Security & identity

Litigation hold vs retention policy vs eDiscovery hold for Exchange

Which preservation method to use for Exchange Online mailboxes: how Litigation Hold, Purview retention policies and eDiscovery holds differ, how to apply each, and how to see which holds a mailbox has.

9 min read
On this page

Use a Microsoft Purview retention policy (or retention labels) when you need to keep mailbox content for a defined period for compliance, use an eDiscovery hold inside a Purview case when you must preserve specific people's content for a legal matter, and treat Litigation Hold as a supported but older option for preserving a whole mailbox. All three keep deleted and edited items in the Recoverable Items folder and raise its quota to 100 GB, and when they overlap, retention beats deletion and an eDiscovery hold beats everything until it is released.

Who this is for and what you will have at the end

This guide is for Exchange Online administrators and compliance teams who are asked to "put a mailbox on hold" and need to choose the right mechanism, apply it, and later prove which holds are in place.

At the end you will have:

  • A comparison of the three preservation methods and when each fits.
  • Steps and PowerShell to apply each one.
  • A repeatable way to list every hold on a mailbox and decode it.
  • A safe process for removing holds, including the 30-day delay hold and inactive mailboxes.

The three methods at a glance

Litigation HoldPurview retention policyeDiscovery hold
Designed forPreserving an entire mailboxLong-term compliance lifecycleA specific legal investigation
ScopeIndividual mailboxesBroad: all mailboxes, groups or scopesSpecific people, groups and sites in a case
CoversMailbox and archiveExchange, SharePoint, OneDrive, Teams and moreMailboxes and SharePoint or OneDrive sites
DurationIndefinite or a number of daysConfigurable, with optional automatic deletionUntil an administrator releases it
Deletes content at the endHold just stops preservingOptional (retain and then delete)No
Where you manage itMicrosoft 365 admin center or Exchange Online PowerShellPurview portal or Security & Compliance PowerShellPurview eDiscovery case
Typical time to applyAdmin center warns up to 240 minutesAllow up to seven daysUp to 24 hours
Licensing noteExchange Online Plan 2, or Plan 1 plus Exchange Online ArchivingSee the Purview service descriptionEligible licence on every held user; query-based and time-bound holds need E5-tier rights

Microsoft's own summary of retention versus eDiscovery holds: retention is for compliance, long-term, broad and content-based, with configurable start and end and low administrative overhead; eDiscovery holds are for legal needs, short-term, specific and user-based, with no automatic deletion and higher overhead. Litigation Hold remains supported, but Microsoft recommends retention or eDiscovery holds instead.

How preservation works inside the mailbox

All three methods use the hidden Recoverable Items folder:

  • Deletions receives items deleted from Deleted Items or with Shift+Delete. Users can still recover them.
  • Purges holds hard-deleted items when Litigation Hold or single item recovery is enabled.
  • Versions keeps the original copy of an item before it is modified, through copy-on-write, when In-Place Hold, Litigation Hold or a retention policy applies.
  • DiscoveryHolds keeps hard-deleted items when an In-Place Hold or a retention policy applies, and purged items when an eDiscovery case hold applies.
  • SubstrateHolds keeps original copies of modified or deleted Teams messages.

Quotas change when a hold applies. By default the Recoverable Items folder has a 20 GB warning and 30 GB hard limit. On Litigation Hold, In-Place Hold or a retention policy these rise to 90 GB and 100 GB; with an archive enabled the hard limit becomes 105 GB, and with auto-expanding archiving the primary mailbox's Recoverable Items folder gets 110 GB. When the folder fills, users can't delete items and copy-on-write can't keep versions, so monitor held mailboxes.

When to use which

  • Regulatory requirement to keep all email for N years. Use a retention policy on the Exchange email location with a retain or retain-then-delete action. It applies to the whole location rather than to a list of mailboxes captured by a script (a bulk Set-Mailbox Litigation Hold command only covers mailboxes that exist when you run it), and it can delete content when the period ends.
  • Lawsuit or internal investigation naming specific people. Use an eDiscovery hold in a Purview case, covering their mailboxes, OneDrive accounts and relevant team mailboxes and sites. See the Purview eDiscovery guide for the full case workflow.
  • Leaver whose mailbox must be kept. Apply a retention policy or retention label that retains content, confirm the hold, then delete the account so the mailbox becomes inactive. Microsoft recommends retention for this, not eDiscovery holds.
  • Quick whole-mailbox preservation in an existing Exchange process. Litigation Hold still works, but plan to move to retention or eDiscovery holds.

Avoid using eDiscovery holds for long-term retention. If the case is closed or the hold released, an inactive mailbox kept only by that hold is permanently deleted.

Apply Litigation Hold

In the Microsoft 365 admin center:

  1. Go to Users > Active users and select the user.
  2. On the Mail tab, under More actions, select Manage litigation hold.
  3. Select Turn on litigation hold. Optionally set Hold duration (days), a Note visible to the user and a Web page with more information for the user.
  4. Select Save changes. The banner warns it can take up to 240 minutes to take effect.

In Exchange Online PowerShell:

Connect-ExchangeOnline -UserPrincipalName admin@contoso.com
 
# Indefinite hold
Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $true
 
# Time-based hold, about seven years
Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $true -LitigationHoldDuration 2555
 
Get-Mailbox lee.gu@contoso.com | Format-List LitigationHold*

The hold duration is counted from when each item was received or created. An indefinite hold shows LitigationHoldDuration as Unlimited.

Apply a Purview retention policy to mailboxes

You can create the policy in the Purview portal under Data Lifecycle Management, or in Security & Compliance PowerShell. The policy's retention settings come from a rule that you add with New-RetentionComplianceRule, and each retention policy can have only one rule.

Connect-IPPSSession -UserPrincipalName admin@contoso.com
 
New-RetentionCompliancePolicy -Name "Exchange - keep 7 years" -ExchangeLocation All
 
New-RetentionComplianceRule -Name "Keep 7 years" -Policy "Exchange - keep 7 years" -RetentionDuration 2555 -RetentionComplianceAction Keep

RetentionComplianceAction accepts Keep, Delete and KeepAndDelete; RetentionDuration accepts a number of days or Unlimited. Always set the action explicitly: the cmdlet reference notes that without it the policy is created as a UniH policy instead of an mbx policy. Allow up to seven days for the policy to apply.

If a regulator requires that nobody can weaken the policy, Preservation Lock (-RestrictiveRetention $true) locks it so it can only be extended. That is irreversible, so lock only after the policy is final.

Apply an eDiscovery hold

In the Purview portal: eDiscovery > Cases > your case > Hold policies > Create policy, add data sources, optionally add a query, then Apply hold. Allow up to 24 hours, and remember that group membership is captured as a snapshot when the hold is created.

Find every hold on a mailbox

Run this in Exchange Online PowerShell:

Get-Mailbox lee.gu@contoso.com | Format-List LitigationHoldEnabled,InPlaceHolds,ComplianceTagHoldApplied,*HoldApplied*
 
Get-Mailbox lee.gu@contoso.com | Select-Object -ExpandProperty InPlaceHolds
 
Get-OrganizationConfig | Select-Object -ExpandProperty InPlaceHolds

Decode the InPlaceHolds values like this:

Value patternMeaning
LitigationHoldEnabled : TrueLitigation Hold is on
UniH prefixeDiscovery case hold
mbx prefixRetention policy applied to this mailbox (on the mailbox) or to all mailboxes (on the organisation config)
skp prefixRetention policy for Skype for Business conversations
grp prefix (organisation config)Retention policy for Microsoft 365 Groups and Teams channel messages
-mbx prefixMailbox is excluded from an organisation-wide retention policy
No prefix or cld prefixLegacy In-Place Hold
Suffix :1, :2, :3Delete (or label publishing), retain, or retain then delete
ComplianceTagHoldApplied : TrueA retaining retention label is applied to a folder or item

To name the policy behind a GUID, strip the prefix and suffix and look it up in Security & Compliance PowerShell:

Get-RetentionCompliancePolicy <GUID> -DistributionDetail | Format-List Name,*Location
 
$CaseHold = Get-CaseHoldPolicy <GUID>
Get-ComplianceCase $CaseHold.CaseId | Format-List Name

Some newer retention locations, such as Teams chats and Copilot experiences, don't stamp mailbox objects; use Policy lookup or Get-AppRetentionCompliancePolicy for those.

Remove a hold safely

  • Litigation Hold: Set-Mailbox lee.gu@contoso.com -LitigationHoldEnabled $false.
  • Retention policy: exclude the mailbox, turn the location off or delete the policy (not possible with Preservation Lock).
  • eDiscovery hold: remove the location from the hold policy, release the hold or close the case. Closing or deleting a case turns off all its holds.

After any hold is removed, the Managed Folder Assistant applies a 30-day delay hold by setting DelayHoldApplied (Outlook content) or DelayReleaseHoldApplied (Teams and other app data) to True. The mailbox is treated as on hold until it expires. If you are sure, you can remove it early; this needs the Legal Hold role:

Set-Mailbox lee.gu@contoso.com -RemoveDelayHoldApplied
Set-Mailbox lee.gu@contoso.com -RemoveDelayReleaseHoldApplied

Troubleshooting

  • Manage litigation hold is missing in the admin center. The mailbox probably lacks an Exchange Online Plan 2 licence, or Plan 1 plus Exchange Online Archiving.
  • Users can't delete items and versions stop being saved. The Recoverable Items folder has hit its quota. Check it with Get-MailboxFolderStatistics, and consider auto-expanding archiving.
  • Deleted user's mailbox didn't become inactive. The policy was delete-only, or the hold hadn't applied when the account was deleted. Retention must retain or retain-then-delete, and you should confirm the hold before deleting the account.
  • Can't delete an inactive mailbox from a retention policy. The UPN or primary SMTP address was changed before the account was deleted, so the mailbox can't be matched to the policy any more. Don't change them before deletion.
  • Delay hold never clears. The user account is disabled, so the mailbox isn't processed. Remove it with the parameters above.
  • Policy applied but InPlaceHolds is empty. Check Get-OrganizationConfig for organisation-wide policies, and allow up to seven days for new retention policies.

Decision checklist

  • Compliance retention for everyone: retention policy with an explicit Keep or KeepAndDelete action.
  • Legal matter for named people: eDiscovery hold in a case, including OneDrive and team locations.
  • Leavers: retention policy or label, confirm the hold, then delete the account.
  • Existing Litigation Holds: inventory them with Get-Mailbox -ResultSize Unlimited | Where-Object {$_.LitigationHoldEnabled} and plan the move to retention or eDiscovery holds.
  • Before removing anything: list all holds, understand the 30-day delay hold and record who approved the release.

References

Questions people ask

Is Litigation Hold deprecated in Exchange Online?

No, Litigation Hold is still supported. Microsoft lists it as an older feature and recommends Microsoft 365 retention policies or eDiscovery holds instead, depending on whether the need is long-term compliance or a specific legal matter.

What licence does Litigation Hold need?

The mailbox needs an Exchange Online Plan 2 licence. A mailbox with Exchange Online Plan 1 needs a separate Exchange Online Archiving licence before you can place it on Litigation Hold. If the Manage litigation hold option is missing in the admin center, check the licence first.

Which wins if a mailbox has a retention policy and an eDiscovery hold?

Preservation for the eDiscovery hold always takes precedence. Across retention settings, retention wins over deletion and the longest retention period wins, so content is kept until every hold and retention setting allows it to be deleted.

Why does a mailbox stay on hold after I removed the hold?

Microsoft applies a 30-day delay hold after any hold is removed so that content isn't purged immediately. Check DelayHoldApplied and DelayReleaseHoldApplied with Get-Mailbox. If the user account is disabled, the Managed Folder Assistant doesn't process the mailbox and the delay hold can remain after 30 days.

Exchange OnlineMicrosoft PurviewLitigation holdRetention policies
  1. Build Purview DLP policies for Exchange, SharePoint, Teams and devices

    Step-by-step Microsoft Purview DLP setup that stops card numbers and PII leaking through email, SharePoint, OneDrive, Teams chat and Windows or macOS devices, with a safe simulation rollout.

  2. Microsoft 365 audit log search: who deleted, shared or forwarded what

    Use Microsoft Purview Audit and Search-UnifiedAuditLog to find who deleted a file, shared a link, purged email or created a forwarding rule, then export and read the AuditData.

  3. Purview eDiscovery: run cases, legal holds, searches and exports

    A practical walkthrough of the unified eDiscovery experience in the Microsoft Purview portal: permissions, cases, hold policies, searches, statistics and exports, with limits and fixes.