Glossary
eDiscovery
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft Purview's toolset for finding, preserving, reviewing, and exporting content for legal cases and investigations.
eDiscovery in Microsoft Purview is the toolset for finding, preserving, reviewing, and exporting Microsoft 365 content for legal cases, regulatory requests, and internal investigations. Searches span Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats and channels, and Viva Engage. Two tiers: eDiscovery (Standard) included with E3, providing content search, hold, and basic export; and eDiscovery (Premium) included with E5, adding custodian management, conversation reconstruction, predictive coding, near-duplicate detection, advanced review-set workflows, and Cloud Attached eDiscovery integration with platforms like Relativity. Replaced older Exchange-specific In-Place eDiscovery. Per-user eDiscovery licences may apply for Premium scenarios.
Standard vs Premium, in practice
eDiscovery (Standard) is enough for straightforward cases: a content search across a defined set of mailboxes and sites, a hold to prevent deletion while the matter is active, and an export of what matched. eDiscovery (Premium) exists for genuinely contested litigation and regulatory matters where the volume and legal stakes justify more structure: it introduces the concept of a formal case with named custodians (the specific individuals whose data is in scope), legal hold notifications (a documented, trackable process for telling a custodian they must preserve relevant material and acknowledging that instruction), review sets with tagging and redaction workflows for outside counsel to work through material without giving them raw mailbox access, and analytics like near-duplicate detection and email threading that reduce the volume a human reviewer actually has to read.
Worked example
A company receives a regulatory inquiry requiring it to produce all communications between three named executives and an external vendor over an 18-month period. Using eDiscovery (Premium), a case is created naming the three executives as custodians; a hold is placed on their mailboxes and OneDrive accounts the moment the case opens, so nothing relevant can be deleted (including by IT's own routine mailbox retention policies) while the matter is live. A search is run scoped to the custodians, the vendor's known domains, and the relevant date range; email threading collapses long reply chains into their most complete version so reviewers aren't reading the same thread twenty times; near-duplicate detection groups substantially identical attachments together. The review team tags responsive documents in a review set, and the final production is exported in a format outside counsel can load directly into their own review platform.
Holds don't just freeze — they preserve quietly
A hold placed via eDiscovery doesn't visibly change anything for the custodian — their mailbox looks and behaves normally, and they can still delete messages from their own view. What actually happens is the content is retained in a hidden preservation area even after the user's own deletion, recoverable for the eDiscovery search regardless of what the user did on their end. This is deliberate: a hold that visibly altered a custodian's mailbox would tip them off that they're under investigation, which is exactly wrong for internal-investigation scenarios (though for formal litigation holds, a legal hold notification is often required precisely so the custodian does know and can acknowledge their preservation obligation).
Common pitfalls
The most common mistake is scoping a search too broadly out of caution ("just search everything, everyone, always") — which massively inflates review cost and time, since eDiscovery's own tooling doesn't replace the human legal judgment needed to keep a matter proportionate. The second is not accounting for the interaction between a hold and a tenant's normal retention policies: content under a hold survives even a retention policy's deletion schedule, which is correct behaviour but occasionally surprises admins who assumed their retention policy alone governed what could be recovered.