Purview eDiscovery — standard vs premium
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
How Purview eDiscovery finds, preserves, and exports content for legal cases — and what premium adds.
5 min read
Share as imagePNGPurview eDiscovery is the toolset for legal teams to find, preserve, review, and export Microsoft 365 content for litigation, regulatory requests, and internal investigations. Microsoft offers two tiers — Standard and Premium — and the difference matters a lot for serious cases.
Standard eDiscovery
Available in Microsoft 365 E3 / Office 365 E3, Standard eDiscovery provides:
- Content search across Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats, and Viva Engage.
- Case management to organise searches.
- Hold on specific mailboxes and sites, preserving content for the case.
- Export to PST and to standard formats.
It's enough for basic compliance work — a regulator asks for emails between two parties about a specific topic, you search, hold, and export.
Premium eDiscovery
Available in Microsoft 365 E5 and as a Purview add-on, Premium adds:
- Custodian management — tracks individuals, their associated data sources, and hold notifications.
- Legal hold notifications with acknowledgment tracking.
- Communication compliance integration to follow conversations across workloads.
- Advanced indexing of file content and email metadata.
- Conversation reconstruction — Teams chats reassembled into a coherent conversation, not isolated messages.
- Near-duplicate detection and email threading to reduce review volume.
- Predictive coding — ML-driven relevance ranking that trains on reviewer decisions.
- Review sets with annotations, redactions, and tagging.
- Working set management for very large cases (millions of items).
- Export with metadata in load files for downstream review tools (Relativity, etc.).
For large cases — where review volume is high and the cost of manual review dominates — Premium is dramatically more efficient.
Cloud Attached eDiscovery
For organisations using third-party eDiscovery platforms like Relativity, Cloud Attached eDiscovery keeps Microsoft 365 as the source of truth: data is preserved and processed in Purview, and only the relevant subset is exported to the review platform.
Operational tips
- Practice with non-case data before a real matter arrives. eDiscovery isn't intuitive on day one.
- Build named saved searches for common scenarios (a specific user's mail over six months).
- Set up role groups so legal and compliance teams have eDiscovery roles without broader admin rights.
- Combine with retention policies — eDiscovery searches content that exists, including in preservation hold from retention.
- For Teams chat, ensure retention is sufficient — chats default to 30-day retention on some plans.
Licensing
- eDiscovery (Standard) — Microsoft 365 / Office 365 E3 and above.
- eDiscovery (Premium) — Microsoft 365 E5, Office 365 E5, or Microsoft 365 E5 Compliance add-on.
- Some advanced features require per-user "eDiscovery user licences" rather than tenant-level entitlement.
For legal teams in regulated industries, Premium is rarely optional. For SMBs handling occasional requests, Standard plus a thoughtful retention design is usually enough.
Decision matrix — Standard, Premium, or third-party
| Situation | Recommendation | |---|---| | One or two matters a year, mostly a single custodian | Standard. Practise the search-hold-export loop on a training case first. | | Regulated industry with steady request volume | Premium. Custodian management and hold notifications are the difference between "we responded" and "we can prove we responded." | | Large litigation with millions of items and outside counsel | Premium plus Cloud Attached — process in Purview, export the relevant subset to Relativity or your review platform. | | You already run Relativity or a similar review tool tenant-wide | Cloud Attached eDiscovery. Do not duplicate review UX in Purview when your reviewers already live in the third-party tool. | | E3 tenant, single-request annual regulator | Standard is enough — but review Teams chat retention because 30 days is not enough if the request lands late. |
Wrong-fit warnings
- eDiscovery is not backup. A hold preserves content against deletion for a case; it does not restore a corrupted mailbox or a wiped SharePoint site. If someone loses a file to a bad workflow, that is a retention/recovery problem, not an eDiscovery one.
- Standard's export is not review-tool-friendly. You get PST and native files; if downstream counsel wants a load file with control numbers and metadata, that is Premium.
- Holds do not preserve everything forever automatically. A hold covers the specified custodians and locations. New locations added mid-case need explicit hold updates.
- Predictive coding is not a substitute for a review protocol. It ranks relevance based on reviewer decisions — garbage in, garbage out. Train a coder against a defensible seed set, not against yesterday's coffee-fuelled tagging.
Worked example — a regulator asks for six months of correspondence
Scenario: E5 tenant. Regulator requests all correspondence between four named employees and an external counterparty domain over the last six months, plus any shared documents.
- Day 1: Open a Premium case. Add the four employees as custodians, capturing their mailboxes, OneDrive, Teams chat, and any team memberships they own. Legal hold notifications go out; acknowledgments track in the case.
- Day 2: Draft a collection query — recipient / sender domain match, date range, plus keywords the counterparty is likely to have used. Preview the collection to check volume and refine before commit.
- Day 3: Commit the collection to a review set. Turn on near-duplicate detection and email threading — usually reduces the raw item count by 30–60%.
- Day 4–7: Reviewers tag responsive / privileged / redact. Redactions burn into the produced copy; the source stays intact.
- Day 8: Export with load file. Hand-off to outside counsel or produce direct to the regulator per the request format.
- Day 30: Release the hold once the response is accepted and the retention rules allow. Document the release in the case timeline for defensibility.
FAQ for MSPs
- Can we run eDiscovery on behalf of a customer? Yes, if you hold the reviewer / manager role in their tenant and the customer's legal has approved the delegation in writing. Delegated Access via GDAP is usually enough; add role assignments in each tenant explicitly.
- Does eDiscovery show up in Lighthouse? No first-class view. You will operate per-tenant.
- A customer without E5 needs Premium for one case — options? Buy the Purview eDiscovery add-on per-custodian, run the case, drop the add-on afterwards. Cheaper than blanket upgrades for a one-off matter.
- How do we avoid touching customer data ourselves? Restrict your role to case configuration and hold administration; assign the customer's own legal team as reviewers so they see and tag content — you do not.
Frequently asked questions
- Has Microsoft replaced Content Search?
- The classic Content Search and Core/Advanced eDiscovery tools were unified into the new Purview eDiscovery experience during 2025, with Standard and Premium as feature tiers within it. Old cases were migrated; the cmdlets remained available for a period.
Further reading
Was this useful?
Spot something wrong or want a topic covered? Send it through the contact form.