Microsoft Purview eDiscovery
There is no server. The mail runs in the cloud, like the rest of the administration, and the computers you find on site hold at most a local cache of what sits in the tenant. Searching locally is pointless, and the Microsoft 365 tenant is the only route to the material requested.
That finding belongs in the report, and not as an aside. It accounts for why you go on working through the administrator of an environment that is not yours, and why the collection looks different from an ordinary copy of a disk.
Permissions and conditions of access
The precise export permission exists only inside the eDiscovery Manager role group. Check with the IT administrator whether that role has been assigned.
Permissions nobody has by default
Purview eDiscovery sits behind a role model of its own, separate from ordinary administration. An account with global administrator rights cannot run an eDiscovery export as long as the corresponding role has not been granted explicitly: the Export role sits only in the eDiscovery Manager role group (with its eDiscovery Administrator subgroup). Role groups such as Compliance Administrator and Organization Management do get Case Management, Compliance Search and Hold, but no Export and no Preview.
In practice that means “we made you an administrator” is not enough, and you find out only at the moment the Export button is missing. Have the IT administrator add you to the eDiscovery Manager role group, in the Purview portal under Settings → Role groups.
Two conditions attach to that access, and they weigh more than they sound.
- Ask for personal, non-shared access on your own email address. Every operation in the tenant is logged against an account. On a shared administrator account that log proves nothing about who did what, and therefore nothing about what you did not do. Microsoft itself treats the download links of an export package as personal and non-shareable.
- Close the loop in writing. After a successful download, confirm to the administrator that the access can be revoked, and note that moment. Put both the opening and the closing in the report. That loop is the difference between a defensible and a contestable intervention in someone else’s environment.
The steps
- Have the permissions granted as above, and check that Export is genuinely among them before you schedule anything.
- Open a case, named after the assignment.
- Run a custodian-based search: everything attached to the account and the email address, with the date range the court imposed. Keep the exact query text and the locations selected, because that is what you have to be able to show when someone asks how the selection came about.
- Request the export from the search, with the settings in the next section. Microsoft prepares the package in the background.
- Download, extract and hash, and only then have the access closed.
Settings that matter in a court assignment
Export format. Create PSTs for messages yields PST files that open in an email client; Create .msg files for messages yields individual messages. PST is the workable choice for a mailbox; loose .msg files are handy when individual messages have to go into a bundle as numbered exhibits.
Package size. The maximum PST package size can be set to 1, 2, 5 (default) or 10 GB, and the maximum zip to 2, 10 (default), 20 or 40 GB. Microsoft goes no higher than ten gigabytes, because large PST files are prone to corruption. Count on a full mailbox coming back in several PSTs. Number them, hash them one by one and list all of them in the report; a single hash over the whole set says nothing about the file the opposing party is going to open.
Organize data from different locations into separate folders or PSTs. Switch it on: you get one PST per mailbox, named after the address, so the origin stays visible in the file name. Note that the primary mailbox and the archive are merged into the same PST regardless.
Include folder and path of the source. Switch it on. Without this option every message lands in the root of the PST and the original folder structure survives only in the report. The folder structure is often a finding in itself.
Items.csv. The process report that comes with the export is your inventory: per item it holds the source, the original path and the metadata. This is the counting instrument, not the email client.
Pitfalls
The export takes hours. Close to three hours is not unusual. Plan around it: the last steps can be done from your own office. An export that runs longer than seven days is aborted automatically. Split a large set by date range or by source.
The package disappears after fourteen days. An export from a search expires fourteen days after it was created, after which the package and all the data in it are deleted automatically and irreversibly. So download at once, and put the files somewhere safe immediately. Anyone who postpones the download until after the holidays gets to run the whole export again, with a fresh intervention in someone else’s environment as the price.
More comes along than mail. Chat messages from Teams and Skype are kept in the mailbox, so a custodian-based search takes them along, including when the assignment speaks of “email”. On top of that there is a separate option that adds Teams and Viva Engage messages in a window of twelve hours before and after each item found: that is context by design, and it does not itself answer the query. Data from other applications in the mailbox can end up in the package as HTML as well. Decide before the export what is allowed in, and write down what you chose.
The folder counter in the email client is not a count. For a number of folders it shows the unread item count, not the total. Anyone who copies that figure reports a wrong number in a document that goes out under his signature. Count from Items.csv.
Deleted mail sits apart, or nowhere. Deleted messages live in the Recoverable Items folder and not among the ordinary mail. If they were expressly asked for, check that the folder is genuinely in the package. And write down what the environment was actually still able to retain: without a retention policy or a hold, whatever fell outside the retention period is gone for good. That is not a failed export, that is a finding.
Do not extract with File Explorer. Long paths run into the file system limit; use 7-Zip or something comparable. Extraction tools can also modify file properties. For timestamps Items.csv is the reference point, not what you see in the folder.
The A/B split
A custodian-based export almost always contains more than the assignment covers. That knot is not for the expert to cut: what a party ultimately gets to see is for the court to decide.
So deliver two sets:
- Category A: the raw export, kept whole and unaltered as source material, with hash values.
- Category B: the production set, containing only what falls within the assignment beyond dispute.
Describe both in the report, produce B, and keep A available under protection. You do not solve the scope question, you make it decidable, and that is where the expert’s role ends.
Verification stays minimal
If the assignment calls for no analysis of the content, you check only whether the export succeeded:
- sort by date and note the oldest and the newest message, which shows that the date range imposed was applied correctly;
- list the folder categories present.
Nothing further. Write down expressly that the check went no further than this, so that nobody can assume later that you read along.
Sources
Screen names in the Purview portal change regularly; the logic underneath does not. When in doubt, go to the documentation itself:
- Microsoft Learn, Assign permissions in eDiscovery: the role groups and what each role allows.
- Microsoft Learn, Export search results in eDiscovery: export options, package sizes and the fourteen-day expiry.