Use a Microsoft Purview retention policy (or retention labels) when you need to keep mailbox content for a defined period for compliance, use an eDiscovery hold inside a Purview case when you must preserve specific people's content for a legal matter, and treat Litigation Hold as a supported but older option for preserving a whole mailbox. All three keep deleted and edited items in the Recoverable Items folder and raise its quota to 100 GB, and when they overlap, retention beats deletion and an eDiscovery hold beats everything until it is released.
Who this is for and what you will have at the end
This guide is for Exchange Online administrators and compliance teams who are asked to "put a mailbox on hold" and need to choose the right mechanism, apply it, and later prove which holds are in place.
At the end you will have:
- A comparison of the three preservation methods and when each fits.
- Steps and PowerShell to apply each one.
- A repeatable way to list every hold on a mailbox and decode it.
- A safe process for removing holds, including the 30-day delay hold and inactive mailboxes.
The three methods at a glance
| Litigation Hold | Purview retention policy | eDiscovery hold | |
|---|---|---|---|
| Designed for | Preserving an entire mailbox | Long-term compliance lifecycle | A specific legal investigation |
| Scope | Individual mailboxes | Broad: all mailboxes, groups or scopes | Specific people, groups and sites in a case |
| Covers | Mailbox and archive | Exchange, SharePoint, OneDrive, Teams and more | Mailboxes and SharePoint or OneDrive sites |
| Duration | Indefinite or a number of days | Configurable, with optional automatic deletion | Until an administrator releases it |
| Deletes content at the end | Hold just stops preserving | Optional (retain and then delete) | No |
| Where you manage it | Microsoft 365 admin center or Exchange Online PowerShell | Purview portal or Security & Compliance PowerShell | Purview eDiscovery case |
| Typical time to apply | Admin center warns up to 240 minutes | Allow up to seven days | Up to 24 hours |
| Licensing note | Exchange Online Plan 2, or Plan 1 plus Exchange Online Archiving | See the Purview service description | Eligible licence on every held user; query-based and time-bound holds need E5-tier rights |
Microsoft's own summary of retention versus eDiscovery holds: retention is for compliance, long-term, broad and content-based, with configurable start and end and low administrative overhead; eDiscovery holds are for legal needs, short-term, specific and user-based, with no automatic deletion and higher overhead. Litigation Hold remains supported, but Microsoft recommends retention or eDiscovery holds instead.
How preservation works inside the mailbox
All three methods use the hidden Recoverable Items folder:
- Deletions receives items deleted from Deleted Items or with Shift+Delete. Users can still recover them.
- Purges holds hard-deleted items when Litigation Hold or single item recovery is enabled.
- Versions keeps the original copy of an item before it is modified, through copy-on-write, when In-Place Hold, Litigation Hold or a retention policy applies.
- DiscoveryHolds keeps hard-deleted items when an In-Place Hold or a retention policy applies, and purged items when an eDiscovery case hold applies.
- SubstrateHolds keeps original copies of modified or deleted Teams messages.
Quotas change when a hold applies. By default the Recoverable Items folder has a 20 GB warning and 30 GB hard limit. On Litigation Hold, In-Place Hold or a retention policy these rise to 90 GB and 100 GB; with an archive enabled the hard limit becomes 105 GB, and with auto-expanding archiving the primary mailbox's Recoverable Items folder gets 110 GB. When the folder fills, users can't delete items and copy-on-write can't keep versions, so monitor held mailboxes.
When to use which
- Regulatory requirement to keep all email for N years. Use a retention policy on the Exchange email location with a retain or retain-then-delete action. It applies to the whole location rather than to a list of mailboxes captured by a script (a bulk
Set-MailboxLitigation Hold command only covers mailboxes that exist when you run it), and it can delete content when the period ends. - Lawsuit or internal investigation naming specific people. Use an eDiscovery hold in a Purview case, covering their mailboxes, OneDrive accounts and relevant team mailboxes and sites. See the Purview eDiscovery guide for the full case workflow.
- Leaver whose mailbox must be kept. Apply a retention policy or retention label that retains content, confirm the hold, then delete the account so the mailbox becomes inactive. Microsoft recommends retention for this, not eDiscovery holds.
- Quick whole-mailbox preservation in an existing Exchange process. Litigation Hold still works, but plan to move to retention or eDiscovery holds.
Avoid using eDiscovery holds for long-term retention. If the case is closed or the hold released, an inactive mailbox kept only by that hold is permanently deleted.
Apply Litigation Hold
In the Microsoft 365 admin center:
- Go to Users > Active users and select the user.
- On the Mail tab, under More actions, select Manage litigation hold.
- Select Turn on litigation hold. Optionally set Hold duration (days), a Note visible to the user and a Web page with more information for the user.
- Select Save changes. The banner warns it can take up to 240 minutes to take effect.
In Exchange Online PowerShell:
Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
# Indefinite hold
Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $true
# Time-based hold, about seven years
Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $true -LitigationHoldDuration 2555
Get-Mailbox lee.gu@contoso.com | Format-List LitigationHold*The hold duration is counted from when each item was received or created. An indefinite hold shows LitigationHoldDuration as Unlimited.
Apply a Purview retention policy to mailboxes
You can create the policy in the Purview portal under Data Lifecycle Management, or in Security & Compliance PowerShell. The policy's retention settings come from a rule that you add with New-RetentionComplianceRule, and each retention policy can have only one rule.
Connect-IPPSSession -UserPrincipalName admin@contoso.com
New-RetentionCompliancePolicy -Name "Exchange - keep 7 years" -ExchangeLocation All
New-RetentionComplianceRule -Name "Keep 7 years" -Policy "Exchange - keep 7 years" -RetentionDuration 2555 -RetentionComplianceAction KeepRetentionComplianceAction accepts Keep, Delete and KeepAndDelete; RetentionDuration accepts a number of days or Unlimited. Always set the action explicitly: the cmdlet reference notes that without it the policy is created as a UniH policy instead of an mbx policy. Allow up to seven days for the policy to apply.
If a regulator requires that nobody can weaken the policy, Preservation Lock (-RestrictiveRetention $true) locks it so it can only be extended. That is irreversible, so lock only after the policy is final.
Apply an eDiscovery hold
In the Purview portal: eDiscovery > Cases > your case > Hold policies > Create policy, add data sources, optionally add a query, then Apply hold. Allow up to 24 hours, and remember that group membership is captured as a snapshot when the hold is created.
Find every hold on a mailbox
Run this in Exchange Online PowerShell:
Get-Mailbox lee.gu@contoso.com | Format-List LitigationHoldEnabled,InPlaceHolds,ComplianceTagHoldApplied,*HoldApplied*
Get-Mailbox lee.gu@contoso.com | Select-Object -ExpandProperty InPlaceHolds
Get-OrganizationConfig | Select-Object -ExpandProperty InPlaceHoldsDecode the InPlaceHolds values like this:
| Value pattern | Meaning |
|---|---|
LitigationHoldEnabled : True | Litigation Hold is on |
UniH prefix | eDiscovery case hold |
mbx prefix | Retention policy applied to this mailbox (on the mailbox) or to all mailboxes (on the organisation config) |
skp prefix | Retention policy for Skype for Business conversations |
grp prefix (organisation config) | Retention policy for Microsoft 365 Groups and Teams channel messages |
-mbx prefix | Mailbox is excluded from an organisation-wide retention policy |
No prefix or cld prefix | Legacy In-Place Hold |
Suffix :1, :2, :3 | Delete (or label publishing), retain, or retain then delete |
ComplianceTagHoldApplied : True | A retaining retention label is applied to a folder or item |
To name the policy behind a GUID, strip the prefix and suffix and look it up in Security & Compliance PowerShell:
Get-RetentionCompliancePolicy <GUID> -DistributionDetail | Format-List Name,*Location
$CaseHold = Get-CaseHoldPolicy <GUID>
Get-ComplianceCase $CaseHold.CaseId | Format-List NameSome newer retention locations, such as Teams chats and Copilot experiences, don't stamp mailbox objects; use Policy lookup or Get-AppRetentionCompliancePolicy for those.
Remove a hold safely
- Litigation Hold:
Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $false. - Retention policy: exclude the mailbox, turn the location off or delete the policy (not possible with Preservation Lock).
- eDiscovery hold: remove the location from the hold policy, release the hold or close the case. Closing or deleting a case turns off all its holds.
After any hold is removed, the Managed Folder Assistant applies a 30-day delay hold by setting DelayHoldApplied (Outlook content) or DelayReleaseHoldApplied (Teams and other app data) to True. The mailbox is treated as on hold until it expires. If you are sure, you can remove it early; this needs the Legal Hold role:
Set-Mailbox lee.gu@contoso.com -RemoveDelayHoldApplied
Set-Mailbox lee.gu@contoso.com -RemoveDelayReleaseHoldAppliedTroubleshooting
- Manage litigation hold is missing in the admin center. The mailbox probably lacks an Exchange Online Plan 2 licence, or Plan 1 plus Exchange Online Archiving.
- Users can't delete items and versions stop being saved. The Recoverable Items folder has hit its quota. Check it with
Get-MailboxFolderStatistics, and consider auto-expanding archiving. - Deleted user's mailbox didn't become inactive. The policy was delete-only, or the hold hadn't applied when the account was deleted. Retention must retain or retain-then-delete, and you should confirm the hold before deleting the account.
- Can't delete an inactive mailbox from a retention policy. The UPN or primary SMTP address was changed before the account was deleted, so the mailbox can't be matched to the policy any more. Don't change them before deletion.
- Delay hold never clears. The user account is disabled, so the mailbox isn't processed. Remove it with the parameters above.
- Policy applied but
InPlaceHoldsis empty. CheckGet-OrganizationConfigfor organisation-wide policies, and allow up to seven days for new retention policies.
Decision checklist
- Compliance retention for everyone: retention policy with an explicit
KeeporKeepAndDeleteaction. - Legal matter for named people: eDiscovery hold in a case, including OneDrive and team locations.
- Leavers: retention policy or label, confirm the hold, then delete the account.
- Existing Litigation Holds: inventory them with
Get-Mailbox -ResultSize Unlimited | Where-Object {$_.LitigationHoldEnabled}and plan the move to retention or eDiscovery holds. - Before removing anything: list all holds, understand the 30-day delay hold and record who approved the release.
References
- https://learn.microsoft.com/en-us/microsoft-365/admin/misc/create-litigation-hold-mac
- https://learn.microsoft.com/en-us/exchange/security-and-compliance/recoverable-items-folder/recoverable-items-folder
- https://learn.microsoft.com/en-us/purview/retention
- https://learn.microsoft.com/en-us/purview/inactive-mailboxes-in-office-365
- https://learn.microsoft.com/en-us/purview/edisc-hold-create
- https://learn.microsoft.com/en-us/purview/ediscovery-identify-a-hold-on-an-exchange-online-mailbox
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-retentioncompliancepolicy
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/new-retentioncompliancerule
- https://learn.microsoft.com/en-us/powershell/exchange/connect-to-scc-powershell
- https://learn.microsoft.com/en-us/powershell/exchange/connect-to-exchange-online-powershell
- https://learn.microsoft.com/en-us/exchange/policy-and-compliance/holds/litigation-holds