How long email 365 is preserved, retention policy, eDiscovery and Archive relationship.

Rusydan (Dan) 141 Reputation points
2022-01-10T10:09:41.533+00:00

Hi,

I have been attempting to corelate the items above in regards to Microsoft 365 email and compliance policy.

First and foremost, by default, without archive enabled, how long does email lived in a mailbox if we dont delete it?

Next, lets say a user account (archive disabled) who have been deleted or his subscription revoked, will the mail content which transit to and from his mailbox, be searchable from content search or eDiscovery?

Finally, does retention policy only works when archived is enabled to a user? if archived is not enabled, what ever retention policy will not be process (including the default MDM policy). is this true?

I received this question from our customer who plans to retain their user account mailbox history up to 7 years, regardless that the user account has been deleted (due to resignation for example). But they plan to use it in a covert fashion, i.e the user is not aware that their email is being kept. Also in terms of use case, eDiscovery fits for uses in legal issues, but to retain email in its true sense, a backup (like veeam) is much more suitable. Is this a correct assumption?

Appreciate for your feedback.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,669 questions
0 comments No comments
{count} votes

Accepted answer
  1. Kael Yao-MSFT 37,651 Reputation points Microsoft Vendor
    2022-01-11T02:40:06.553+00:00

    Hi @Rusydan (Dan)

    by default, without archive enabled, how long does email lived in a mailbox if we dont delete it?

    When a new mailbox is created, the default MRM policy would be automatically applied to it.

    Below is a list of the default retention tags in the default MRM policy:
    163771-50.png

    • Default policy tag (DPT): Automatically to entire mailbox A DPT applies to untagged items, which are mailbox items that don't have a retention tag applied directly or by inheritance from the folder.
    • Retention policy tag (RPT): Automatically to a default folder Default folders are folders created automatically in all mailboxes, for example: Inbox, Deleted Items, and Sent Items.
    • Personal tag: Manually to items and folders Users can automate tagging by using Inbox rules to either move a message to a folder that has a particular tag or to apply a personal tag to the message.

    The default DPT in the default MRM policy would move items which are 2 years old to archive mailbox.
    Since the mailbox doesn't have archive enabled, it would have no effect and the items would remain in the primary mailbox as long as you don't delete them.

    If you enable archive for the mailbox, items which reach two years old would be moved to archive mailbox.


    lets say a user account (archive disabled) who have been deleted or his subscription revoked, will the mail content which transit to and from his mailbox, be searchable from content search or eDiscovery?

    If you deleted a user account or remove the license from the account, the mailbox data would be retained for 30 days.
    During this period, you can still recover the mailbox data by undeleting the account.
    After 30 days, the data is permanently removed.

    Meanwhile, contents in the mailbox would become unsearchable from content search or eDiscovery.
    Please refer to this link: Searching disconnected or de-licensed mailboxes

    However, if you would like to keep the data, you may also consider applying hold on the mailbox to convert it to an inactive mailbox before you remove the user account.
    More details are introduced in these links:
    Learn about inactive mailboxes
    Create and manage inactive mailboxes


    does retention policy only works when archived is enabled to a user? if archived is not enabled, what ever retention policy will not be process (including the default MDM policy). is this true?

    No.
    MRM (retention policy) has two actions, move to archive and delete.

    If you have a custom retention policy or modified the default one,
    for example, you add a DPT which would permanently delete items which are 1 year old,
    it would still work on mailboxes which have this retention policy assigned even if these mailboxes don't have archive enabled.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.