M365 email archiving is the thing most UK businesses believe they have and very few have configured. The belief usually comes from a reasonable source — Microsoft 365 keeps deleted items for a while, there is something called an archive mailbox, and the administrator once mentioned retention. The discovery that it was not enough usually comes from a less comfortable one: a solicitor’s letter, an employment tribunal claim, a regulator’s information request, or a data subject access request with a one-month clock attached — followed by the realisation that the mailbox that mattered belonged to someone who left fourteen months ago and was deleted thirty days after they went.
This guide covers how preservation and search actually work in Microsoft 365, because the terminology misleads and the defaults do not protect you. It explains the difference between an archive mailbox, a retention policy, a litigation hold and an eDiscovery hold — four things routinely confused for one another — how to design retention so the data exists when a request arrives, the practical difference between the standard eDiscovery tools and the Premium tier, what a compliance search will and will not find, how to handle leavers so their mailboxes survive, and what to do in the first seventy-two hours after the duty to preserve begins so that you are not explaining later why something relevant no longer exists.
One framing note. Preservation obligations in litigation and tribunals are legal duties, and this guide describes how to meet them technically rather than when they arise or what they require in a particular case. Where a dispute is in prospect, the timing and scope of a hold are questions for your solicitor, and the technical steps here are how you carry out their instructions reliably.
How preservation actually works in Microsoft 365
Four mechanisms are regularly treated as the same thing. They are not, and the differences decide whether data survives.
The archive mailbox is a storage tier, not a compliance archive. Exchange Online offers an additional mailbox, with auto-expanding capacity on qualifying plans, into which older items are moved to keep the primary mailbox manageable. It is useful and it does nothing to prevent deletion: a user can delete items from their archive exactly as from their inbox, and when the account is removed the archive goes with it. Having an archive enabled tells you nothing about whether anything is preserved.
Retention policies preserve by rule, organisation-wide, in advance. A retention policy in Microsoft Purview says that content in specified locations — Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams chats and channel messages — must be kept for a defined period, and optionally deleted after it. While the period runs, a user deleting an item removes it from their view and the system keeps a copy out of sight. This is the mechanism that protects you against the request you did not know was coming.
Litigation hold preserves everything in a mailbox, indefinitely or for a set period. Applied to a specific mailbox, it retains all content including items the user deletes or edits, until the hold is removed. It is blunt, complete and mailbox-scoped, and it is the traditional response to a named individual becoming relevant to a dispute.
An eDiscovery hold preserves content within a case, optionally by query. Created inside an eDiscovery case, it can cover mailboxes, sites and Teams locations for specified custodians and can be narrowed by keywords or dates. It is tied to the matter, which makes it auditable and easier to release cleanly when the matter closes.
And separately from all four: backup is a different thing again. Third-party Microsoft 365 backup protects against loss, corruption and malicious deletion, and can be invaluable. It is not usually designed to be your preservation mechanism for disclosure, and relying on it as one tends to produce gaps in what can be demonstrated about the integrity and completeness of what you hold — a distinction set out more fully in our guide to backup retention policy.
The single most important practical consequence follows from the first point. Many organisations have archive mailboxes enabled, assume that equals archiving, and have no retention policy at all. Their data is exactly as deletable as if the archive did not exist.
Answer one question before anything else: if an employee who left eighteen months ago were named in a tribunal claim tomorrow, could you produce their email? Check by looking at what happens to mailboxes when accounts are deleted in your tenant. If no retention policy or hold covers departing users, the mailbox was permanently removed roughly thirty days after the account was deleted, and nothing in Microsoft 365 can bring it back. That single test tells you more about your preparedness than any configuration review, and in most UK SMEs we work with the answer is no.
Email preservation in UK businesses — the numbers
The figures below reflect what we find reviewing Microsoft 365 tenants for UK organisations of 20 to 500 staff, usually at the point a request has arrived or a compliance review has been commissioned.
The first and last figures together describe the commonest unrecoverable loss. When a user account is deleted, the mailbox enters a soft-deleted state and can be restored for about thirty days. After that it is gone — unless a retention policy or hold applied to it before deletion, in which case it becomes an inactive mailbox, preserved indefinitely or for the retention period, without needing a licence. That mechanism exists in every tenant and is used by fewer than one organisation in five, which means most leavers’ email disappears on a schedule nobody chose.
The second figure is the one that should prompt action. Roughly a quarter of tenants have any retention policy over mailboxes. The remainder are relying on users not deleting things, which is not a preservation strategy, and on the deleted items retention window, which is measured in days.
The third figure explains why eDiscovery is not only a litigation concern. Data subject access requests are by some distance the most common reason UK SMEs need to search their own mail, they arrive without warning, they frequently arise from an employment dispute, and the clock does not wait while somebody works out how to run a search across forty mailboxes. Being able to search competently is a routine operational need rather than a contingency.
Retention configured in advance against a hold placed reactively
The comparison below highlights advance configuration, and the qualification is narrow: reactive holds are not wrong — they are the correct response once a matter is identified and they will always be needed. The point is that a reactive hold can only preserve what still exists on the day it is placed, and in the typical tenant a substantial amount has already gone by then.
Reactive hold only
Preserve once a matter is known
Retention configured in advance
Preserve by rule, hold by matter
The spoliation row is the commercial heart of the comparison. If litigation is reasonably in contemplation and relevant documents are lost after that point, courts and tribunals can draw inferences against the party that lost them and can reflect it in costs. An organisation whose routine processes deleted a key custodian’s mailbox weeks after a dispute surfaced is in a materially worse position than one that can show a documented retention policy was applied consistently throughout. Advance configuration does not remove the duty to place a specific hold; it narrows the gap between when the duty arose and when the hold was placed to approximately nothing.
Note the tension retention creates with data minimisation, because it is real. UK GDPR requires that personal data is kept no longer than necessary, and an indefinite retain-everything policy is difficult to justify. The answer is a defined period with a documented rationale — commonly aligned to the six-year limitation period for contract claims for business correspondence — with deletion at the end, rather than either extreme. A retention policy that retains and then deletes is both a preservation control and a minimisation control, which is a more comfortable position than most compliance trade-offs.
Why UK businesses end up searching their own email
The chart below shows the triggers for eDiscovery or compliance searches across UK SMEs we support. The distribution matters because it shows that the routine case — not the dramatic one — is what most organisations need to be ready for.
Nearly half of searches are subject access requests, and that should shape how organisations think about this capability. A DSAR must be answered within one month, extendable by up to two further months only where requests are complex or numerous, and frequently arrives from a current or former employee in dispute with the business. It requires searching across mailboxes, Teams chats, OneDrive and SharePoint for references to an individual, reviewing the results, and redacting third-party information before disclosure. Organisations that only discover how to run a search when the first one arrives lose a week of the month to learning.
The second and third rows are closely related to the first and often arrive together: a grievance becomes a tribunal claim, and somewhere in between a DSAR is used to obtain documents. The practical implication is that the custodian whose email matters most is frequently a current or recent employee, which is why leaver handling and holds on individuals involved in disputes are the two controls that most often decide outcomes.
The security incident row is small and worth noting. Determining which mailboxes a compromised account accessed, or what a phishing email reached, uses the same search capability and often the same audit data. Organisations competent at eDiscovery tend to be faster at incident scoping as a side effect.
Where Microsoft 365 preservation fails
The grid below groups the failure modes we find. The badges reflect how often each causes data to be unavailable when requested, combined with how serious the consequence is.
The third row of the second card catches organisations that are otherwise careful. A common leaver process removes the Microsoft 365 licence on the last day to save cost, then deletes the account later. Removing the licence without a hold or retention policy in place starts a countdown on the mailbox’s data, and the order in which offboarding steps happen determines whether the mailbox can become inactive. Apply the preservation first, confirm it has taken effect, and only then remove the licence and the account.
The Teams row deserves emphasis because so much business communication has moved there. Teams chat and channel messages are stored in the Exchange substrate and can be retained, held and searched — but only if those locations are included in the policy or hold. A retention policy scoped to Exchange email alone will preserve the email about a disputed decision and lose the chat where the decision was actually made.
Exports deserve the attention the final card gives them. An eDiscovery export of a former employee’s mailbox is a large file of personal data about many people. Leaving it on a laptop, emailing it, or retaining it after the matter closes creates a separate data protection exposure, and the export handling process is part of running a search defensibly.
What the capability costs: licensing tiers
Preservation and search capability in Microsoft 365 depends on licence tier, and the dividing lines are not always where people expect. The table below is indicative of UK per-user monthly pricing on annual commitment, excluding VAT, at the time of writing. Microsoft adjusts both prices and feature boundaries periodically, so confirm the current position against your own agreement or licensing partner before relying on it. Our guide to Microsoft 365 plans covers the wider plan differences.
| Licence | Indicative per user per month | Litigation hold | eDiscovery capability |
|---|---|---|---|
| Business Standard | Around £10–11 | Not included by default; available via an archiving add-on | Content search and standard tools |
| Business Premium | Around £17–19 | Included via the bundled archiving capability | Standard eDiscovery with cases and holds |
| Office 365 or Microsoft 365 E3 | Around £20–34 depending on suite | Included | Standard eDiscovery with cases and holds |
| Microsoft 365 E5 | Around £48–55 | Included | Premium eDiscovery: custodians, review sets, analytics |
| Compliance or eDiscovery add-on for E3 users | Around £6–10 per user | Already included in base | Adds Premium eDiscovery for licensed users |
The first row is where the most consequential gap sits. Business Standard is a very common plan in UK SMEs, and on its own it does not include litigation hold. An organisation on Business Standard that receives a solicitor’s letter asking it to preserve a named employee’s email may find that the obvious mechanism is not available without adding a licence — which is quick to fix and unhelpful to discover on the day. Retention policies are a separate matter and broadly available; the point is to establish which preservation mechanisms your tenant actually has before you need one.
The Premium tier is worth paying for in specific circumstances rather than generally. Its value lies in handling volume: identifying custodians, collecting into review sets, removing near-duplicates, threading conversations, and applying analytics so that a reviewer reads thousands of items rather than hundreds of thousands. For an SME handling a handful of DSARs and the occasional tribunal a year, standard capability is usually adequate. For organisations in regulated sectors, or those facing commercial litigation with large disclosure obligations, the time saved in review — frequently charged by the hour by external lawyers — can exceed the licence cost quickly.
Note also that Premium capability is commonly licensed per user whose content is in scope rather than across the whole tenant. Adding it for the subset of staff likely to be custodians, rather than everyone, is often the economical route.
Standard and Premium eDiscovery in practice
Microsoft’s naming has shifted over time — what was called Core eDiscovery became Standard, and the tools have been consolidated into a unified eDiscovery experience in the Purview portal. The labels matter less than the capability line between standard features and Premium ones, which has remained broadly consistent. The table below summarises that line.
| Capability | Standard | Premium |
|---|---|---|
| Cases, searches and case-scoped holds | Yes | Yes |
| Search across mailboxes, sites, OneDrive and Teams | Yes | Yes |
| Export of search results | Yes | Yes, with richer processing |
| Custodian management and notifications | No | Yes |
| Review sets with tagging and annotation | Limited | Yes |
| Near-duplicate detection and email threading | No | Yes |
| Predictive coding and relevance analytics | No | Yes |
The practical test is review volume. If a typical request produces a few thousand items that someone can reasonably read, standard tools are sufficient and the work is mostly in constructing a defensible search. If requests produce tens of thousands of items and external review is being paid for, the Premium features that collapse duplicates and thread conversations reduce the volume a person has to look at, and that is where the cost is.
Custodian management is the Premium feature most relevant to smaller organisations with recurring disputes. It lets you formally identify the people whose content is relevant, place holds on all their locations at once, and issue hold notifications so custodians are told not to delete material — a record of having done so is useful evidence that preservation was taken seriously.
Preservation readiness — where most UK tenants sit
Combining the assessment areas gives an indication of how well an organisation could respond to a disclosure obligation or subject access request arriving tomorrow. The gauge reflects a first review of a UK business of 20 to 500 staff using Microsoft 365 with no compliance configuration applied.
A score around twenty-nine reflects a specific pattern. The capability exists in the tenant — search tools are present, holds are usually available on the plan, and Purview is waiting to be configured. Configuration scores close to zero: no retention policies, no inactive mailboxes, Teams outside any scope. Process scores low because no offboarding step preserves mailboxes and no trigger exists to place a hold. And capability scores low because nobody has run a search under pressure before.
The distinctive feature here is how much of the gap is permanent once lost. Every other benchmark in this series can be improved after the fact. This one cannot: a mailbox that was deleted unprotected last year is not recoverable by any configuration made today. That asymmetry is the case for acting before a request arrives rather than in response to one, and it is why the timeline below begins with configuration rather than with the request.
What a compliance search will and will not find
A search can only return what is indexed, held and in scope, and each of those has edges worth knowing before you certify that a search was complete.
Partially indexed items
Some content cannot be fully indexed: encrypted items, attachments in unsupported formats, very large files, certain image-based documents without text, and items exceeding indexing limits. Searches report these separately as partially indexed or unindexed items. They are not automatically excluded from relevance, and a defensible search reviews the count and decides how to handle them — often by including all unindexed items from relevant custodians in the export for manual review. Ignoring the unindexed report is one of the commonest ways a search is quietly incomplete.
Locations people forget
Shared mailboxes, group mailboxes behind Microsoft 365 Groups and Teams, OneDrive accounts of the custodians, the SharePoint sites they worked in, and Teams chats are all separate locations and must be included deliberately. A search across a custodian’s mailbox alone will miss the files they shared, the team channels they posted in and, frequently, the chat where the substantive conversation happened.
Query construction
Keyword queries are literal in ways that trip people up. Variant spellings, nicknames, initials, email aliases, and the difference between a name appearing in a body and in an address field all affect results. Build queries iteratively, test them against known documents, record every version and its hit count, and keep the final query — because a search you cannot reproduce is a search you cannot defend if it is later questioned.
What is simply not there
Items deleted and purged before any retention or hold applied, mailboxes permanently removed after deletion, and content held only on personal devices or in services outside the tenant will not appear. Being clear about that boundary — and recording it — is part of a competent response, and it is better stated by you than discovered by the other side.
From configuration to a defensible response
The sequence below has two halves. The first is preparation, done once, before any request. The second is what happens when the duty to preserve is triggered, and it is written so that the first seventy-two hours run from a checklist rather than from improvisation.
The broad-then-narrow principle in the first trigger step is the one most often reversed. The instinct is to hold only what seems obviously relevant, which feels proportionate and is the wrong way round at the outset. Over-preservation for a few weeks while scope is clarified costs storage; under-preservation that misses a custodian or a location costs the evidence, and the second cannot be corrected later.
Rehearsal is the preparation step most likely to be skipped and most valuable when it happens. Organisations that have run one mock search respond to their first real request in days; those that have not typically lose the first week of a one-month subject access window working out permissions, locations and export mechanics.
Benchmarks — preservation practice against what we find
The figures below show how often each practice is in place across UK organisations of 20 to 500 staff using Microsoft 365, at first review.
Adoption of email preservation practices in UK businesses
The first two rows side by side are the whole misunderstanding in two numbers. Sixty-one per cent have archive mailboxes; twenty-seven per cent have retention. A large share of organisations therefore believe they are archiving when they are only tiering storage, and they will discover the difference when something they expected to find has been deleted by a user or removed with an account.
The Teams figure at fifteen per cent is the one most likely to matter in a dispute about a decision, because decisions increasingly happen in chat. Organisations that extended retention to email when they adopted Microsoft 365 and never revisited it after Teams became the main channel have preserved the formal record and lost the informal one, which is frequently where the relevant material is.
The bottom rows are inexpensive and almost universally absent. A one-page hold procedure, a rehearsed search and an export disposal record are an afternoon each, and together they are the difference between a response that can be explained and defended and one that cannot.
The number that decides whether a leaver’s email still exists
If one figure predicts whether an organisation will be able to produce what a tribunal or a subject access request requires, it is the proportion of departed employees whose mailboxes were preserved rather than deleted.
Eighteen per cent means the email of most departed staff in most UK businesses is permanently deleted about a month after their account is removed. That would matter less if disputes only ever concerned current employees, but a disproportionate share of them concern people who have left — a tribunal claim follows a departure, a commercial dispute turns on what a former account manager agreed, a subject access request comes from a former employee asking for everything mentioning them.
The mechanism to fix it is already in the tenant and costs nothing in licences. If a retention policy or hold covers a mailbox before the account is deleted, the mailbox becomes inactive: preserved, searchable, and not requiring a licence. The only change needed is the order of offboarding steps and a retention policy covering mailboxes.
What it cannot do is reach backwards. Mailboxes already permanently deleted are gone, and the honest position for most organisations is that their preservation of departed staff begins on the day they configure it. That is the strongest argument for doing it this week rather than when the first request arrives.
Spoliation, disclosure duties and subject access requests
The legal frame is worth understanding in outline, while recognising that its application to any particular situation is a matter for your solicitor.
When the duty to preserve begins
In civil litigation in England and Wales, the obligation to preserve documents that may be relevant arises once litigation is reasonably in contemplation — which can be well before any claim is issued. The Civil Procedure Rules and their practice directions treat electronic documents, including email, chat and metadata, as documents for disclosure purposes. Employment tribunals have their own procedures and can order disclosure of relevant documents. In both settings the practical point is the same: the duty frequently arises earlier than people expect, and routine deletion after it arises can be damaging.
What spoliation costs
Where relevant material is lost after the duty arose, courts and tribunals can draw adverse inferences — essentially, assuming the missing material would have been unhelpful to the party that lost it — and can reflect the conduct in costs. The strength of your position depends heavily on whether you can show a consistent, documented approach to retention and a prompt hold once the matter surfaced. A documented retention policy applied consistently is a very different story from an account deleted in the ordinary course a fortnight after a grievance was raised.
Subject access requests
Under UK data protection law, individuals can request their personal data and organisations must normally respond within one month, extendable by up to two further months where requests are complex or numerous. A request must be met with a reasonable and proportionate search; exemptions and redaction of third-party data apply. The ICO publishes detailed guidance on handling requests. In practice, a subject access request is the most common reason a UK SME needs eDiscovery capability, and the combination of a fixed deadline and an adversarial requester makes advance preparation especially valuable.
One point connects all three. Retention configured in advance, holds placed promptly, searches documented and reproducible, and exports handled securely are simultaneously the controls that protect against spoliation, the controls that make subject access responses competent, and the controls that support data minimisation. Organisations that do this work once find it serves several obligations rather than one.
Where preservation quietly breaks: migrations, recovery and edge cases
Four situations account for most of the preservation gaps we find in tenants that otherwise have retention configured. None of them is obvious until it matters.
Migrations
Retention policies and holds are properties of the tenant they were set in. They do not travel with the data. When an organisation moves from Google Workspace, from an older hosted Exchange service, or between Microsoft 365 tenants after an acquisition, the migrated mailboxes arrive with no preservation applied until it is configured in the destination — and items users deleted in the source before migration are typically not migrated at all. Two practical rules follow. Configure retention in the destination before migrating rather than afterwards, so content is preserved from the moment it lands. And where a matter is live or reasonably anticipated at the time of migration, take legal advice about preserving the source system before it is decommissioned, because switching off the old platform may be the moment relevant material is lost. Our guide to migrating from Google Workspace to Microsoft 365 covers the wider migration sequence.
Recovering deleted items is not the same as preserving them
Microsoft 365 provides recovery for recently deleted items through the Recoverable Items folder, and administrators can often restore mail a user removed in error. That window is short and is designed for mistakes rather than for evidence. It is useful to know — we cover the mechanics in our guide to recovering deleted emails in Microsoft 365 — but it should never be described as a preservation capability, and a response that relies on it will be incomplete for anything older than the recovery period.
Shared and group mailboxes
Shared mailboxes — accounts@, sales@, the generic addresses many SMEs run on — and the group mailboxes behind Microsoft 365 Groups and Teams are frequently where customer correspondence actually lives. Retention policies scoped to named users miss them, and they are often absent from leavers’ processes because no one person owns them. Include them explicitly in retention scope and in any hold where the subject matter touches them.
Preserved content is still discoverable content
Retention and holds keep content out of users’ sight, but tools with broad search reach — including AI assistants that draw on what a user has permission to see — operate on whatever the permission model exposes. Preservation is not a reason to tolerate oversharing, and a tenant that retains everything while granting broad access has made both its disclosure exercises and its everyday exposure larger than they need to be. The interaction between permissions and AI tooling is covered in our guide to Microsoft 365 Copilot data security.
Sector context also shifts the baseline. Regulated firms and professional services with formal record-keeping duties generally need longer and more granular retention than a general commercial business, and more frequent eDiscovery — we look at that in our guide to Microsoft 365 for legal firms. The principles here apply unchanged; the periods and the frequency of use differ.
What this looks like in practice
A UK recruitment business with 65 staff ran Microsoft 365 Business Standard. Archive mailboxes had been enabled during migration from an older hosted Exchange service, and the internal view was that email was archived. There were no Purview retention policies. The offboarding process removed licences on an employee’s last day to save cost and deleted accounts at the end of the month.
A senior consultant left after a dispute about commission and, about four months later, lodged an employment tribunal claim alleging that commission had been unlawfully withheld and that she had been treated unfavourably in the period before her departure. Shortly before the claim, her solicitor submitted a subject access request on her behalf.
The business’s own case relied on email exchanges between the consultant and her manager setting out the commission arrangement, and on Teams messages in which, according to the manager, she had accepted a revised structure. Her mailbox had been permanently deleted roughly three months earlier — her licence was removed on her final day, the account deleted at month end, and nothing preserved it. Her manager’s mailbox still existed, but he had cleared his Teams chat history and periodically deleted email to stay within his mailbox quota. The archive mailbox held some of his older mail; it did not hold the deleted items, because nothing prevented their deletion.
Some of the correspondence was recovered from the manager’s sent items and from attachments forwarded to the finance team. The Teams exchange in which the revised structure was said to have been accepted could not be found at all. The business’s solicitor advised that, without the documents, it would be difficult to establish the agreed arrangement, and that the deletion of the claimant’s mailbox after a commission dispute had already surfaced internally was unlikely to be viewed favourably. The claim was settled.
The remediation took about two weeks. Exchange Online Archiving was added to the Business Standard licences so litigation hold was available. A retention policy was applied across Exchange mailboxes, Teams chats and channel messages, and OneDrive, for six years with deletion afterwards. The offboarding process was reordered so that preservation is confirmed before the licence is removed, which with the retention policy in place means every leaver’s mailbox now becomes inactive automatically. Two people were given eDiscovery roles, and a mock subject access search was run against a volunteer to establish how long the process actually took.
We genuinely thought the archive meant everything was kept. It was in the migration notes and nobody questioned it. The part I still think about is that the fix took two weeks and cost a few pounds per person per month, and the documents that would have answered the claim were gone because we removed a licence on a Friday to save money.
Two points generalise. The first is the archive misunderstanding, which is extremely common and costs nothing to correct once noticed — an archive mailbox is storage, and only retention or a hold stops deletion. The second is timing: the dispute about commission had surfaced internally before the consultant left, which is a strong indication that preservation should have been considered then, and the routine offboarding process removed the evidence weeks after that point. A hold procedure triggered by an internal grievance, not only by a formal letter, would have changed the outcome.
The 12-point M365 preservation checklist
Items one to five configure preservation before any request. Items six to nine handle the trigger. Items ten to twelve keep the capability working.
- Confirm which preservation mechanisms your licences include. Particularly whether litigation hold is available on your plan, and add the archiving capability where it is not.
- Apply a retention policy across Exchange, Teams chats and channels, OneDrive and SharePoint. For a defined period with a written rationale, retaining then deleting rather than retaining forever.
- Stop treating the archive mailbox as an archive. It is a storage tier. Only retention policies and holds prevent deletion.
- Reorder the leavers process so preservation precedes licence removal. With retention covering mailboxes, deleted leavers become inactive mailboxes automatically and need no licence.
- Assign eDiscovery roles to two named people. So the capability does not depend on one administrator, and so the people who will run searches have actually got the permissions.
- Write a one-page hold procedure with a trigger that includes internal disputes. A grievance, a disciplinary, a complaint or a solicitor’s letter — not only a formal claim.
- On a trigger, hold broadly first and narrow later. All locations for every plausible custodian, recorded with times. Over-preservation is correctable; under-preservation is not.
- Suspend routine deletion for relevant custodians. Check whether any retention period or offboarding step would remove relevant content and override it until the matter closes.
- Document every search. Every query version, hit count, location set and the unindexed items decision, so the search can be reproduced and defended.
- Rehearse a subject access search before the first real one. End to end, timed, so that the first week of a one-month deadline is not spent learning the mechanics.
- Handle exports as sensitive data. Encrypted storage, restricted access, a record of where copies exist, and secure deletion when the matter ends.
- Release holds deliberately when matters close. On your solicitor’s confirmation, with a record. Indefinite holds become a retention liability of their own.
If only three items are completed, make them two, four and six. A retention policy across mailboxes and Teams is what makes content exist when a request arrives. Reordering the leavers process is what preserves the custodians who are most often relevant and most often lost. And a hold procedure that triggers on internal disputes, not only formal letters, closes the gap between when the duty to preserve begins and when someone acts on it — which is where most spoliation risk actually lives.
Common mistakes with M365 retention and eDiscovery
The errors below recur across UK tenants. Most come from the terminology suggesting a protection that the default configuration does not provide.
- Treating the archive mailbox as compliance archiving. It moves older items to additional storage and does nothing to stop deletion. Sixty-one per cent have archives; twenty-seven per cent have retention.
- Removing licences from leavers before preserving the mailbox. The order of offboarding steps decides whether a mailbox becomes inactive or disappears permanently about a month later.
- Assuming every plan includes litigation hold. Business Standard on its own does not. Discovering this on receiving a preservation letter is avoidable.
- Leaving Teams outside retention scope. Decisions increasingly happen in chat. Retention that covers email alone preserves the formal record and loses the informal one.
- Waiting for a formal claim before placing a hold. The duty to preserve can arise once litigation is reasonably in contemplation, which may be at an internal grievance rather than a solicitor’s letter.
- Holding narrowly at the outset. Missing a custodian or a location cannot be corrected later. Hold broadly first and refine once scope is clear.
- Ignoring partially indexed items. Encrypted items, unsupported attachments and very large files are reported separately and are not automatically irrelevant. Review the count and decide.
- Running searches nobody can reproduce. Undocumented queries cannot be defended if challenged. Record every version and its hit count.
- Retaining everything forever. Indefinite retention is difficult to justify under data minimisation and enlarges every future disclosure exercise. Retain for a defined period, then delete.
- Leaving exports lying around. An eDiscovery export is a concentrated store of personal data about many people. Treat its handling and deletion as part of the search.
Be careful about relying on third-party Microsoft 365 backup as your preservation mechanism for disclosure. Backup is valuable protection against loss and malicious deletion, and in an emergency it may help recover material. But it is usually designed around restore points rather than around demonstrable, continuous, unaltered preservation, and it may not capture items a user deleted between snapshots. When the question is whether you preserved relevant material from the point the duty arose, a documented Purview retention policy or hold is a far easier thing to explain than a collection of backups — and the two serve different purposes that are worth keeping distinct.
At a glance — M365 archiving and eDiscovery summary
| Question | Short answer |
|---|---|
| Does an archive mailbox preserve email? | No. It is a storage tier. Users can still delete from it and it goes with the account. |
| What actually prevents deletion? | A Purview retention policy, a litigation hold on a mailbox, or an eDiscovery hold within a case |
| What happens to a leaver’s mailbox? | Without preservation, it is permanently unrecoverable about 30 days after account deletion. With it, it becomes an inactive mailbox needing no licence. |
| Order of offboarding steps | Preserve first, confirm, then remove the licence and delete the account |
| Does every plan include litigation hold? | No. Business Standard on its own does not; an archiving add-on or higher plan provides it. |
| Standard or Premium eDiscovery? | Standard for most SMEs. Premium where review volume is large — custodians, review sets, threading, near-duplicates, analytics. |
| Which locations to include | Mailboxes, Teams chats and channels, OneDrive, SharePoint sites, shared and group mailboxes |
| Commonest search gap | Partially indexed items left unreviewed, and Teams or OneDrive left out of scope |
| Commonest reason for searching | Data subject access requests, at around 46 per cent, with a one-month response window |
| When does the duty to preserve begin? | Once litigation is reasonably in contemplation, which can be well before any claim is issued — take legal advice on timing |
| Spoliation consequence | Adverse inferences and costs consequences where relevant material is lost after the duty arose |
| How long to retain | A defined period with a documented rationale, commonly aligned to the six-year limitation period for business correspondence, then delete |
| Holding broadly or narrowly? | Broadly at first; refine once scope is clear. Under-preservation cannot be undone. |
| Is backup a substitute? | Not usually for disclosure. It protects against loss; retention and holds demonstrate preservation. |
| Can deleted mailboxes be recovered later? | Not after permanent deletion. Preservation starts on the day you configure it, which is the case for doing it now. |
How Cloudswitched approaches M365 preservation
Cloudswitched configures and manages Microsoft 365 for UK organisations, and compliance configuration is part of a sound tenant rather than an optional extra. In practice that means confirming which preservation mechanisms your licences include and filling the gaps, designing retention policies across mailboxes, Teams, OneDrive and SharePoint with a documented period and rationale, reordering offboarding so every leaver’s mailbox is preserved as an inactive mailbox, assigning eDiscovery roles and rehearsing a subject access search, and writing the hold procedure your team follows when a dispute surfaces. We work alongside your solicitors rather than in place of them: they decide what must be preserved and when, and we make sure it actually is.
Find out whether your email will exist when you need it
We check what your tenant actually preserves, what happens to leavers’ mailboxes, and whether you could answer a subject access request within the month — then configure what is missing.
Talk to a Cloud Email SpecialistFrequently Asked Questions
Does Microsoft 365 automatically archive all email?
No. Microsoft 365 keeps deleted items for a short recovery window and offers an archive mailbox, but neither preserves email against deletion in a compliance sense. The archive mailbox is additional storage into which older items are moved; users can delete from it and it is removed with the account. Content is only preserved against deletion when a Purview retention policy, a litigation hold or an eDiscovery hold applies. Around 61 per cent of UK tenants we review have archive mailboxes enabled and only about 27 per cent have a retention policy covering mailboxes, which is the gap behind most unpleasant surprises.
What is the difference between litigation hold and a retention policy?
A retention policy preserves content by rule across the organisation, in advance, for a defined period — protecting you against requests you did not know were coming. Litigation hold preserves everything in a specific mailbox, including items the user deletes or edits, indefinitely or for a set period, and is the traditional response to a named individual becoming relevant to a dispute. An eDiscovery hold is similar but created within a case, can span mailboxes, sites and Teams for multiple custodians, and can be narrowed by query. Most organisations need a retention policy as the baseline and holds for specific matters.
What happens to a mailbox when an employee leaves?
If the account is deleted without any retention policy or hold applying to the mailbox, it can be restored for about thirty days and is then permanently unrecoverable. If a retention policy or hold covered the mailbox before deletion, it becomes an inactive mailbox: preserved, searchable through eDiscovery, and not requiring a licence. The order of offboarding steps matters — apply preservation and confirm it before removing the licence and deleting the account. Only about 18 per cent of UK organisations we review preserve leavers this way.
Do all Microsoft 365 plans include litigation hold?
No, and the gap is in a very common plan. Business Standard on its own does not include litigation hold; it can be added through an Exchange Online archiving add-on, and it is included in Business Premium and the enterprise E3 and E5 plans at the time of writing. Microsoft adjusts licensing boundaries periodically, so confirm against your current agreement. The practical advice is to establish which preservation mechanisms your tenant actually has before a solicitor’s letter asks you to use one.
Do we need Premium eDiscovery?
Usually not, for a typical UK SME. Standard eDiscovery provides cases, searches across mailboxes, sites, OneDrive and Teams, case-scoped holds and exports, which covers most subject access requests and tribunal disclosure. Premium adds custodian management with hold notifications, review sets, near-duplicate detection, email threading and relevance analytics — features that earn their cost when a matter produces tens of thousands of items and review time is being paid for externally. It is commonly licensed per user in scope, so adding it for likely custodians rather than everyone is often the economical route.
Are Teams chats included in eDiscovery and retention?
They can be, but only if Teams locations are included. Teams chat and channel messages are stored in the Exchange substrate and can be retained, held and searched, yet a retention policy or search scoped only to email will not cover them. Only about 15 per cent of tenants we review retain Teams content. Given how much business decision-making now happens in chat, a retention policy that covers email alone often preserves the formal record while losing the conversation where the relevant decision was actually made.
What does a compliance search miss?
Anything not indexed, not in scope, or no longer there. Partially indexed items — encrypted content, unsupported attachment formats, very large files — are reported separately and should be reviewed rather than assumed irrelevant. Locations must be included deliberately: shared and group mailboxes, custodians’ OneDrive accounts, the SharePoint sites they used and Teams. Keyword queries are literal, so variants, nicknames and aliases matter. And content purged before any preservation applied, or mailboxes permanently deleted, will not appear at all. Recording those boundaries is part of a competent search.
When do we have to start preserving documents for a dispute?
In outline, once litigation is reasonably in contemplation, which can be considerably earlier than a formal claim — an internal grievance, a complaint or a dispute about terms may be enough in some circumstances. The timing and scope in any particular case is a question for your solicitor. The technical lesson is that a hold procedure triggered only by a solicitor’s letter often acts too late, and that routine offboarding deletion after a dispute has surfaced internally is one of the commonest ways relevant material is lost.
What is spoliation and why does it matter?
Spoliation is the loss or destruction of relevant evidence after the duty to preserve it has arisen. Courts and tribunals can respond by drawing adverse inferences — in effect assuming the missing material would not have helped the party that lost it — and by reflecting the conduct in costs. How seriously it is viewed depends heavily on circumstances, and a documented retention policy applied consistently together with a prompt hold once a matter surfaced is a far stronger position than an account deleted in the ordinary course shortly after a dispute arose.
How should we handle a data subject access request in Microsoft 365?
Respond within one month, extendable by up to two further months only where requests are complex or numerous. Search across the requester’s own mailbox and others where they are mentioned, Teams chats and channels, OneDrive and relevant SharePoint sites, using queries that cover their name variants and email addresses. Review the unindexed items, review results for relevance, apply any exemptions, and redact third-party personal data before disclosure. The ICO publishes detailed guidance. Rehearsing a search before the first real request saves the week most organisations otherwise lose working out the mechanics.
How long should we retain email?
For a defined period with a documented rationale, then delete. UK GDPR requires personal data is kept no longer than necessary, so retain-everything-forever is hard to justify and enlarges every future disclosure exercise. A common approach aligns business correspondence with the six-year limitation period for contract claims, with longer periods only where specific obligations require them. A retention policy that retains and then deletes serves both preservation and data minimisation, which is a more comfortable position than most compliance trade-offs.
Can third-party backup replace retention policies for legal hold?
Not usually, though it remains valuable. Backup protects against loss, corruption and malicious deletion and may help recover material in an emergency. But it is generally organised around restore points rather than continuous, demonstrable preservation, and it may not capture items deleted between snapshots. When the question is whether relevant material was preserved from the point the duty arose, a documented Purview retention policy or hold is considerably easier to explain and defend. Keep the two distinct: backup for recovery, retention and holds for preservation.
Related reading
More guidance on securing, governing and managing UK business IT:
- Cyber Essentials and insurance: how certification affects premiums
- Network documentation: building a map that actually gets used
- Virtual CIO versus IT consultant: understanding the difference
- VoIP security: preventing toll fraud and call interception
- AI agent reliability: testing autonomous workflows
Preservation starts the day you configure it
Cloudswitched sets up retention across mailboxes, Teams, OneDrive and SharePoint, preserves every leaver as an inactive mailbox, and rehearses the search — so when a request arrives, the data exists and the response is defensible.
Talk to a Cloud Email Specialist