5 Compliance / eDiscovery Premium add-on).61- Scope access tightly; eDiscovery can reach highly sensitive content, including content sensitivity62 labels would otherwise restrict - use role groups and case-level membership, not tenant-wide grants.63- Hold notification, custodian acknowledgements, and chain-of-custody records belong outside Purview64 (matter management system) - eDiscovery is the technical tool, not the legal record.65- Test export against your review platform's load-file expectations before the deadline.6667## Common anti-patterns68- Running a tenant-wide content search and skipping the hold step "to save time".69- Granting eDiscovery Manager broadly instead of per-case Reviewer assignment.70- Forgetting to add Teams chat / Copilot interaction locations when scoping.71- Exporting from a search instead of from a reviewed review set (no defensible review trail).72- Closing the case (and releasing holds) before legal confirms the matter is concluded.7374## Example prompts75- `Create an eDiscovery case with legal hold to preserve content.`76- `Collect and review content for litigation in a review set.`77- `How do I export evidence and manage custodians?`78- `Run search and hold across Microsoft 365 for an investigation.`79- `Apply analytics and near-duplicate detection to cull a large review set.`8081## Microsoft Learn82- eDiscovery overview: https://learn.microsoft.com/purview/edisc83- Get started with eDiscovery: https://learn.microsoft.com/purview/ediscovery-standard-get-started84- Create and manage holds: https://learn.microsoft.com/purview/ediscovery-create-holds85- Manage review sets: https://learn.microsoft.com/purview/ediscovery-managing-review-sets86- Export from a review set: https://learn.microsoft.com/purview/ediscovery-export-documents-from-review-set87- Role and permissions: https://learn.microsoft.com/purview/ediscovery-assign-permissions