Legal Hold in Microsoft 365: Scope and Verification Guide

A Microsoft 365 legal hold is a preservation control, not a complete legal process. The correct design depends on the matter, custodians, workloads, content locations, licensing, permissions, and instructions from counsel. This guide gives New Jersey organizations a technical framework for scoping, applying, verifying, maintaining, and releasing preservation controls without treating a checkbox as proof.

Method and freshness: reviewed August 19, 2026 against current Microsoft Learn guidance for Microsoft Purview eDiscovery, retention, Exchange Litigation Hold, Teams content locations, permissions, hold status, and hold errors. Microsoft changes licensing and portal behavior, so verify the current tenant and documentation before implementation.

Important boundary: Rivell provides technical planning, implementation support, evidence collection, and operational monitoring. Rivell does not decide who is a custodian, what content is legally relevant, how long a matter must be preserved, or when a hold may be released. Those decisions belong to the organization and its legal counsel.

What does “legal hold” mean in Microsoft 365?

People often use “legal hold” as a general label for several different Microsoft 365 controls. They are related, but they are not interchangeable. Microsoft Purview eDiscovery holds are case-specific controls used to preserve data for an investigation or legal matter. Microsoft 365 retention policies and labels are broader lifecycle controls designed to retain or delete content according to organizational rules. Exchange Litigation Hold is a mailbox-level preservation feature for Exchange Online.

Microsoft recommends choosing retention or eDiscovery holds as appropriate instead of treating legacy Litigation Hold as the default for every workload. A preservation plan can use more than one control, but overlapping policies make release and deletion behavior harder to understand. Before applying or releasing anything, identify every control already acting on each mailbox or site.

ControlTypical purposePrimary scopeKey limitation
Purview eDiscovery holdSpecific investigation or legal matterSelected mailboxes, OneDrive accounts, SharePoint sites, Teams or Microsoft 365 group locationsCase scope and release depend on administrator action and legal direction
Microsoft 365 retentionLong-term information lifecycle and compliance policyBroad workloads, locations, users, groups, or contentIt should not be substituted for matter-specific scoping without counsel and records-management review
Exchange Litigation HoldPreserve mailbox content, including deleted and modified itemsExchange Online mailbox and archiveIt does not independently cover SharePoint, OneDrive, or Teams files

Which Microsoft 365 locations belong in the scope?

Start with the business activity, not the product name. A single employee may create relevant content in Exchange, OneDrive, SharePoint, Teams chats, standard channels, private channels, shared channels, meeting recordings, and Microsoft 365 group locations. Microsoft documents different compliance storage locations for different Teams content types, so selecting only a user mailbox or only the parent team site can leave gaps.

Business contentLocations to investigateScoping question
Email, calendar, and mailbox itemsCustodian Exchange mailbox and archive, if enabledAre all named custodians, shared mailboxes, and relevant group mailboxes identified?
Personal working files and files shared in chatsCustodian OneDrive accountsWho created or shared the file, and did ownership change?
Team and department filesRelevant SharePoint sitesDoes the matter touch the parent site, a private-channel site, or a shared-channel site?
Teams 1:1 or group chat messagesParticipant mailboxes used for compliance recordsAre all relevant participants and the correct date range included?
Standard channel messages and filesParent team mailbox plus the associated SharePoint siteWere both messages and files scoped?
Private or shared channel contentChannel-specific or parent-team mailbox locations plus the separate channel SharePoint site, as Microsoft currently documentsWas the channel type confirmed instead of assuming it behaves like a standard channel?
Meeting recordings and transcriptsOrganizer or recording-owner OneDrive, or the relevant SharePoint site, depending on meeting configurationWas the actual recording owner and storage location verified?

Decision rule: build a custodian-and-location register before creating the hold. For every person, team, site, and workload, record the immutable identifier, current URL or address, content type, matter relevance, approval source, and verification owner.

How should an organization prepare before applying a hold?

  1. Obtain written legal direction. Record the matter, custodians, date range, content types, search criteria if applicable, preservation start, and decision authority.
  2. Confirm licensing from current Microsoft requirements. Do not rely on a generic E3/E5 statement. Verify the organization subscription, each affected user, the features being used, and any premium reporting or review functions.
  3. Assign least-privilege eDiscovery roles. Microsoft separates case, hold, search, review, and export capabilities. Confirm the operator has the required role and case membership without granting broader access than needed.
  4. Inventory all data locations. Map Exchange, OneDrive, SharePoint, Teams, Microsoft 365 groups, shared mailboxes, private channels, shared channels, and meeting content relevant to the matter.
  5. Check existing preservation controls. Retention policies, retention labels, Litigation Hold, eDiscovery holds, delay holds, and Single Item Recovery can overlap.
  6. Define evidence and rollback requirements. Decide which screenshots, exports, policy identifiers, approvals, location results, timestamps, and change records must be retained.

What is a defensible technical execution sequence?

1. Create or identify the eDiscovery case

Use a case identifier that matches the organization’s legal matter register. Restrict case access to authorized personnel and document who can create, edit, apply, review, and release holds.

2. Add the approved data sources

Add the mailboxes, OneDrive accounts, SharePoint sites, Teams locations, and group locations in the approved scope. Confirm URLs and identities from the tenant rather than copying stale documentation. If many locations must be added, Microsoft recommends consolidating updates instead of repeatedly changing a policy while distribution is pending.

3. Apply the hold and wait for location results

Applying a policy is asynchronous. Treat “in progress,” partial application, or location errors as unresolved. Do not delete a user or data location based only on the fact that a policy was submitted.

4. Verify each location

Use the current hold-policy details and process results to verify the status of every mailbox and site. Microsoft’s tenant-wide hold report is a useful inventory view, but it is a preview feature and can lag recent policy changes. For current status, use the specific case and policy details.

5. Record and remediate exceptions

Preserve the location status and error for every exception. Common causes include an inaccessible or nonexistent site, a site with no quota, an ineligible recipient type, or a transient distribution failure. Correct the cause and use Microsoft’s supported retry action. Never treat a missing error message in a stale report as proof that preservation succeeded.

6. Maintain the hold as the matter changes

Microsoft states that eDiscovery does not continuously monitor every workload or location identity change after the hold operation completes. When a UPN, SharePoint URL, OneDrive URL, custodian list, team, or matter scope changes, update the data-source register, apply the approved policy change, and verify the affected locations again.

What evidence should be retained?

EvidenceWhy it mattersAcceptance check
Legal authorization and scopeConnects the technical action to an approved matterNamed approver, date, matter ID, custodians, workloads, release authority
Subscription and role preflightShows the feature and operator were eligible at execution timeCurrent Microsoft source, tenant result, assigned roles, case membership
Location registerPrevents mailbox-only or parent-site-only gapsEvery relevant content type maps to a tenant location and owner
Policy and per-location resultsDistinguishes submission from successful applicationNo unresolved applying, partial, failed, or location-error state
Change logTracks additions, removals, identity changes, retries, and approvalsTimestamp, operator, old state, new state, reason, evidence link
Periodic reviewDetects custodian and workload driftScope, status, errors, subscriptions, and access reviewed on schedule
Release packagePrevents an unsupported or premature releaseWritten counsel approval, affected controls, exports if required, post-release verification

How should a hold be released?

Release is a governed change, not a cleanup shortcut. Obtain written direction from counsel, identify every policy or hold source affecting the locations, preserve required exports and audit records, then disable or remove only the approved control. A location can remain preserved because of another eDiscovery hold, retention policy, retention label, Litigation Hold, delay hold, or recovery setting.

After the change, verify the policy and location states and record what remains. Do not use an undocumented command copied from a guide to force-remove a delay hold. Follow Microsoft’s current product documentation and escalation path because release can make content eligible for deletion.

Who owns each decision?

Decision or taskPrimary ownerTechnical support role
Matter scope, custodians, date range, relevance, and releaseLegal counsel and authorized business leadershipTranslate approved scope into tenant locations
Records policy and retention scheduleLegal, compliance, and records managementConfigure approved retention controls and report conflicts
Subscription, permissions, identity, and workload inventoryMicrosoft 365 ownerAudit tenant state and document gaps
Hold configuration and per-location verificationAuthorized eDiscovery operatorImplement, capture evidence, remediate errors, and monitor status
Evidence export and chain of custodyLegal or eDiscovery leadSupport approved exports, access controls, hashes, and transfer logs

How Rivell can support the technical work

Rivell can help a New Jersey organization inventory Microsoft 365 workloads, review identities and access, map approved custodians to tenant locations, confirm technical prerequisites, implement an approved hold design, document location results, monitor errors, and maintain the operating runbook. Related work may include Microsoft 365 implementation support, identity and cybersecurity controls, backup and disaster-recovery planning, and IT support for New Jersey law firms.

Rivell does not determine legal scope, provide legal advice, guarantee preservation completeness, or authorize release. The organization should involve qualified counsel and verify current Microsoft requirements for its tenant.

Related planning boundaries

Preservation is not the same as operational resilience. A hold can preserve content covered by the policy, but it does not replace an on-premises backup plan or a tested managed IT and disaster-recovery plan. Document these controls separately so legal preservation, recovery, and business continuity are not treated as interchangeable.

A legal hold also does not replace security or sector-specific governance. Coordinate the approved preservation process with phishing-risk controls, the organization’s healthcare cybersecurity and HIPAA planning where applicable, and the operating model described in Rivell’s law-firm managed IT guide. If data is moving between tenants, include preservation in the Microsoft 365 tenant-to-tenant migration plan before identities, domains, or workload locations change.

Need a technical Microsoft 365 preservation-readiness review? Rivell can document workloads, identities, permissions, locations, operating ownership, and verification gaps against an approved legal scope. Contact Rivell to plan the technical assessment.

Frequently asked questions

Is Exchange Litigation Hold enough for Teams and SharePoint?

No. Exchange Litigation Hold is mailbox-focused. Teams messages, channel files, personal files, recordings, and SharePoint content can reside in different mailbox, OneDrive, and SharePoint locations. Map the actual content types and use the appropriate approved controls.

Does creating a hold prove every location is preserved?

No. Policy application is asynchronous, and individual locations can remain pending, partially applied, or failed. Verify the current per-location results and remediate every exception.

Which Microsoft 365 license is required?

The answer depends on the feature, organization subscription, affected users, and whether premium eDiscovery capabilities are used. Check Microsoft’s current subscription requirements and the tenant’s assigned licenses before implementation.

Can an eDiscovery hold replace an organization-wide retention policy?

Usually not. Microsoft describes eDiscovery holds as specific and matter-focused, while retention policies and labels support broader lifecycle requirements. Legal, compliance, and records-management owners should choose the approved control.

Can Rivell decide when a legal hold should be released?

No. Release requires authorization from the organization and its legal counsel. Rivell can execute and document an approved technical change and verify the resulting tenant state.

Primary Microsoft sources

Facebook
Twitter
LinkedIn