FileClass/ItemClass/MessageKind metadata in direct search exports csv

Sripriya Gunukula 20 Reputation points
2025-11-04T06:46:44.1466667+00:00

Is there any possible way to have FileClass populated in metadata csv of direct purview exports from search cases?
If not, then is it possible to list the scenarios where the ItemClass or Message Kind will be blank.
We see some entries in the csv [metadata for search exports] have all the FileClass, ItemClass, MessageKind as empty which will make it difficult for us to categorize the data.
A list of all supported ItemClass will help.
We want to clearly know the differences in metadata for search exports and review set exports in purview portal.

Thanks,
Sripriya

Microsoft Security | Microsoft Purview
0 comments No comments

2 answers

Sort by: Most helpful
  1. Pratyush Vashistha 5,135 Reputation points Microsoft External Staff Moderator
    2025-12-01T05:05:52.98+00:00

    You're absolutely correct Searching for Help with Metadata when you export email items from a Microsoft Purview eDiscovery review set in .msg format, the enriched eDiscovery metadata (like FileClass, ItemClass, MessageKind, Custodian, ExportID, etc.) is not embedded inside the .msg file itself.

    The .msg file contains only the native email properties (From, To, Subject, Body, Attachments, etc.), the same as if you'd dragged an email from Outlook to your desktop. Windows file properties or Outlook message details won’t show Purview-specific metadata because that contextual information is external to the message format.

    Instead, all eDiscovery metadata is provided exclusively in the accompanying CSV manifest file that downloads alongside the .msg files during export. Microsoft confirms this in their documentation:

    “When you export documents from a review set in eDiscovery (Premium), the export includes a CSV file that contains metadata for each document in the export.” — Export documents from a review set

    This CSV is your authoritative source for mapping each .msg filename (e.g., ABC123.msg) to its full metadata record—including ItemClass, MessageKind, and other case-specific fields.

    So yes, you’re right: the metadata lives only in the CSV, not in the .msg file. There’s no alternative method (via Outlook, file properties, PowerShell, or third-party tools) to extract the Purview-assigned metadata from the .msg itself because it was never written into it.

    One quick tip: always keep the CSV and the .msg files together in the same folder structure as exported renaming or separating them can break traceability.

    Please "Accept as Answer" or click 'Thumbs Up YES' if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.

    Thanks

    Pratyush

    Was this answer helpful?


  2. Pratyush Vashistha 5,135 Reputation points Microsoft External Staff Moderator
    2025-11-06T11:29:04.66+00:00

    Hi Sripriya,

    Thanks for your question on the Microsoft Q&A portal! You're seeing FileClass, ItemClass, and MessageKind blank in direct search export CSVs—and that’s expected behavior based on how Microsoft Purview handles metadata across export types.

    First, FileClass is not included in metadata from direct search exports. Microsoft only populates FileClass in review set exports under eDiscovery (Premium), where documents undergo additional processing and classification. As confirmed in Microsoft’s documentation: “This article defines the metadata fields for documents in a review set in a case in Microsoft Purview eDiscovery (Premium)” . The same level of enrichment does not apply to raw search exports.

    For ItemClass and MessageKind, these fields will be blank when the system cannot assign a recognized type—for example, with unstructured files (like .txt, custom logs), non-M365 sources, or items lacking email/message schema. Microsoft states that metadata fields like these are tied to the content’s origin and processing context, and they are not guaranteed to appear in search exports only in review set exports where normalization occurs .

    Regarding a list of supported ItemClass values, Microsoft does not publish a complete, versioned list of all possible ItemClass or MessageKind values in public documentation. The available values depend on the source (Exchange, SharePoint, Teams, etc.) and internal classification logic. What is documented is that “export items from a review set in eDiscovery (Premium)” includes enriched metadata fields that are absent in basic content or search exports.

    The key difference between search exports and review set exports is clearly called out:

    “Export lets you customize the content that's included in the download package when you export items from a review set in eDiscovery (Premium)”, whereas standard search exports (from Content Search or eDiscovery Standard) deliver raw hits with minimal enrichment, .

    Reference links:

    To help narrow this further: are you using eDiscovery Standard or Premium, and are your exports coming from a review set or directly from a search result? That will determine whether you can realistically expect these fields to be populated.

    Please "Accept as Answer" or click 'Thumbs Up YES' if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.

    Thanks

    Pratyush

    User's image

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.