What is Microsoft Purview eDiscovery?
Electronic discovery, or eDiscovery, is the process of identifying and delivering electronically stored information that you can use as evidence in investigations and legal cases. With Microsoft Purview eDiscovery you identify, review and manage content in Microsoft 365 services to support your investigations. Supported services include Exchange Online, Microsoft Teams, Microsoft 365 Groups, OneDrive, SharePoint and Viva Engage.
You can search mailboxes and sites in the same eDiscovery search and export the results. eDiscovery cases identify, hold and export content. If your organization has an Office 365 E5 or Microsoft 365 E5 subscription, or related E5 add-on subscriptions, you can further manage cases and analyze content using premium eDiscovery features. eDiscovery is part of Microsoft Purview; for an overview of the whole platform, see our page on Microsoft Purview.
Core Features
Search and conditions: KeyQL queries and conditions narrow the scope of a search. Statistics show the number and total size of matching items, the content locations with the most items, and a representative sample.
Holds and case management: An eDiscovery case contains all searches, holds and review sets related to an investigation. Holds secure content from inadvertent or intentional deletion. Case members control who can access the case.
Review sets (premium): A secure, Microsoft-provided Azure Storage location holds copied content that can be searched, filtered, tagged and analyzed.
Analytics (premium): Near duplicate detection groups textually similar documents, email threading identifies the messages that give full context of a thread, and themes assigns topics to documents.
Advanced indexing (premium): Partially indexed content is reindexed automatically during search, review set ingestion or export, rather than in a separate step.
Security Copilot (premium): Helps draft KeyQL queries using natural language and provides contextual summaries of items in a review set.
Typical Use Cases
Legal proceedings: Relevant content is identified, preserved, reviewed and exported.
Internal investigations: Cases escalated from Insider Risk Management receive additional legal review.
Removing high-risk content: Search and delete finds and removes email, Teams chat messages, and Copilot and AI application data across the organization.
Working with external reviewers: Guest user access, in preview, invites external reviewers with the Reviewer role group.
Benefits
- One process across mailboxes, sites, Teams content and Microsoft 365 Groups
- Automatic advanced indexing avoids stale indices and separate reindexing steps
- Analytics reduces review volume through duplicate detection, email threading and themes
- Automatic decryption of protected messages and documents on ingestion
- Role-based permissions and traceable processes with full reporting
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in building eDiscovery processes in Microsoft Purview: permission and role model, case and hold structure, search and export strategy, and integration with Insider Risk Management and your legal workflows.
Contact us for a no-obligation consultation on eDiscovery with Microsoft Purview.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Microsoft Purview eDiscovery?
Electronic discovery, or eDiscovery, is the process of identifying and delivering electronically stored information that you can use as evidence in investigations and legal cases. Microsoft Purview eDiscovery identifies, reviews and manages content in Microsoft 365 services for that purpose. eDiscovery is part of Microsoft Purview; for an overview of the whole platform see our page on [Microsoft Purview](/en/cloud/azure/products/purview/).
Which services are supported?
Microsoft names Exchange Online, Microsoft Teams, Microsoft 365 Groups, OneDrive, SharePoint and Viva Engage. You can search mailboxes and sites in the same eDiscovery search and then export the search results.
What sets premium eDiscovery apart?
Premium eDiscovery adds advanced indexing, review sets, import of external data, support for cloud attachments and SharePoint versions, optical character recognition, conversation threading, decryption, review set filtering, tagging, analytics, computed document metadata, Security Copilot and full reporting, among others. It requires an Office 365 E5 or Microsoft 365 E5 subscription or related E5 add-ons.
What is a review set?
A review set is a secure, Microsoft-provided Azure Storage location in the Microsoft cloud. When you add data, the collected items are copied from their original content location. Review sets provide a static, known set of content that you can search, filter, tag, analyze and assess for relevance using predictive coding models.
What changed compared with earlier eDiscovery versions?
Microsoft names several changes: advanced indexing now runs automatically instead of as a separate reindexing step, statistics in searches replace the earlier collections and searches are no longer immutable, content search is included in eDiscovery, the case rather than custodians is the central organizing unit, the export flow is unified, and jobs are now referred to as processes.
Can insider risk cases be moved into eDiscovery?
Yes. In Microsoft Purview Insider Risk Management you can escalate cases to new cases in eDiscovery when additional legal review of potentially risky user activity is needed.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
