Large Scale Exchange Compliance Search

Rachel N 66 Reputation points
2022-07-12T04:36:57.2+00:00

Hello!

I need to remove a phishing email from an Exchange 2019 On-Prem environment of over 10,000 mailboxes. I have tried "Get-Mailbox -Database "..." -ResultSize Unlimited | Search-Mailbox -SearchQuery ..." -DeleteContent -Force", but on our larger databases the it fails as there are too many mailboxes and/or overuses the server resources. I am attempting to use the New-ComplianceSearch, but I think I am running into an issue with the search only returning 1000 results. Does anyone have recommendations on how to clean a single email out of a large number of mailboxes with over 1000 results? I'd love a how-to or even recommendations for a third-party solution.

Thank you!

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,227 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Peter T 326 Reputation points
    2022-07-12T06:31:22.91+00:00

    Hi,

    Please refer to this documentation for the eDiscovery limits: https://learn.microsoft.com/en-us/microsoft-365/compliance/limits-for-content-search?view=o365-worldwide

    The 1000 results you see are the limit of the preview.

    In case you need to review more, you can try the method described here: https://learn.microsoft.com/en-us/exchange/policy-and-compliance/ediscovery/compliance-search?view=exchserver-2019#optional-step-2-verify-the-number-of-source-mailboxes-in-the-compliance-search

    BR,
    P

    0 comments No comments

  2. Aholic Liang-MSFT 13,736 Reputation points Microsoft Vendor
    2022-07-13T03:09:50.427+00:00

    Hi @Rachel N ,
    According to the official documentation , the maximum number of mailboxes that can be searched in a single search is 10,000 in on-prem exchange.

    220175-2022-7-13-1.png

    Moreover ,in this documentation, a compliance search will return a maximum of 500 source mailboxes that contain search results.

    220193-2022-7-13-2.png

    It is suggested that you could try creating two (or more) compliance searches and change the search criteria to reduce the number of mailboxes that contain search . For example, you could specify a date range or refine the keyword query.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments