Introduction
After you have classified your data with sensitivity labels and protected it with DLP policies, the next question is: how long do we keep it? Some data must be preserved for years for regulatory compliance. Other data should be deleted as soon as possible to reduce legal exposure. Retention policies and retention labels answer both needs.
Retention policies apply broad rules across entire workloads – keep all Exchange email for 7 years, delete all Teams chats after 90 days. Retention labels give you item-level control – apply a label to a specific contract that keeps it for 10 years then deletes it. This guide explains how to create both, when to use each, and how to avoid conflicts.
Retention features require Microsoft 365 E3 or higher. Records management – with event-based retention and disposition review – requires E5. Before configuring anything, go to Data lifecycle management and check the Overview tab. It shows items currently subject to retention, active policies, and disposition activity. This tells you what is already in effect before you add new rules. If you are still setting up core Purview features, start with the first-day setup guide.
Retention Policies vs Retention Labels: Which One to Use
A retention policy applies broadly to an entire location – all Exchange mailboxes, all SharePoint sites, all Teams channels. It is a blanket rule. You create one policy that says “retain all Exchange email for 5 years” and it applies to every mailbox in scope. Policies are simple to set up and impossible for users to override, but they lack granularity.
A retention label is applied to individual items – a specific email, a document, a folder. Labels can be applied manually by users, automatically by auto-labeling policies, or set as a default on a SharePoint library so every document inherits it. Labels travel with content – an email labeled “keep 7 years” remains under retention even if forwarded.
Use retention policies for baseline compliance across the organization. Use retention labels for exceptions and item-level control. Policies and labels work together. If a document is subject to both a 5-year retention policy and a 10-year retention label, Purview applies the longer period – the 10-year label wins. This means you can safely deploy broad policies knowing specific labels can extend retention without shortening it. For item-level classification before retention, set up sensitivity labels first – they determine who can access content, while retention labels determine how long it lives.
Creating Your First Retention Policy Step by Step
Go to Data lifecycle management and select Retention policies. Click New retention policy. Give it a descriptive name like “Retain Exchange email 7 years” – clarity saves confusion later. Choose Static for fixed locations or Adaptive to dynamically include locations based on attributes like department. Start with static.
On the locations page, select Exchange email, SharePoint sites, OneDrive accounts, Teams messages, or other workloads. For a first policy, select Exchange and SharePoint and apply to all. On the retention settings page, choose Retain items for a specific period and set the duration. The critical choice is at the bottom – at the end of the retention period, should items be deleted automatically or just stop being retained? For most compliance scenarios, automatic deletion is the right choice. Keeping data beyond its required retention period increases legal exposure.
If your policy does not seem to be deleting expired items, check for conflicts. Purview always honors the longest retention period across all applicable policies and labels. An item subject to both a 2-year delete policy and a 5-year retain policy will be kept for 5 years. The troubleshooting guide covers retention policy conflicts and other common configuration issues.
Creating Retention Labels and Publishing Them to Users
Retention labels are created separately from retention policies. Go to Data lifecycle management and select Retention labels. Click Create a label. The wizard asks about the label’s purpose: retain data, retain then delete, only delete after a period, or mark as a record. A record label applies stricter controls – users cannot edit or delete the content at all. Use record labels for documents with legal immutability requirements like signed contracts or financial filings.
After configuring the retention action and period, publish the label through a label policy – similar to how sensitivity label policies work. Select which labels to publish, which users and groups the policy applies to, and where the label should appear. Users then see the label in Outlook, SharePoint, and OneDrive. You can also configure the label to be applied automatically using the same auto-labeling mechanism used for sensitivity labels, with conditions based on sensitive info types or trainable classifiers.
Once retention policies and labels are deployed, track their status through the monitoring dashboards. The Data lifecycle management overview shows you how many items are under retention, which policies are active, and any pending disposition reviews. If you also need to preserve specific data for legal cases, eDiscovery holds take precedence over retention policies – data under a legal hold will never be deleted until the hold is released.



Leave a Reply
You must be logged in to post a comment.