In the Microsoft Purview portal, eDiscovery is now a single case-based experience: open eDiscovery > Cases, create a case, put the custodians' mailboxes and OneDrive accounts on a hold policy, build and run a search, then export the results or add them to a review set. The classic Content Search, eDiscovery (Standard) and eDiscovery (Premium) experiences were retired on August 31, 2025 for all tenants except those operated by 21Vianet, so everything in this guide happens in the unified portal.
Who this is for and what you will have at the end
This guide is for Microsoft 365 administrators, compliance staff and legal operations teams who need to preserve and collect mailbox, OneDrive, SharePoint and Teams content for a legal matter, HR investigation or data subject request.
At the end you will have:
- eDiscovery permissions assigned with least privilege.
- A case with a hold policy that preserves the right mailboxes and sites.
- A tested KeyQL search with statistics and samples.
- An export downloaded and checked before it expires.
- A verification and troubleshooting routine you can repeat for the next matter.
What changed from classic eDiscovery
| Classic concept | Unified experience |
|---|---|
| Separate Content Search tool | A system-generated Content Search case, available to eDiscovery Manager and Administrator role groups |
| Custodians as the core object | The case is the core object; you add people, groups and data sources to it |
| Collections | Statistics on searches; searches stay editable after results go to a review set |
| Manual advanced indexing | Advanced indexing runs automatically during statistics, review set and export processes (premium) |
| Jobs | Processes, tracked in Process manager |
| Separate standard and premium export flows | One export flow with a common structure |
All cases created in the new portal have the Premium case type regardless of licence. The case type alone doesn't give you premium features; access to them depends on licensing.
Prerequisites
- Licensing. Microsoft states that both admins and users working with eDiscovery cases need a Microsoft 365 Enterprise E3 or E5 licence, and that admins exporting SharePoint content also need a SharePoint E3 licence or some SharePoint items may not export as expected. Premium features (review sets, analytics, OCR, query-based and time-bound holds) need E5 or the E5 Compliance or E5 eDiscovery and Audit add-ons.
- Hold targets. Every user whose content you preserve needs a licence that includes eDiscovery hold rights. Frontline plans such as Office 365 F1 and F3 don't include them, and placing an unlicensed user on hold isn't supported.
- Enterprise apps. In the Azure portal under Enterprise applications, check that these apps exist with Enabled for users to sign-in set to Yes: ComplianceWorkbenchApp, MicrosoftPurviewEDiscovery, Office365Zoom and the built-in security add-on for on-premises mailboxes.
- Conditional Access. Policies that apply to admin accounts can restrict some eDiscovery operations, so test with the account you will actually use.
Step 1: Assign eDiscovery permissions
The main role group is eDiscovery Manager, which has two subgroups:
- eDiscovery Manager members can create cases, add members, create holds, run searches and export, but only in cases they created or are members of.
- eDiscovery Administrator members can do all of that, plus access every case, configure eDiscovery settings and remove case members. Keep this group small.
To assign:
- In the Microsoft Purview portal go to Settings > Role groups.
- Select eDiscovery Manager > Edit.
- Use Choose users or Choose groups for the eDiscovery Manager subgroup, then Next.
- Add eDiscovery Administrators the same way, then Next > Save > Done.
You need to be in Organization Management or hold the Role Management role to do this. Groups added to the eDiscovery Manager subgroup must be mail-enabled security groups (distribution groups and Microsoft 365 groups aren't supported), and eDiscovery Administrators must be individual users. Review-only staff go in the Reviewer role group.
Useful built-in roles to know: Hold (place holds), Compliance Search (search and estimate), Preview, Export, Review and RMS Decrypt (view and export rights-protected content).
Step 2: Create a case
- Go to the Purview portal, select the eDiscovery solution card and then Cases.
- Select Create case.
- Enter a unique Case name and an optional Case description, then select Create.
You are added as a member automatically and land on the case's Searches tab. Open Case settings to add other members or role groups and to review the case's search, analytics and review set settings.
Step 3: Place custodians on hold
Create the hold before you start searching. Holds don't depend on searches, and preservation is the time-critical step.
- In the case, open the Hold policies tab and select Create policy.
- Enter a unique Policy name and optional description, then Create.
- In Manage data sources, add the people, groups or organisational locations to preserve, review the mailboxes and sites selected for each, and Save.
- Optionally narrow the hold with the Condition builder or a Keyword Query Language (KeyQL) query, for example a date range. Query-based and time-bound holds need the higher licensing tiers described above.
- Select Apply hold.
- Open the hold policy's Details tab and confirm each location's Hold status.
Rules that catch people out:
- A hold can take up to 24 hours to take effect.
- Group membership is a snapshot. Members added to a distribution list, Microsoft 365 group or team later are not placed on hold. Re-add the group to pick up new members.
- Distribution list expansion is limited to 100 members. Split larger lists or use bulk import of data sources.
- Placing a hold on a subsite places it on the parent site instead. A site needs a title to be held, and keeping site names under 70 characters avoids URL truncation problems.
- For query-based holds on encrypted or partially indexed items, limit conditions to Date, Participants and Type. All content is held at first; non-matching content is cleared every seven to 14 days, unless more than five holds of any type apply to the location.
Teams content needs more than one location
- Channel conversations are stored in the team's group mailbox, and channel files in the team's SharePoint site. Hold both.
- 1:1 and group chats are stored in each participant's mailbox, and files shared in chat are in the sharer's OneDrive. Hold the users' mailboxes and OneDrive accounts.
- Holding a team doesn't hold its members' mailboxes or OneDrive accounts. Add them explicitly if the matter requires it.
To find a team's site URL, run this in Exchange Online PowerShell:
Get-UnifiedGroup "Project Falcon" | Format-List DisplayName,PrimarySmtpAddress,SharePointSiteUrlStep 4: Build and run a search
- In the case, select Create a search, enter a unique Search name and select Create.
- On the Query tab, add data sources. For a user, the ellipsis menu offers shortcuts such as Frequent collaborators, Manager, Direct reports and Groups the user is in.
- Build the query with the Condition builder or switch to KeyQL. If Security Copilot is enabled you can use Draft a query with Copilot (preview) to turn a natural-language request into KeyQL.
- Select Run query and choose a result view:
- Statistics: estimated counts and sizes, with optional categories, a query keywords report and partially indexed item analysis.
- Sample: a representative set of items, with 1, 10 or 100 items per location.
- Refine and rerun until the statistics make sense, then Duplicate the search if you want to keep the original intact.
KeyQL rules that matter in practice:
- AND, OR, NOT and NEAR must be uppercase, and only work in the KeyQL field.
- Keyword matching is always case-insensitive.
- All searches run in UTC.
- An empty keyword condition returns everything in the selected sources.
- Only prefix wildcards are supported, with at least three characters, for example
budg*. - Use
kind:emailfor mail andkind:microsoftteamsfor Teams chats, meetings and calls. - Add a trailing slash with the
pathproperty to match a single site, for examplepath:sites/finance/.
(kind:email OR kind:microsoftteams) AND ("project falcon" OR falcon*)Step 5: Export the results
- Open the search and select Export.
- Enter an Export name and choose which items to include: indexed items that match, indexed plus partially indexed items, or partially indexed items only.
- For SharePoint and OneDrive, choose document versions (latest only up to all versions) and whether to include whole folders or list attachments.
- For mailboxes, choose whether to Organize conversation into HTML transcript, include Teams and Viva Engage context, and collect cloud attachments.
- Choose Export items with items report (or a report only), then Create PSTs for messages or Create .msg files for messages.
- Set package sizes: PST 1, 2, 5 (default) or 10 GB; .zip 2, 10 (default), 20 or 40 GB.
- Select Export, then track progress in Process manager and download from the export's Overview tab.
Download tips from Microsoft: use a current Microsoft Edge, allow pop-ups and multiple automatic downloads for the Purview site, avoid network shares as the download target, and unzip with 7-Zip or WinZip rather than the built-in Windows utility. Download before the 14-day expiry.
Verify holds and cases with PowerShell
Connect to Security & Compliance PowerShell and check the case and hold distribution:
Connect-IPPSSession -UserPrincipalName admin@contoso.com
Get-ComplianceCase | Format-Table -Auto Name,Status,Identity
Get-CaseHoldPolicy -Case "Contoso Legal" -DistributionDetail | Format-List Name,DistributionStatus,ExchangeLocation,SharePointLocationWithout -DistributionDetail, DistributionStatus shows Pending. On a held mailbox, Get-Mailbox <user> | Format-List InPlaceHolds should list a GUID with the UniH prefix, which identifies an eDiscovery hold.
Limits to plan around
| Limit | Standard | Premium features |
|---|---|---|
| Hold policies per case | 100 | 200 |
| Mailboxes in a single case hold | 1,000 | 2,000 |
| Sites in a single case hold | 1,000 | 2,000 |
| Recommended locations in a targeted search | 1,000 | 1,000 |
| Exportable data per search | 2 TB | 5 TB |
| Data an organisation can export per day | 2 TB | 5 TB |
| Maximum size per export package | 40 GB | 40 GB |
| Process run time before cancellation | 7 days | 7 days |
Microsoft recommends using separate hold policies for mailboxes and for SharePoint and OneDrive sites.
Troubleshooting
- "Please close the current PowerShell session and open a new session using Connect-IPPSSession with the -EnableSearchOnlySession flag." You ran
*-ComplianceSearchorNew-ComplianceSearchActioncmdlets on a normal session. Update the ExchangeOnlineManagement module to 3.9.0 or later and reconnect with-EnableSearchOnlySession. - A location shows a hold error. eDiscovery doesn't monitor identity changes after the hold is applied. Edit the hold's data sources (for example a changed OneDrive URL after a UPN change) and retry the policy.
- Distribution list won't add. It has more than 100 members. Split it or bulk import the members.
- Case stuck in Pending delete or Closed with errors. A hold didn't release. Check the hold policy errors, fix them and redistribute.
- Files appear in statistics but not in the export. Files restricted by a DLP action, sites locked with NoAccess, and files you can't access because of SharePoint access controls are skipped.
- Content still exists after the hold was removed. A 30-day delay hold applies to mailboxes and sites after removal. Closing a case turns off all its holds and starts the same delay, and deleting a case also turns off its holds. Treat closing or deleting a case as a release decision.
Closing checklist
- eDiscovery Managers assigned through a mail-enabled security group; Administrators kept to a few named people.
- Hold created first, with users' mailboxes and OneDrive plus team mailboxes and sites.
- Hold status confirmed after 24 hours in the portal and with
Get-CaseHoldPolicy -DistributionDetail. - Search statistics reviewed before any export; partially indexed items handled deliberately.
- Export downloaded and verified against the items report within 14 days.
- For long-term preservation outside a legal matter, compare options in litigation hold vs retention policies. eDiscovery case data stays in the region and service environment where it was created, so export what you need before a region or environment move. For tenant-to-tenant moves, see tenant-to-tenant migration architecture.
References
- https://learn.microsoft.com/en-us/purview/edisc
- https://learn.microsoft.com/en-us/purview/edisc-get-started
- https://learn.microsoft.com/en-us/purview/edisc-permissions
- https://learn.microsoft.com/en-us/purview/edisc-cases-manage
- https://learn.microsoft.com/en-us/purview/edisc-hold-create
- https://learn.microsoft.com/en-us/purview/edisc-search-query
- https://learn.microsoft.com/en-us/purview/edisc-search-export
- https://learn.microsoft.com/en-us/purview/edisc-ref-limits
- https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/get-caseholdpolicy
- https://learn.microsoft.com/en-us/powershell/exchange/connect-to-scc-powershell
- https://learn.microsoft.com/en-us/purview/ediscovery-identify-a-hold-on-an-exchange-online-mailbox