How can I export only a specific 1:1 Microsoft Teams chat using Microsoft Purview eDiscovery (Premium)?

Nigam Raval 0 Reputation points
2026-07-18T01:23:05.9766667+00:00

I'm using Microsoft 365 E5 with Microsoft Purview eDiscovery (Premium).

I need to export the complete 1:1 Teams chat between two specific users, but none of the searches I've tried return only that conversation.

I've tested:

  • Participants
  • Sender
  • Recipients
  • KeyQL queries
  • Review Sets
  • Message Kind = microsoftteams, im

The results still include:

  • Other 1:1 chats
  • Group chats
  • Meeting chats

I also noticed metadata fields such as Conversation ID, Thread ID, and Conversation Type, but I can't find a way to use them to isolate a single conversation.

Is it possible to export only one specific 1:1 Teams chat using Purview eDiscovery (Premium)? If so, what is the recommended approach?I'm using Microsoft 365 E5 with Microsoft Purview eDiscovery (Premium).

Microsoft 365 and Office | Subscription, account, billing | For business | Windows
0 comments No comments

2 answers

Sort by: Most helpful
  1. Srikanth Chavithina 265 Reputation points Microsoft External Staff Moderator
    2026-07-18T09:21:17.26+00:00

    Hi @Nigam Raval

    Thanks for the detailed information.

    Based on the current capabilities of Microsoft Purview eDiscovery (Premium), it isn't possible to isolate a specific Teams 1:1 chat during the search stage using Conversation ID, Thread ID, or Conversation Type, as these aren't supported search properties.

    The supported approach is to collect the chat data for the participants, commit it to a Review set, and use the Group Teams conversations feature to reconstruct the conversation. From there, you can identify the required 1:1 chat and export it.

    If your goal is to export a PST, note that PST exports don't preserve the conversation grouping needed to isolate a single thread.

    For reference:

    Was this answer helpful?


  2. Sophie N 18,175 Reputation points Microsoft External Staff Moderator
    2026-07-18T03:44:56.4633333+00:00

    Dear @Nigam Raval,

    Based on my analysis of the situation, the short answer is yes, it is possible, but you cannot achieve this using search queries alone. The key is to use the conversation grouping and reconstruction features available within a review set in Purview eDiscovery (Premium).

    Filters like Sender, Recipients, and Message Kind are not sufficient because they cast too wide a net and will capture messages from other conversations involving the same users. Furthermore, as you've observed, you cannot use metadata fields like Conversation ID, Thread ID, or Conversation Type within the initial search syntax to isolate a single chat.

    You need to collect all relevant data into a review set first, and then use its built-in tools to isolate the specific conversation you need .

    1. Create a Collection for All Relevant Data:
      • In your eDiscovery (Premium) case, create a collection that includes the custodians (users) involved in the specific 1:1 chat. User's image
      • When defining the search query, add a condition for Type equals Instant Messages to capture all Teams chats. You might also want to add a date range to narrow the results to the relevant timeframe. User's image
    2. Commit the Collection to a Review Set:
      • This is a critical step. Commit the results of your collection to a new or existing review set. The data must be in a review set to use the conversation grouping features.
    3. Group Items by Conversation:
      • Within the review set, locate the "Group" control in the command bar.
      • Select "Group Teams or Yammer conversations" (or a similar option). This action will reconstruct the messages from Teams into threaded, readable conversations, grouping them by ConversationId . For 1:1 and group chats, the ConversationType metadata field will show "Group," so you cannot rely on that field to distinguish between them. Please refer to this document: Group and view documents in a review set in eDiscovery (Premium)
    4. Identify and Export the Single Conversation:
      • Once the review set is grouped by conversation, you will see a list of conversations.
      • You can now browse this list and identify the specific 1:1 chat you need. You can open the grouped conversation to review the full, threaded chat complete with all messages and metadata .
      • Finally, you can export this single conversation. You have the option to export the entire chat as a single PDF file, which is ideal for preserving the conversation as a complete record.

    I found a similar post on the forum regarding your issue, I hope it proves helpful to you: Can we filter the 1:1 chats and group chat messages in the pst file - Microsoft Q&A (I hope you understand that, as this article was written by other members, it adheres to the original information and language of the post)

    Important Note on PST Exports: It is crucial to understand that if your goal is to export this isolated chat to a PST file, it cannot be done directly from eDiscovery (Premium). The recommended and only effective way to isolate a single conversation is through the review set's conversation view and then exporting it as a PDF or individual files. The PST export process is designed to export mailbox items and does not retain the necessary threading or conversation metadata to filter down to a single thread.

    Please refer to this document: eDiscovery (Premium) workflow for content in Microsoft Teams

    Hope my answer will help you, for any further concerns, kindly let me know in the comment section.


    If the answer is helpful, please click "Yes" and kindly upvote it. If you have extra questions about this answer, please click "Comment".   

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.