A Microsoft 365 legal hold is a preservation control, not a complete legal process. The correct design depends on the matter, custodians, workloads, content locations, licensing, permissions, and instructions from counsel. This guide gives New Jersey organizations a technical framework for scoping, applying, verifying, maintaining, and releasing preservation controls without treating a checkbox as proof.
Important boundary: Rivell provides technical planning, implementation support, evidence collection, and operational monitoring. Rivell does not decide who is a custodian, what content is legally relevant, how long a matter must be preserved, or when a hold may be released. Those decisions belong to the organization and its legal counsel.
What does “legal hold” mean in Microsoft 365?
People often use “legal hold” as a general label for several different Microsoft 365 controls. They are related, but they are not interchangeable. Microsoft Purview eDiscovery holds are case-specific controls used to preserve data for an investigation or legal matter. Microsoft 365 retention policies and labels are broader lifecycle controls designed to retain or delete content according to organizational rules. Exchange Litigation Hold is a mailbox-level preservation feature for Exchange Online.
Microsoft recommends choosing retention or eDiscovery holds as appropriate instead of treating legacy Litigation Hold as the default for every workload. A preservation plan can use more than one control, but overlapping policies make release and deletion behavior harder to understand. Before applying or releasing anything, identify every control already acting on each mailbox or site.
| Control | Typical purpose | Primary scope | Key limitation |
|---|---|---|---|
| Purview eDiscovery hold | Specific investigation or legal matter | Selected mailboxes, OneDrive accounts, SharePoint sites, Teams or Microsoft 365 group locations | Case scope and release depend on administrator action and legal direction |
| Microsoft 365 retention | Long-term information lifecycle and compliance policy | Broad workloads, locations, users, groups, or content | It should not be substituted for matter-specific scoping without counsel and records-management review |
| Exchange Litigation Hold | Preserve mailbox content, including deleted and modified items | Exchange Online mailbox and archive | It does not independently cover SharePoint, OneDrive, or Teams files |
Which Microsoft 365 locations belong in the scope?
Start with the business activity, not the product name. A single employee may create relevant content in Exchange, OneDrive, SharePoint, Teams chats, standard channels, private channels, shared channels, meeting recordings, and Microsoft 365 group locations. Microsoft documents different compliance storage locations for different Teams content types, so selecting only a user mailbox or only the parent team site can leave gaps.
| Business content | Locations to investigate | Scoping question |
|---|---|---|
| Email, calendar, and mailbox items | Custodian Exchange mailbox and archive, if enabled | Are all named custodians, shared mailboxes, and relevant group mailboxes identified? |
| Personal working files and files shared in chats | Custodian OneDrive accounts | Who created or shared the file, and did ownership change? |
| Team and department files | Relevant SharePoint sites | Does the matter touch the parent site, a private-channel site, or a shared-channel site? |
| Teams 1:1 or group chat messages | Participant mailboxes used for compliance records | Are all relevant participants and the correct date range included? |
| Standard channel messages and files | Parent team mailbox plus the associated SharePoint site | Were both messages and files scoped? |
| Private or shared channel content | Channel-specific or parent-team mailbox locations plus the separate channel SharePoint site, as Microsoft currently documents | Was the channel type confirmed instead of assuming it behaves like a standard channel? |
| Meeting recordings and transcripts | Organizer or recording-owner OneDrive, or the relevant SharePoint site, depending on meeting configuration | Was the actual recording owner and storage location verified? |
Decision rule: build a custodian-and-location register before creating the hold. For every person, team, site, and workload, record the immutable identifier, current URL or address, content type, matter relevance, approval source, and verification owner.
How should an organization prepare before applying a hold?
- Obtain written legal direction. Record the matter, custodians, date range, content types, search criteria if applicable, preservation start, and decision authority.
- Confirm licensing from current Microsoft requirements. Do not rely on a generic E3/E5 statement. Verify the organization subscription, each affected user, the features being used, and any premium reporting or review functions.
- Assign least-privilege eDiscovery roles. Microsoft separates case, hold, search, review, and export capabilities. Confirm the operator has the required role and case membership without granting broader access than needed.
- Inventory all data locations. Map Exchange, OneDrive, SharePoint, Teams, Microsoft 365 groups, shared mailboxes, private channels, shared channels, and meeting content relevant to the matter.
- Check existing preservation controls. Retention policies, retention labels, Litigation Hold, eDiscovery holds, delay holds, and Single Item Recovery can overlap.
- Define evidence and rollback requirements. Decide which screenshots, exports, policy identifiers, approvals, location results, timestamps, and change records must be retained.
What is a defensible technical execution sequence?
1. Create or identify the eDiscovery case
Use a case identifier that matches the organization’s legal matter register. Restrict case access to authorized personnel and document who can create, edit, apply, review, and release holds.
2. Add the approved data sources
Add the mailboxes, OneDrive accounts, SharePoint sites, Teams locations, and group locations in the approved scope. Confirm URLs and identities from the tenant rather than copying stale documentation. If many locations must be added, Microsoft recommends consolidating updates instead of repeatedly changing a policy while distribution is pending.
3. Apply the hold and wait for location results
Applying a policy is asynchronous. Treat “in progress,” partial application, or location errors as unresolved. Do not delete a user or data location based only on the fact that a policy was submitted.
4. Verify each location
Use the current hold-policy details and process results to verify the status of every mailbox and site. Microsoft’s tenant-wide hold report is a useful inventory view, but it is a preview feature and can lag recent policy changes. For current status, use the specific case and policy details.
5. Record and remediate exceptions
Preserve the location status and error for every exception. Common causes include an inaccessible or nonexistent site, a site with no quota, an ineligible recipient type, or a transient distribution failure. Correct the cause and use Microsoft’s supported retry action. Never treat a missing error message in a stale report as proof that preservation succeeded.
6. Maintain the hold as the matter changes
Microsoft states that eDiscovery does not continuously monitor every workload or location identity change after the hold operation completes. When a UPN, SharePoint URL, OneDrive URL, custodian list, team, or matter scope changes, update the data-source register, apply the approved policy change, and verify the affected locations again.
What evidence should be retained?
| Evidence | Why it matters | Acceptance check |
|---|---|---|
| Legal authorization and scope | Connects the technical action to an approved matter | Named approver, date, matter ID, custodians, workloads, release authority |
| Subscription and role preflight | Shows the feature and operator were eligible at execution time | Current Microsoft source, tenant result, assigned roles, case membership |
| Location register | Prevents mailbox-only or parent-site-only gaps | Every relevant content type maps to a tenant location and owner |
| Policy and per-location results | Distinguishes submission from successful application | No unresolved applying, partial, failed, or location-error state |
| Change log | Tracks additions, removals, identity changes, retries, and approvals | Timestamp, operator, old state, new state, reason, evidence link |
| Periodic review | Detects custodian and workload drift | Scope, status, errors, subscriptions, and access reviewed on schedule |
| Release package | Prevents an unsupported or premature release | Written counsel approval, affected controls, exports if required, post-release verification |
How should a hold be released?
Release is a governed change, not a cleanup shortcut. Obtain written direction from counsel, identify every policy or hold source affecting the locations, preserve required exports and audit records, then disable or remove only the approved control. A location can remain preserved because of another eDiscovery hold, retention policy, retention label, Litigation Hold, delay hold, or recovery setting.
After the change, verify the policy and location states and record what remains. Do not use an undocumented command copied from a guide to force-remove a delay hold. Follow Microsoft’s current product documentation and escalation path because release can make content eligible for deletion.
Who owns each decision?
| Decision or task | Primary owner | Technical support role |
|---|---|---|
| Matter scope, custodians, date range, relevance, and release | Legal counsel and authorized business leadership | Translate approved scope into tenant locations |
| Records policy and retention schedule | Legal, compliance, and records management | Configure approved retention controls and report conflicts |
| Subscription, permissions, identity, and workload inventory | Microsoft 365 owner | Audit tenant state and document gaps |
| Hold configuration and per-location verification | Authorized eDiscovery operator | Implement, capture evidence, remediate errors, and monitor status |
| Evidence export and chain of custody | Legal or eDiscovery lead | Support approved exports, access controls, hashes, and transfer logs |
How Rivell can support the technical work
Rivell can help a New Jersey organization inventory Microsoft 365 workloads, review identities and access, map approved custodians to tenant locations, confirm technical prerequisites, implement an approved hold design, document location results, monitor errors, and maintain the operating runbook. Related work may include Microsoft 365 implementation support, identity and cybersecurity controls, backup and disaster-recovery planning, and IT support for New Jersey law firms.
Rivell does not determine legal scope, provide legal advice, guarantee preservation completeness, or authorize release. The organization should involve qualified counsel and verify current Microsoft requirements for its tenant.
Related planning boundaries
Preservation is not the same as operational resilience. A hold can preserve content covered by the policy, but it does not replace an on-premises backup plan or a tested managed IT and disaster-recovery plan. Document these controls separately so legal preservation, recovery, and business continuity are not treated as interchangeable.
A legal hold also does not replace security or sector-specific governance. Coordinate the approved preservation process with phishing-risk controls, the organization’s healthcare cybersecurity and HIPAA planning where applicable, and the operating model described in Rivell’s law-firm managed IT guide. If data is moving between tenants, include preservation in the Microsoft 365 tenant-to-tenant migration plan before identities, domains, or workload locations change.
Need a technical Microsoft 365 preservation-readiness review? Rivell can document workloads, identities, permissions, locations, operating ownership, and verification gaps against an approved legal scope. Contact Rivell to plan the technical assessment.
Frequently asked questions
Is Exchange Litigation Hold enough for Teams and SharePoint?
No. Exchange Litigation Hold is mailbox-focused. Teams messages, channel files, personal files, recordings, and SharePoint content can reside in different mailbox, OneDrive, and SharePoint locations. Map the actual content types and use the appropriate approved controls.
Does creating a hold prove every location is preserved?
No. Policy application is asynchronous, and individual locations can remain pending, partially applied, or failed. Verify the current per-location results and remediate every exception.
Which Microsoft 365 license is required?
The answer depends on the feature, organization subscription, affected users, and whether premium eDiscovery capabilities are used. Check Microsoft’s current subscription requirements and the tenant’s assigned licenses before implementation.
Can an eDiscovery hold replace an organization-wide retention policy?
Usually not. Microsoft describes eDiscovery holds as specific and matter-focused, while retention policies and labels support broader lifecycle requirements. Legal, compliance, and records-management owners should choose the approved control.
Can Rivell decide when a legal hold should be released?
No. Release requires authorization from the organization and its legal counsel. Rivell can execute and document an approved technical change and verify the resulting tenant state.
Primary Microsoft sources
- Create holds in eDiscovery
- Manage holds in eDiscovery
- Learn about the eDiscovery workflow
- Assign permissions in eDiscovery
- Learn about retention policies and retention labels
- Finding Microsoft Teams content in eDiscovery
- Use the hold report in eDiscovery
- Process reports in eDiscovery
- Identify Exchange mailbox hold types
- Place a mailbox on Litigation Hold
- Resolve eDiscovery hold errors