Security & identity

Purview retention policies and labels: meet retention, avoid data loss

How Microsoft Purview retention policies and retention labels work across Exchange, SharePoint, OneDrive and Teams, which settings win, and how to roll them out without deleting content by accident.

13 min read
On this page

Microsoft Purview retention policies apply retain, delete, or retain-then-delete settings to whole locations such as Exchange mailboxes, SharePoint sites, OneDrive accounts and Teams messages, while retention labels apply settings to individual items as exceptions. To meet a retention requirement without losing data, start with retain-only or retain-then-delete policies, remember that the period counts from when content was created or last modified rather than from when the policy was assigned, test delete actions on a narrow scope first, and rely on the principles of retention: retention always wins over deletion and the longest retention period wins. Create them in the Microsoft Purview portal under Data Lifecycle Management > Policies, and allow up to seven days for them to take effect.

Who this is for and what you will have

This guide is for Microsoft 365 and compliance administrators who have been given a requirement such as "keep all email for seven years" or "delete files nobody has touched in five years" and need to implement it without surprising anyone. At the end you will have:

  • A clear model of how retained content is stored for each workload.
  • A design that combines retention policies with a few retention labels for exceptions.
  • Policies created in the portal or in Security & Compliance PowerShell.
  • A rollout and verification process that catches mistakes before they delete data.

How retention works

Content stays in place

Retention doesn't move content anywhere while users work with it. When a user edits or deletes something that must be retained, a copy is kept in a hidden, secure location:

WorkloadWhere retained copies go
SharePoint and OneDriveThe Preservation Hold library of the site
Exchange mailboxesThe Recoverable Items folder
Teams, Viva Engage, Copilot and AI appsA hidden SubstrateHolds folder under Recoverable Items

The Preservation Hold library counts towards the site's storage quota, so large retained sites can need more storage. Retained mail counts towards mailbox limits, which is why Microsoft recommends enabling auto-expanding archiving for mailboxes under long retention.

Policies versus labels

CapabilityRetention policyRetention label
Retain-only, delete-only, retain then deleteYesYes
Applies to a whole location automaticallyYesThrough auto-apply or default labels
Exchange, SharePoint, OneDrive, Microsoft 365 GroupsYesYes (not public folders)
Teams, Copilot and AI apps, Viva EngageYesNo
Travels with the item when moved within the tenantNoYes
Start the period when labeled or on an eventNoYes
Disposition review, mark as a recordNoYes
Applied manually by usersNoYes

A common pattern is a retention policy for the baseline (for example, all SharePoint content three years) and a retention label for the exceptions (contracts seven years).

The principles of retention

When several settings apply to the same item, the outcome is worked out in this order:

  1. Retention wins over deletion. If anything says retain, the item isn't permanently deleted, although it can still be removed from the user's view.
  2. The longest retention period wins.
  3. Explicit wins over implicit for deletions. A retention label's delete action takes precedence over any retention policy's delete action.
  4. The shortest deletion period wins among policies, when the earlier steps don't resolve it.

eDiscovery holds sit under the first principle: held content can't be permanently deleted by any retention setting. This is your main safety net. A "keep everything for seven years" policy on a location means that a badly configured delete-only policy on the same location can't permanently delete content inside those seven years.

When the period starts

  • When the content was created: the default.
  • When the content was last modified: only for files in SharePoint, OneDrive and Microsoft 365 Groups.
  • When the content was labeled and when an event occurs: retention labels only.

The period is never calculated from when you assign the policy. A delete-only policy of five years from creation, applied today, deletes every existing item older than five years in its first run. This is the most common way retention causes unexpected data loss.

What happens at the end of the period

SharePoint and OneDrive

A timer job evaluates sites; it can take up to seven days to run.

  • Retain then delete, content not modified: at the end of the period the item moves to the first-stage Recycle Bin. A 93-day period spans both recycle bins, after which it is permanently deleted.
  • Content modified or deleted during the period: a copy of the original goes to the Preservation Hold library. Expired copies move to the second-stage Recycle Bin and are permanently deleted after 93 days.
  • Delete-only: items go to the first-stage Recycle Bin at the end of the period and follow the same 93-day path.

Content in the Preservation Hold library is only cleaned up after it has been there for more than 30 days and the weekly job runs, so deletion from it can take up to 37 days. Retention policies also suspend library versioning limits: old versions aren't purged and users can't delete versions until the retention period ends. To retain every version, versioning must be on, because new content isn't copied to the Preservation Hold library the first time it's edited.

Exchange

A timer job evaluates the Recoverable Items folder and other folders; it can also take up to seven days. Items whose retention has expired are permanently deleted within 14 days of the end of the period (configurable up to 30 days). With delete-only, items move to Recoverable Items at the end of the period and are permanently deleted 14 days later unless the user purges them first.

Mailboxes must contain at least 10 MB of data before retention settings apply. Users see the name and expiry date of the shortest-expiring delete policy at the top of each message; retain-only policies show nothing.

When a user's account is deleted and their mailbox is covered by a retention policy, the mailbox becomes an inactive mailbox and stays searchable for as long as the policy requires.

Prerequisites

  • Permissions: the Compliance Administrator role group, or a custom role group with the Retention Management role. View-Only Retention Management gives read access. The administrator doesn't need access to the content.
  • Licences: data lifecycle management features are licensed per feature; check the Microsoft Purview service description for what your subscription includes before you design around adaptive scopes or auto-apply labels.
  • Security & Compliance PowerShell for scripted configuration, through the Exchange Online PowerShell module.
  • A written requirement for each workload: what must be kept, for how long, from which date, and what must be deleted afterwards.
  • Administrative units: if you are a restricted administrator, you can't create policies that include SharePoint sites or Exchange public folders. Use Full directory.

Step 1: Map requirements to locations and scopes

Turn each requirement into a location, a duration, a start date and an action. Notes that affect the design:

  • The Exchange mailboxes location covers user, shared and resource mailboxes, but not Microsoft 365 group mailboxes. Use Microsoft 365 Group mailboxes & sites for groups and group-connected team sites.
  • With a static scope, the SharePoint location is SharePoint classic and communication sites and doesn't cover group-connected sites. With an adaptive scope it is SharePoint sites, which also includes OneDrive and group-connected sites.
  • Teams channel messages, Teams chats and Viva Engage are separate locations. In a static policy, selecting a Teams or Viva Engage location excludes the others, so those need their own policies. Files shared in Teams live in SharePoint and OneDrive, so cover those locations too.
  • Choose adaptive scopes when membership changes, such as all users in a department. They run a daily query and have no per-policy item limit. Choose static scopes for whole locations. Static scopes with includes and excludes are subject to per-policy limits.

Step 2: Start with retention, not deletion

For the first deployment, create a retain-only policy or a retain-then-delete policy with a long period across the whole location. Decide the settings carefully: after the policy is saved you can still change the retention period and when it starts, but not the name, the scope type or the other retention settings, so switching a retain-only policy to delete later means creating a new policy.

  1. In the Microsoft Purview portal, go to Solutions > Data Lifecycle Management > Policies > Retention policies.
  2. Select New retention policy and enter a name. Names can't be changed later.
  3. On Assign admin units, keep Full directory.
  4. Choose Static or Adaptive.
  5. Choose the locations. For static scopes, leave a location at its default to cover every instance, including new mailboxes and sites created later.
  6. On Decide if you want to retain content, delete it, or both, select Retain items for a specific period, enter the period, choose whether it starts when items were created or last modified, and set At end of the retention period to Do nothing (retain-only) or Delete items automatically. Retain items forever retains without an end date.
  7. Review and submit.

The equivalent in Security & Compliance PowerShell, a seven-year retain-then-delete policy for all mailboxes:

Connect-IPPSSession -UserPrincipalName admin@contoso.com
 
New-RetentionCompliancePolicy -Name "Exchange 7 years" -ExchangeLocation All
New-RetentionComplianceRule -Name "Exchange 7 years rule" -Policy "Exchange 7 years" `
  -RetentionDuration 2555 -RetentionDurationDisplayHint Days -RetentionComplianceAction KeepAndDelete `
  -ExpirationDateOption CreationAgeInDays

A policy isn't valid until it has a rule, and each policy has exactly one rule. RetentionComplianceAction accepts Keep, Delete and KeepAndDelete; -RetentionDuration Unlimited with Keep retains indefinitely. Always specify the action explicitly. Microsoft notes that the parameter is mandatory to prevent non-compliant deletion. Months in the portal are 30 days and years are 365 days, so seven years is 2,555 days.

Step 3: Add deletion carefully

When you add a delete action, assume it will remove everything that is already older than the period on its first run.

  1. Report on content age before you enable deletion, and tell users and the help desk what will be removed.
  2. Create the delete policy with a narrow static scope first: a test site, or a few mailboxes. For a delete-only policy, select Only delete items when they reach a certain age on the Decide if you want to retain content, delete it, or both page.
  3. Check the result after the timer jobs have run, then widen the scope.
  4. Keep any longer retain policy in place on the same location; it prevents the delete policy from permanently removing anything still inside its period.

Be careful with includes. If a static policy includes specific sites or mailboxes and you remove the last one, the location reverts to All. On a delete policy, that applies deletion to every site or mailbox. Turn the location off instead, or use excludes.

Step 4: Use retention labels for exceptions

  1. Go to Data Lifecycle Management > Retention labels > Create a label. Choose Retain items indefinitely or for a specific period for a longer retention, or Enforce actions after a specific period for a delete-only label.
  2. Select Just save the label for now.
  3. Go to Policies > Label policies > Publish labels, choose the labels and the locations.

Labels typically appear in SharePoint and OneDrive within a day and in Outlook within seven days; mailboxes need at least 10 MB. Users apply them from the details pane in SharePoint and OneDrive, or with Assign Policy in Outlook. A default label on a SharePoint library applies to new unlabeled items; select Apply to existing items to label what is already there.

Use Records Management instead of Data Lifecycle Management when you need disposition review, event-based retention or record declaration.

Verify the configuration

  1. Open the policy in the portal and wait for the status to change from On (Pending) to On (Success).
  2. Use Policy lookup in Data Lifecycle Management with an exact email address or site URL to confirm which policies apply to a specific user, site or group.
  3. In a test site, delete a file and confirm it can still be found with an eDiscovery or Content Search search. The Preservation Hold library is a hidden system location; Microsoft says to use compliance tools such as eDiscovery to access retained content rather than opening or editing it directly.
  4. In a test mailbox with at least 10 MB of data, confirm the policy name and expiry date appear at the top of messages if the policy deletes.
  5. Review admin changes to retention policies in the audit log, as described in Microsoft 365 audit log search.

Troubleshooting

Status shows (Error) or the policy is taking longer than expected to deploy. Retry distribution:

Set-RetentionCompliancePolicy -Identity "Exchange 7 years" -RetryDistribution

For Teams private channel and Viva Engage locations, use Set-AppRetentionCompliancePolicy with the same switch.

"RemoteGroupMailbox" isn't a valid selection for this location. You added a Microsoft 365 group mailbox to the Exchange location. Use the Microsoft 365 Group mailboxes & sites location.

A SharePoint site fails validation when you save the policy. Static scopes check that each site URL exists on the final page. Correct or remove the URL. Separately, a SharePoint site must be indexed for retention settings to apply to it.

Retention labels don't appear in Outlook after seven days. Check the mailbox has 10 MB of data, then check when the mailbox was last processed with Export-MailboxDiagnosticLogs <user> -ExtendedProperties and the ELCLastSuccessTimeStamp property. Start-ManagedFolderAssistant -Identity <user> forces processing.

Site storage is filling up. The Preservation Hold library counts towards quota, and retention suspends versioning limits. Increase storage or review whether all content in the site needs the policy.

Users can't delete a library or site. Deleting a library, list or site subject to retention isn't allowed; release the policy first if the deletion is legitimate.

You need to remove a policy. Delete it or exclude the location, provided it isn't locked. SharePoint and OneDrive content keeps being retained for 30 days after release, so you can re-enable the policy without loss in that window. Content excluded from a policy is deleted from the Preservation Hold library without the 30-day delay.

Checklist

  • Requirements mapped to locations, durations, start dates and actions.
  • Baseline retain policies created first and showing On (Success).
  • Group mailboxes and sites, Teams locations and OneDrive covered by the right locations.
  • Delete actions tested on a narrow scope, with content age reviewed and users informed.
  • No static policy left with a single include that could revert to All.
  • Retention labels created for exceptions and published to the right locations.
  • Storage and auto-expanding archiving reviewed for retained sites and mailboxes.
  • Preservation Lock considered only after the configuration is proven, because a locked policy can't be turned off or made less restrictive by anyone, including administrators.

References

Questions people ask

What is the difference between a retention policy and a retention label?

A retention policy applies the same settings to a whole container, such as all mailboxes or all SharePoint sites. A retention label applies settings to an individual item, travels with it within the tenant, and supports extras such as event-based retention, disposition review and declaring records.

If two retention settings conflict, which one wins?

Retention wins over deletion, and the longest retention period wins. For deletion, a label's delete action beats a policy's, and among policies the shortest deletion period wins. eDiscovery holds also prevent permanent deletion.

How long does a retention policy take to apply?

Allow up to seven days for a retention policy to be distributed and applied, and up to seven days for published retention labels to appear in apps. The status changes from On (Pending) to On (Success) when replication completes.

Can I undo a retention policy that deletes content?

You can delete or edit the policy if it isn't locked with Preservation Lock. For SharePoint and OneDrive, content already subject to the policy keeps being retained for a 30-day grace period after release. Content that a delete action has already permanently removed can't be recovered.

Microsoft PurviewData Lifecycle ManagementExchange OnlineSharePoint Online
  1. Microsoft 365 audit log search: who deleted, shared or forwarded what

    Use Microsoft Purview Audit and Search-UnifiedAuditLog to find who deleted a file, shared a link, purged email or created a forwarding rule, then export and read the AuditData.

  2. Build Purview DLP policies for Exchange, SharePoint, Teams and devices

    Step-by-step Microsoft Purview DLP setup that stops card numbers and PII leaking through email, SharePoint, OneDrive, Teams chat and Windows or macOS devices, with a safe simulation rollout.

  3. Deploy Purview sensitivity labels: encryption, defaults and auto-labeling

    Plan, create and publish Microsoft Purview sensitivity labels, add encryption safely, set default and mandatory labeling, and roll out auto-labeling with simulation.