1. Understand the Purview Security and Governance System
Map the Purview Landscape and Its Security Boundaries Translate Licensing, Roles, and Governance into an Operating Model
2. Discover, Map, and Curate the Data Estate
Design Data Map Scanning and Metadata Collection Build Unified Catalog, Lineage, Quality, and Data Products
3. Classify and Protect Information
Engineer Sensitive Information Types and Classifiers Design Sensitivity Labels, Publishing, and Auto-Labeling
4. Prevent Unsafe Data Movement
Design DLP Policies from Business Scenarios Extend DLP to Endpoints, Browsers, Teams, and AI
5. Govern the Information Lifecycle
Design Retention Policies and Labels Operate Records, Events, Disposition, and Legal Holds
6. Investigate and Preserve Evidence
Use Purview Audit as Evidence Run eDiscovery Cases, Holds, Searches, and Reviews
7. Manage Human, Communication, and Compliance Risk
Operate Insider Risk and Communication Compliance Responsibly Use Information Barriers and Compliance Manager as Governed Controls
8. Protect Privacy, SharePoint, Microsoft 365, and AI
Secure SharePoint and Microsoft 365 Collaboration Paths Govern Microsoft 365 Copilot and Other Generative AI Protect Privacy and Support Data-Subject Workflows
9. Integrate, Report, and Operate Purview
Integrate Scanners, APIs, Reporting, and Multi-Cloud Sources Run Purview as a Production Security Service Turn DSPM Findings into Data Security Investigations
10. Design and Prove a Complete Purview Program
Build the Purview Target Architecture and Roadmap Capstone: Prove the Security Layer End to End
6. Investigate and Preserve Evidence

Run eDiscovery Cases, Holds, Searches, and Reviews

Move from legal purpose to custodians, holds, collections, review sets, exports, and defensible case closure.

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.

In this lesson, you will learn to:

  • Apply a repeatable method for run ediscovery cases, holds, searches, and reviews in a licensed, governed, and testable Purview environment.

Run eDiscovery Cases, Holds, Searches, and Reviews

This lesson develops a practical understanding of run ediscovery cases, holds, searches, and reviews and connects design choices to supported capabilities, operational dependencies, user impact, and verifiable evidence.

eDiscovery begins with authority and a scoped matter

An eDiscovery case organizes people, data sources, holds, searches, review, and exports for a legal or investigative purpose. Before collecting content, record the authority, matter, custodians, date range, issues, locations, preservation duty, and approved reviewers. Overcollection increases privacy, cost, and review burden; undercollection can miss relevant evidence.

Preserve first when deletion risk exists. Validate that holds cover the intended mailboxes, sites, OneDrive accounts, Teams-connected locations, and other supported sources. A hold status or item estimate is operational evidence, not the final legal conclusion. When size estimates are unavailable or changed in a portal experience, validate with searches and documented checks rather than assuming nothing is preserved.

Build queries from issues and concepts, then test them against known responsive and nonresponsive examples. Parentheses, fields, dates, operators, and keyword grouping matter.

Review and export must retain case integrity

Deduplicate and thread content where supported, but understand what the processing choice removes or groups. Reviewers need tags, issue definitions, privilege handling, quality control, and escalation. Sample excluded material to test search precision and sample expected sources to test recall.

Exports should retain case identifiers, query and review-set versions, processing choices, export operator, timestamps, item counts, errors, and custody. Protect exports outside Purview with equivalent access and retention. Close a case only when holds are reviewed and released under authority, residual evidence has an owner, and the closure record explains what happened.

The condition builder helps structure searches, but it does not replace query validation. Use the eDiscovery condition-builder guide when combining keywords and operators, and preserve screenshots or exports only as supplements to the case record—not as the sole evidence.

Resources