Aug. 1, 2026

Microsoft Purview eDiscovery — Simply Explained

Microsoft Purview eDiscovery — Simply Explained
Microsoft Purview eDiscovery — Simply Explained
M365 FM Podcast
Microsoft Purview eDiscovery — Simply Explained

What happens when a regulator requests company records, HR launches an investigation, or legal teams need to preserve critical evidence? Searching through Outlook mailboxes, Teams chats, SharePoint sites, and OneDrive folders manually is slow, error-prone, and often impossible at enterprise scale. In this episode of Microsoft Knowledge Nuggets on M365.fm, Mirko Peters explains Microsoft Purview eDiscovery in plain English. You'll learn how organizations can securely discover, preserve, review, and export Microsoft 365 data using a structured, case-based process that supports legal investigations, compliance requests, internal audits, HR matters, and security incidents. Whether you're an IT administrator, Microsoft 365 consultant, compliance officer, security professional, or simply preparing for Microsoft certifications, this episode provides a practical introduction to one of the most important Microsoft Purview capabilities.

WHY eDISCOVERY MATTERS IN MICROSOFT 365
Modern work is scattered across multiple Microsoft services. Business conversations no longer live only in Outlook. Critical evidence may be spread across:

  • Exchange Online emails
  • Microsoft Teams chats and meetings
  • SharePoint Online document libraries
  • OneDrive for Business
  • Microsoft 365 Groups
  • Viva Engage conversations
During an investigation, missing even one location can result in incomplete evidence. Microsoft Purview eDiscovery provides a centralized process that helps organizations collect the right information while maintaining security, privacy, and governance. Instead of searching every mailbox and document library, organizations create structured cases that define exactly what should be searched and who may access the results.

HOW MICROSOFT PURVIEW eDISCOVERY WORKS
Rather than acting as a giant search engine, eDiscovery follows a carefully controlled workflow. The process begins by creating a case, which becomes the secure workspace for a specific investigation. Authorized users define the data sources, preserve evidence through Legal Hold when required, execute targeted searches, review the collected results, classify relevant documents, and finally export only the approved evidence. This structured workflow dramatically reduces risk compared to manually searching Microsoft 365 services while providing a clear audit trail for compliance and legal teams.

EXPLORE THE COMPLETE eDISCOVERY WORKFLOW
This episode explains every major component of Microsoft Purview eDiscovery, including:
  • Creating investigation cases
  • Selecting Exchange, Teams, SharePoint and OneDrive data sources
  • Understanding Legal Hold
  • Running targeted searches
  • Using Keyword Query Language (KQL)
  • Reviewing collected evidence
  • Working with Review Sets
  • Applying Tags
  • Exporting evidence securely
  • Managing permissions and access control
  • Understanding Standard vs Premium eDiscovery
Every topic is illustrated using practical business scenarios that demonstrate how investigations typically unfold inside Microsoft 365 environments

LEGAL HOLD EXPLAINED
One of the most misunderstood concepts in Microsoft Purview is Legal Hold. A Legal Hold ensures that potentially relevant information remains preserved even if users delete emails, edit documents, or leave the organization during an active investigation. Unlike traditional retention policies, which enforce normal business record retention, Legal Hold protects data because of a specific legal or compliance matter. This episode explains:
  • when Legal Hold should be used,
  • how it differs from Microsoft 365 retention,
  • why preservation must happen before searching,
  • and why only authorized business stakeholders should decide when a hold is applied or released.
SEARCH SMARTER — NOT WIDER
Many administrators assume that searching the entire Microsoft 365 tenant is the safest option. In reality, enterprise investigations work best when searches remain focused. You'll learn how to:
  • define relevant custodians,
  • limit searches using date ranges,
  • search by sender or recipient,
  • use keywords effectively,
  • understand Keyword Query Language (KQL),
  • analyze search statistics,
  • refine search queries iteratively,
  • and avoid collecting unnecessary personal or business information.
The episode demonstrates why successful investigations begin with focused questions instead of massive searches.

REVIEW, CLASSIFY AND EXPORT EVIDENCE
Finding information is only the beginning. Microsoft Purview eDiscovery enables reviewers to examine search results, determine relevance, classify documents using tags, and prepare evidence for legal or compliance teams. You'll discover:
  • what Review Sets are,
  • how reviewers organize findings,
  • when Premium review capabilities become valuable









<



Become a supporter of this podcast: https://www.spreaker.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365--6704921/support.

🚀 Want to be part of m365.fm?

Then stop just listening… and start showing up.

👉 Connect with me on LinkedIn and let’s make something happen:

  • 🎙️ Be a podcast guest and share your story
  • 🎧 Host your own episode (yes, seriously)
  • 💡 Pitch topics the community actually wants to hear
  • 🌍 Build your personal brand in the Microsoft 365 space

This isn’t just a podcast — it’s a platform for people who take action.

🔥 Most people wait. The best ones don’t.

👉 Connect with me on LinkedIn and send me a message:
"I want in"

Let’s build something awesome 👊

1
00:00:00,000 --> 00:00:04,480
Welcome to another episode of Microsoft Knowledge Nuggets here on M365, FM.

2
00:00:04,480 --> 00:00:05,640
I'm your host, Mirko Peters.

3
00:00:05,640 --> 00:00:08,440
Today's topic is one that almost everyone has heard of,

4
00:00:08,440 --> 00:00:10,960
but most people hope they never actually need to use.

5
00:00:10,960 --> 00:00:11,800
Picture this.

6
00:00:11,800 --> 00:00:14,440
A sensitive email lands in the wrong person's inbox,

7
00:00:14,440 --> 00:00:16,080
or an employee raises a complaint.

8
00:00:16,080 --> 00:00:18,160
Maybe a regulator asks for records,

9
00:00:18,160 --> 00:00:20,840
or someone thinks company data has left the business.

10
00:00:20,840 --> 00:00:22,480
When that happens, people can panic.

11
00:00:22,480 --> 00:00:24,000
Someone wants to delete the email,

12
00:00:24,000 --> 00:00:27,080
another person starts digging through inboxes by hand.

13
00:00:27,080 --> 00:00:29,120
Managers ask employees what they remember,

14
00:00:29,120 --> 00:00:32,080
while files move around and the story gets harder to piece together,

15
00:00:32,080 --> 00:00:35,360
that's exactly the point where Microsoft Perview eDiscovery comes in.

16
00:00:35,360 --> 00:00:37,040
By the end of this knowledge nugget,

17
00:00:37,040 --> 00:00:38,360
you'll understand how to find,

18
00:00:38,360 --> 00:00:42,120
protect, review, and hand over the right Microsoft 365 data

19
00:00:42,120 --> 00:00:44,840
without turning your IT team into a legal team.

20
00:00:44,840 --> 00:00:48,120
In plain English, Microsoft Perview eDiscovery is a case-based tool

21
00:00:48,120 --> 00:00:51,040
for finding, preserving, reviewing, and exporting work data.

22
00:00:51,040 --> 00:00:53,120
Think of Microsoft 365 like an office building,

23
00:00:53,120 --> 00:00:56,040
exchange online, teams, sharepoint, and one drive

24
00:00:56,040 --> 00:00:58,240
are different rooms where people work every day.

25
00:00:58,240 --> 00:01:00,680
Email sit in one room, team files sit in another,

26
00:01:00,680 --> 00:01:02,920
chats and shared documents sit somewhere else.

27
00:01:02,920 --> 00:01:05,920
Perview eDiscovery is like the locked records room in that building

28
00:01:05,920 --> 00:01:07,480
with a search desk outside it.

29
00:01:07,480 --> 00:01:09,840
You don't walk through every room without a plan.

30
00:01:09,840 --> 00:01:11,880
You open a case decide which rooms matter,

31
00:01:11,880 --> 00:01:13,840
protect the records, search for what fits,

32
00:01:13,840 --> 00:01:15,960
and prepare the right items for the people who need them.

33
00:01:15,960 --> 00:01:17,440
Let's break this down step by step.

34
00:01:17,440 --> 00:01:18,760
First, why eDiscovery exists?

35
00:01:18,760 --> 00:01:20,520
Then the case and the data sources,

36
00:01:20,520 --> 00:01:23,960
after that, legal hold, search, review, and export.

37
00:01:23,960 --> 00:01:25,960
We'll start with the reason this exists,

38
00:01:25,960 --> 00:01:29,040
because a search only helps if the data still exists.

39
00:01:29,040 --> 00:01:33,120
Building block one, why eDiscovery exists?

40
00:01:33,120 --> 00:01:36,400
20 years ago, work data often sat in separate places.

41
00:01:36,400 --> 00:01:39,680
Email might live in one archive, files might sit on a file share,

42
00:01:39,680 --> 00:01:42,320
team conversations could happen in another tool.

43
00:01:42,320 --> 00:01:44,360
If someone needed to investigate an issue,

44
00:01:44,360 --> 00:01:48,240
IT would search each place separately, copy items into folders,

45
00:01:48,240 --> 00:01:50,640
and hope the copies included enough context.

46
00:01:50,640 --> 00:01:52,160
That approach creates gaps.

47
00:01:52,160 --> 00:01:54,800
A message might point to a file that nobody collected,

48
00:01:54,800 --> 00:01:57,320
a file may have been changed since the original discussion.

49
00:01:57,320 --> 00:02:00,160
Someone may remember the event differently than the records show.

50
00:02:00,160 --> 00:02:02,840
Work has moved, but the problem hasn't disappeared.

51
00:02:02,840 --> 00:02:05,440
Today, your work may spread across exchange online

52
00:02:05,440 --> 00:02:08,240
for email and calendars, teams for chat and meetings,

53
00:02:08,240 --> 00:02:09,840
SharePoint for team documents,

54
00:02:09,840 --> 00:02:11,760
OneDrive for personal work files,

55
00:02:11,760 --> 00:02:14,280
Microsoft 365 Groups for shared work,

56
00:02:14,280 --> 00:02:16,960
and Viva Engage for community conversations.

57
00:02:16,960 --> 00:02:18,800
One business decision can leave a trail

58
00:02:18,800 --> 00:02:20,440
across several of those places.

59
00:02:20,440 --> 00:02:23,440
That trail matters when your organization receives a legal request,

60
00:02:23,440 --> 00:02:26,160
looks into an HR concern, responds to an audit,

61
00:02:26,160 --> 00:02:27,520
checks an internal report,

62
00:02:27,520 --> 00:02:30,880
or investigates a security incident or possible data exposure.

63
00:02:30,880 --> 00:02:33,880
Imagine a former employee claims they were treated unfairly.

64
00:02:33,880 --> 00:02:37,520
HR and legal may need messages between that employee and their manager.

65
00:02:37,520 --> 00:02:39,400
They may need files from a certain project,

66
00:02:39,400 --> 00:02:41,160
they may need records from a defined period,

67
00:02:41,160 --> 00:02:43,480
not every email and document the company has ever created.

68
00:02:43,480 --> 00:02:46,520
The goal isn't to prove whether anyone did something wrong.

69
00:02:46,520 --> 00:02:49,520
Per view, e-discovery finds and preserves possible evidence.

70
00:02:49,520 --> 00:02:52,640
Legal, HR, compliance, security, and business leaders decide

71
00:02:52,640 --> 00:02:54,440
what the evidence means and what happens next.

72
00:02:54,440 --> 00:02:55,960
It also doesn't replace legal advice.

73
00:02:55,960 --> 00:02:59,120
It gives the right people a controlled way to work with the data they need.

74
00:02:59,120 --> 00:03:02,040
So why not just use normal Microsoft 365 search?

75
00:03:02,040 --> 00:03:03,680
Normal search helps you find your own work.

76
00:03:03,680 --> 00:03:05,040
It's built for day-to-day tasks,

77
00:03:05,040 --> 00:03:06,880
like locating a document from last week

78
00:03:06,880 --> 00:03:08,480
or finding an email from a customer.

79
00:03:08,480 --> 00:03:10,160
An investigation needs more control.

80
00:03:10,160 --> 00:03:12,840
You may need to limit who can see sensitive results.

81
00:03:12,840 --> 00:03:15,080
You need a clear record of the searches that ran.

82
00:03:15,080 --> 00:03:17,920
You may need to preserve content before someone deletes it.

83
00:03:17,920 --> 00:03:21,600
And you need to avoid collecting huge files of unrelated personal or business data

84
00:03:21,600 --> 00:03:23,160
just because a search was too broad.

85
00:03:23,160 --> 00:03:25,280
That's where e-discovery changes the process.

86
00:03:25,280 --> 00:03:28,080
Instead of saying, "Search everything and send me what you find",

87
00:03:28,080 --> 00:03:29,960
the team starts with a defined matter.

88
00:03:29,960 --> 00:03:32,400
They decide what they need to look for, where it may live,

89
00:03:32,400 --> 00:03:33,600
and who should have access.

90
00:03:33,600 --> 00:03:35,360
For you, the practical point is simple.

91
00:03:35,360 --> 00:03:38,320
Learn this process before an urgent request reaches it.

92
00:03:38,320 --> 00:03:40,480
In a real situation, people need fast answers,

93
00:03:40,480 --> 00:03:42,200
but fast doesn't mean careless.

94
00:03:42,200 --> 00:03:45,360
A little preparation helps your organization protect the right data

95
00:03:45,360 --> 00:03:47,160
while keeping the work focused and private.

96
00:03:47,160 --> 00:03:50,880
Every investigation needs a clear home before anyone starts searching.

97
00:03:50,880 --> 00:03:53,600
Building block two, the case and the data sources.

98
00:03:53,600 --> 00:03:55,680
So you have a reason to investigate something.

99
00:03:55,680 --> 00:03:59,040
Before you even type a single search word, you need a case.

100
00:03:59,040 --> 00:04:02,960
Think of a case as a secure digital file box for one specific matter.

101
00:04:02,960 --> 00:04:04,080
It holds everything.

102
00:04:04,080 --> 00:04:06,720
The people involved, the data sources, the searches,

103
00:04:06,720 --> 00:04:09,680
any holds, review work, and exports all in one place.

104
00:04:09,680 --> 00:04:13,520
Imagine a labeled file box, not one that says everything that happened this year.

105
00:04:13,520 --> 00:04:17,920
Instead, employee concern march through June, or project redwood review.

106
00:04:17,920 --> 00:04:21,200
That name matters because it tells everyone what they are working on.

107
00:04:21,200 --> 00:04:24,160
And just as important, what they are not working on.

108
00:04:24,160 --> 00:04:27,120
Cases keep things organized, but they also control access.

109
00:04:27,120 --> 00:04:30,480
Not everyone in IT should be able to open a sensitive HR matter,

110
00:04:30,480 --> 00:04:33,440
and not every HR investigator should see a legal case.

111
00:04:33,440 --> 00:04:37,040
Inside PerView, you assign people to the case based on what they need to do.

112
00:04:37,040 --> 00:04:40,080
A reader can view the case work, a manager can create and run cases,

113
00:04:40,080 --> 00:04:44,080
and administrator handles the wider settings and controls access across eDiscovery.

114
00:04:44,080 --> 00:04:47,120
The exact role names may change when Microsoft updates the service,

115
00:04:47,120 --> 00:04:48,640
but the simple idea stays the same.

116
00:04:48,640 --> 00:04:50,880
Some people need to look, some need to do the work,

117
00:04:50,880 --> 00:04:54,320
and a smaller group decides who gets that access in the first place.

118
00:04:54,320 --> 00:04:56,480
That separation protects the investigation.

119
00:04:56,480 --> 00:04:59,200
It also gives your organization a clearer record of what happened.

120
00:04:59,200 --> 00:05:01,840
You can see which case held the search, who worked on it,

121
00:05:01,840 --> 00:05:04,720
and why those locations were included, when someone asks.

122
00:05:04,720 --> 00:05:07,040
Why did you search these people and not everyone else?

123
00:05:07,040 --> 00:05:09,040
There is a place to explain the decision.

124
00:05:09,040 --> 00:05:10,560
Next, you choose the data sources.

125
00:05:10,560 --> 00:05:13,520
A data source is simply a place where eDiscovery looks for content.

126
00:05:13,520 --> 00:05:17,440
You can add people, groups, sites, or even broader organization locations,

127
00:05:17,440 --> 00:05:19,760
depending on the question you are trying to answer.

128
00:05:19,760 --> 00:05:23,600
To do that well, you need a basic map of where Microsoft 365 stores work.

129
00:05:23,600 --> 00:05:26,000
Business, email, and calendars live in exchange online.

130
00:05:26,000 --> 00:05:28,400
Your personal work files usually live in one drive.

131
00:05:28,400 --> 00:05:30,400
Think of it as your own digital filing cabinet.

132
00:05:30,400 --> 00:05:32,160
Team files usually live in SharePoint.

133
00:05:32,160 --> 00:05:34,480
That includes many files you open through Teams,

134
00:05:34,480 --> 00:05:37,280
even though you may never see the SharePoint site behind the scenes.

135
00:05:37,280 --> 00:05:38,960
Teams itself can confuse people.

136
00:05:38,960 --> 00:05:42,240
A Teams chat is not just sitting inside an app called Teams.

137
00:05:42,240 --> 00:05:46,560
One-to-one and group chat messages actually connect to the participants' exchange online mailboxes,

138
00:05:46,560 --> 00:05:49,680
and files shared in those chats are generally stored in one drive.

139
00:05:49,680 --> 00:05:52,720
So if you search only for email and ignore one drive,

140
00:05:52,720 --> 00:05:55,200
you could miss a file someone sent during a chat.

141
00:05:55,200 --> 00:05:58,240
Imagine HR needs to look into messages between two employees.

142
00:05:58,240 --> 00:06:00,560
You would not begin by searching every mailbox,

143
00:06:00,560 --> 00:06:03,040
every one drive, and every SharePoint site in the company.

144
00:06:03,040 --> 00:06:04,960
You would start with the two employees mailboxes

145
00:06:04,960 --> 00:06:06,480
and their related file locations.

146
00:06:06,480 --> 00:06:08,560
Then you might set a date range around the event

147
00:06:08,560 --> 00:06:10,880
and use the known project or topic as a guide.

148
00:06:10,880 --> 00:06:12,640
That is a focused starting point.

149
00:06:12,640 --> 00:06:15,760
If the results point to a shared project site or a group conversation,

150
00:06:15,760 --> 00:06:17,760
then you can widen the scope with a reason.

151
00:06:17,760 --> 00:06:19,520
You let the evidence guide the next move.

152
00:06:19,520 --> 00:06:22,800
This matters because a wider search does not automatically mean a better search.

153
00:06:22,800 --> 00:06:26,000
A huge result set can bury the few items that matter.

154
00:06:26,000 --> 00:06:29,520
It can also pull in private, unrelated work that nobody needs to review.

155
00:06:29,520 --> 00:06:31,840
More data means more time, more care,

156
00:06:31,840 --> 00:06:34,560
and more chances to lose the thread of the investigation.

157
00:06:34,560 --> 00:06:37,520
So start with known people, known dates, and known places.

158
00:06:37,520 --> 00:06:40,160
Then expand only when the results show you where to look next.

159
00:06:40,160 --> 00:06:44,960
For you, the main lesson is knowing where Microsoft 365 actually stores work data.

160
00:06:44,960 --> 00:06:47,840
Once you understand the map, you are less likely to miss content

161
00:06:47,840 --> 00:06:52,160
and far less likely to create a giant pile of results nobody can sensibly review.

162
00:06:52,160 --> 00:06:55,520
Then once the case points to the right places,

163
00:06:55,520 --> 00:06:57,680
you need to protect the evidence before it changes.

164
00:06:57,680 --> 00:07:02,080
Building block three, legal hold, the pause button for evidence.

165
00:07:02,080 --> 00:07:04,160
A legal hold is a preservation rule.

166
00:07:04,160 --> 00:07:07,040
It keeps relevant content available while a case remains active,

167
00:07:07,040 --> 00:07:09,680
even if someone later tries to delete or change that content.

168
00:07:09,680 --> 00:07:12,160
Think of a filing cabinet with a clear label on one drawer.

169
00:07:12,160 --> 00:07:13,520
Do not destroy.

170
00:07:13,520 --> 00:07:17,280
Someone can still try to throw away a document from that drawer,

171
00:07:17,280 --> 00:07:20,400
but the organization keeps the copy that may matter for the case.

172
00:07:20,400 --> 00:07:21,840
That is the job of a hold.

173
00:07:21,840 --> 00:07:23,520
People clean up inboxes all the time.

174
00:07:23,520 --> 00:07:26,720
They delete chat messages, replace a file with a newer version,

175
00:07:26,720 --> 00:07:30,400
or someone might leave the company and their account moves through an off-boarding process.

176
00:07:30,400 --> 00:07:33,280
None of those actions automatically mean somebody did something wrong.

177
00:07:33,280 --> 00:07:35,680
But once a matter needs preservation,

178
00:07:35,680 --> 00:07:38,000
normal day-to-day cleanup can create a real problem.

179
00:07:38,000 --> 00:07:41,920
The message or document you need may disappear before anyone has a chance to find it.

180
00:07:41,920 --> 00:07:44,880
That is why a hold often comes before a deep search.

181
00:07:44,880 --> 00:07:48,480
You may know enough to identify the people and locations connected to the matter,

182
00:07:48,480 --> 00:07:51,760
even before you know exactly which messages or files will matter.

183
00:07:51,760 --> 00:07:56,080
A hold keeps that material available while the team works out the right search.

184
00:07:56,080 --> 00:07:59,520
Now legal hold and retention are related, but they are not the same thing.

185
00:07:59,520 --> 00:08:02,720
A retention policy follows your organization's normal records rules.

186
00:08:02,720 --> 00:08:05,600
For example, it may keep certain business records for a set period,

187
00:08:05,600 --> 00:08:07,520
then remove them when that period ends.

188
00:08:07,520 --> 00:08:09,600
A legal hold responds to one specific matter.

189
00:08:09,600 --> 00:08:12,880
Retention asks, how long should we normally keep this kind of work?

190
00:08:12,880 --> 00:08:16,160
A legal hold asks, could this content matter in this case right now?

191
00:08:16,160 --> 00:08:20,400
Both can affect what stays available, but they start from different reasons.

192
00:08:20,400 --> 00:08:24,000
Imagine an employee learns that HR is looking into a complaint.

193
00:08:24,000 --> 00:08:27,920
That employee may delete a team's chat or remove an email from their mailbox.

194
00:08:27,920 --> 00:08:31,120
Maybe they think it is irrelevant, or maybe they are simply cleaning up.

195
00:08:31,120 --> 00:08:33,040
If the relevant locations are on hold,

196
00:08:33,040 --> 00:08:35,760
Perview can keep the needed copy available for the case.

197
00:08:35,760 --> 00:08:38,720
The user may no longer see the deleted item in the usual place,

198
00:08:38,720 --> 00:08:42,000
but the preserved copy remains available to authorised case members.

199
00:08:42,000 --> 00:08:43,440
That is why a hold carries weight.

200
00:08:43,440 --> 00:08:47,200
It is not a routine switch that IT turns on whenever someone wants a quick answer.

201
00:08:47,200 --> 00:08:49,760
A quick fact check may only need a narrow search.

202
00:08:49,760 --> 00:08:55,200
A hold belongs where legal, HR compliance, or an investigation team says the content needs to stay available.

203
00:08:55,200 --> 00:08:58,000
The decision should come from the people responsible for the matter,

204
00:08:58,000 --> 00:08:59,840
with IT helping apply it correctly.

205
00:08:59,840 --> 00:09:01,840
There is another detail that catches people out.

206
00:09:01,840 --> 00:09:02,720
Case status matters.

207
00:09:02,720 --> 00:09:06,480
If you close a case, the holds connected to that case can be released,

208
00:09:06,480 --> 00:09:08,800
so closing a case is not just housekeeping.

209
00:09:08,800 --> 00:09:11,600
It is a decision with consequences for preserved content.

210
00:09:11,600 --> 00:09:15,120
Before closing anything, the people responsible for the case need to know whether

211
00:09:15,120 --> 00:09:16,400
preservation should end.

212
00:09:16,400 --> 00:09:18,000
For you, treat a hold with care.

213
00:09:18,000 --> 00:09:20,000
It changes what data must remain available.

214
00:09:20,000 --> 00:09:23,840
It can affect mailboxes, files, chats, and sites connected to the matter.

215
00:09:23,840 --> 00:09:26,400
Make sure the scope is clear, access is controlled,

216
00:09:26,400 --> 00:09:30,800
and the case team knows who owns the decision to apply, change, or release it.

217
00:09:30,800 --> 00:09:34,800
With evidence preserved, the search process has something reliable to work with.

218
00:09:34,800 --> 00:09:35,920
Building block 4.

219
00:09:35,920 --> 00:09:38,160
Search without drowning in data.

220
00:09:38,160 --> 00:09:41,840
So, with the right locations protected, you can begin the search.

221
00:09:41,840 --> 00:09:46,640
A search asks Perview to find content that matches your conditions across the sources you selected for the case,

222
00:09:46,640 --> 00:09:49,200
and you're not asking, "Show me everything."

223
00:09:49,200 --> 00:09:54,640
You're asking a focused question like, "What did these two people discuss about this project during this period?"

224
00:09:54,640 --> 00:09:58,160
Perview gives you several simple ways to narrow that question.

225
00:09:58,160 --> 00:10:02,880
You can look for a word or exact phrase, set a date range, focus on a sender or recipient,

226
00:10:02,880 --> 00:10:05,760
or search by subject line file type or message type.

227
00:10:05,760 --> 00:10:09,760
Each condition cuts away content that probably has nothing to do with the matter.

228
00:10:09,760 --> 00:10:11,280
Start with the guided condition builder.

229
00:10:11,280 --> 00:10:15,040
It gives you clear fields to fill in, which is usually the right place for beginners.

230
00:10:15,040 --> 00:10:17,840
You pick the people, choose the dates, enter a phrase,

231
00:10:17,840 --> 00:10:19,360
and select the locations you need.

232
00:10:19,360 --> 00:10:21,360
Some people need more detailed search logic.

233
00:10:21,360 --> 00:10:25,200
For that, Perview supports keyword query language, usually called KQL.

234
00:10:25,200 --> 00:10:27,360
KQL lets you write more exact search rules.

235
00:10:27,360 --> 00:10:28,960
You don't need to learn it on day one,

236
00:10:28,960 --> 00:10:33,440
but it becomes useful when a simple phrase search returns too much noise or misses a very specific pattern.

237
00:10:33,440 --> 00:10:36,480
The people in places you search matter just as much as the words.

238
00:10:36,480 --> 00:10:38,880
You might search named Exchange Online mailboxes,

239
00:10:38,880 --> 00:10:41,520
individual one driver counts, a known SharePoint site,

240
00:10:41,520 --> 00:10:44,160
teams-related content connected to those locations,

241
00:10:44,160 --> 00:10:48,320
or when the matter truly calls for it broader organization sources.

242
00:10:48,320 --> 00:10:50,880
Imagine an investigation involving two employees

243
00:10:50,880 --> 00:10:52,880
and a project called Project Redwood.

244
00:10:52,880 --> 00:10:55,680
A sensible first search might cover the last 90 days,

245
00:10:55,680 --> 00:10:58,080
they're selected data sources, and the phrases,

246
00:10:58,080 --> 00:10:59,840
Project Redwood and Settlement.

247
00:10:59,840 --> 00:11:02,080
That first result is not your final answer.

248
00:11:02,080 --> 00:11:04,720
You run it, then check the statistics and sample results.

249
00:11:04,720 --> 00:11:07,120
Statistics show you the shape of the results set,

250
00:11:07,120 --> 00:11:11,360
and a sample lets you see whether Perview found the kind of messages and files you expected.

251
00:11:11,360 --> 00:11:14,720
Maybe the phrase Settlement brings back unrelated sales emails,

252
00:11:14,720 --> 00:11:16,320
so you adjust the search.

253
00:11:16,320 --> 00:11:18,400
Or maybe the sample shows a project code,

254
00:11:18,400 --> 00:11:19,600
nobody mentioned at the start,

255
00:11:19,600 --> 00:11:21,600
so you add that term and run another search.

256
00:11:21,600 --> 00:11:22,560
This is normal.

257
00:11:22,560 --> 00:11:24,000
Good searching is a loop.

258
00:11:24,000 --> 00:11:26,480
You ask a focused question, check the results,

259
00:11:26,480 --> 00:11:28,640
learn from them, and refine the question.

260
00:11:28,640 --> 00:11:31,840
You can also create more than one search inside the same case.

261
00:11:31,840 --> 00:11:34,720
One search might focus on messages between the two employees,

262
00:11:34,720 --> 00:11:36,480
another might look only for documents,

263
00:11:36,480 --> 00:11:40,240
and a third might narrow the date range to the week around a particular meeting.

264
00:11:40,240 --> 00:11:42,960
Separating these searches makes the work easier to follow,

265
00:11:42,960 --> 00:11:46,000
and keeps unlike results from becoming one confusing pile.

266
00:11:46,000 --> 00:11:49,440
Many people think the safest move is searching the whole organization first,

267
00:11:49,440 --> 00:11:50,960
but it usually isn't.

268
00:11:50,960 --> 00:11:55,840
A search that covers every mailbox, site, and file can produce far too much unrelated materials,

269
00:11:55,840 --> 00:11:58,880
slowing down the people who need to review it and exposing private work

270
00:11:58,880 --> 00:12:00,480
that has no connection to the matter.

271
00:12:00,480 --> 00:12:02,560
Start narrow, then expand with a reason.

272
00:12:02,560 --> 00:12:04,400
There is also content search in Perview,

273
00:12:04,400 --> 00:12:07,600
which can help with a quick check and early look at whether a term appears,

274
00:12:07,600 --> 00:12:10,400
or fact finding before a formal matter begins.

275
00:12:10,400 --> 00:12:14,720
But when the work becomes an investigation that needs controlled access and a clear home,

276
00:12:14,720 --> 00:12:17,360
an eDiscovery case gives the search a proper structure.

277
00:12:17,360 --> 00:12:20,080
For you, the lesson is simple.

278
00:12:20,080 --> 00:12:23,360
Good eDiscovery starts with a question, not a giant search box.

279
00:12:23,360 --> 00:12:25,120
Once results arrive, the job changes.

280
00:12:25,120 --> 00:12:27,280
You are no longer only finding content.

281
00:12:27,280 --> 00:12:29,840
You need to decide what actually belongs in the matter.

282
00:12:29,840 --> 00:12:33,440
Building block five, review sets, tags, and the final export.

283
00:12:33,440 --> 00:12:35,360
A search gives you possible matches.

284
00:12:35,360 --> 00:12:39,440
That word "possible" matters because Perview can find a document that includes your phrase,

285
00:12:39,440 --> 00:12:42,640
but software can't decide if it actually belongs in the matter.

286
00:12:42,640 --> 00:12:45,120
A person with the right context has to make that call.

287
00:12:45,120 --> 00:12:46,960
This is where a review set comes in.

288
00:12:46,960 --> 00:12:51,680
A review set is a working evidence table where collected results can be examined in more detail.

289
00:12:51,680 --> 00:12:54,080
Instead of looking at a large list of search matches,

290
00:12:54,080 --> 00:12:57,200
authorised reviewers can work through a selected group of content

291
00:12:57,200 --> 00:12:59,680
and decide what each item means for the case.

292
00:12:59,680 --> 00:13:02,640
Think of it as moving possible evidence onto a review table.

293
00:13:02,640 --> 00:13:04,800
The items are there because they match the search,

294
00:13:04,800 --> 00:13:07,360
and now someone needs to read them, understand the context,

295
00:13:07,360 --> 00:13:09,360
and sort them into useful groups.

296
00:13:09,360 --> 00:13:12,560
Review sets and the more advanced review tools depend on your licensing.

297
00:13:12,560 --> 00:13:15,920
Standard eDiscovery workflows center on the case,

298
00:13:15,920 --> 00:13:19,840
hold, search, and export, which may be enough for many smaller matters.

299
00:13:19,840 --> 00:13:25,200
Premium eDiscovery can add review sets and extra ways to analyse a larger or more complex set of results.

300
00:13:25,200 --> 00:13:28,320
So don't assume every Perview tenant will show the same buttons.

301
00:13:28,320 --> 00:13:30,880
Check what your license includes before a real case starts,

302
00:13:30,880 --> 00:13:34,160
so nobody plans a review process around a feature they can't use.

303
00:13:34,160 --> 00:13:36,640
The point of review stays the same either way.

304
00:13:36,640 --> 00:13:39,680
Search finds matching words, but people decide relevance.

305
00:13:39,680 --> 00:13:42,720
A word document may contain the phrase "project redwood",

306
00:13:42,720 --> 00:13:44,800
but that does not make it evidence by itself.

307
00:13:44,800 --> 00:13:46,960
It might be a meeting agenda with no useful detail,

308
00:13:46,960 --> 00:13:49,200
a draft contract that directly relates to the matter,

309
00:13:49,200 --> 00:13:53,280
or a document that needs legal review before anybody shares it outside the organisation.

310
00:13:53,280 --> 00:13:56,080
Tags help reviewers record those decisions.

311
00:13:56,080 --> 00:13:59,120
A tag is just a label you apply to an item after reviewing it.

312
00:13:59,120 --> 00:14:01,200
You might use tags such as relevant, not relevant,

313
00:14:01,200 --> 00:14:03,760
needs review, privileged, internal, or public.

314
00:14:03,760 --> 00:14:06,960
Your organisation may use different labels, but the goal is the same.

315
00:14:06,960 --> 00:14:09,440
Give the case team a clear way to sort content

316
00:14:09,440 --> 00:14:10,960
and explain what they decided.

317
00:14:10,960 --> 00:14:13,360
Imagine that word document turns up in a search.

318
00:14:13,360 --> 00:14:16,560
A reviewer reads it and finds details that connect directly to the issue,

319
00:14:16,560 --> 00:14:17,920
so they mark it relevant.

320
00:14:17,920 --> 00:14:20,240
The document also includes advice from legal counsel,

321
00:14:20,240 --> 00:14:21,920
so they apply a privileged tag as well.

322
00:14:21,920 --> 00:14:24,720
Now the item is no longer just a keyword match.

323
00:14:24,720 --> 00:14:28,800
It has been reviewed, classified, and placed in context for the people handling the matter.

324
00:14:28,800 --> 00:14:32,000
Premium review tools can help when the result set becomes larger.

325
00:14:32,000 --> 00:14:34,320
They can find duplicate or near-duplicate files,

326
00:14:34,320 --> 00:14:37,920
group-related content, and thread email or conversation context together,

327
00:14:37,920 --> 00:14:40,880
helping a reviewer see a discussion as a connected exchange

328
00:14:40,880 --> 00:14:42,720
rather than isolated messages.

329
00:14:42,720 --> 00:14:44,080
Those tools don't replace judgment.

330
00:14:44,080 --> 00:14:46,480
They help the reviewer spend more time on the content

331
00:14:46,480 --> 00:14:48,000
that needs a human decision.

332
00:14:48,000 --> 00:14:51,040
Once the case team has selected the right items, they can export them.

333
00:14:51,040 --> 00:14:52,800
An export package is selected content

334
00:14:52,800 --> 00:14:56,480
and supporting details for legal, HR, compliance, or an outside review team.

335
00:14:56,480 --> 00:14:59,520
It's the hand-off point where the work inside PerView becomes material

336
00:14:59,520 --> 00:15:01,280
another authorised person can review.

337
00:15:01,280 --> 00:15:02,880
There are two broad paths here.

338
00:15:02,880 --> 00:15:05,360
Sometimes a completed search needs a quick hand-off

339
00:15:05,360 --> 00:15:08,160
and the team may export directly from the search results.

340
00:15:08,160 --> 00:15:10,160
Other times, the matter needs closer review first,

341
00:15:10,160 --> 00:15:13,760
so the team can review the content, apply tags, filter out what does not belong,

342
00:15:13,760 --> 00:15:16,560
and export only the selected items from the review work.

343
00:15:16,560 --> 00:15:19,360
The second path gives you more control because instead of sending

344
00:15:19,360 --> 00:15:21,360
every item that happened to match a word,

345
00:15:21,360 --> 00:15:25,360
you can send the items that a reviewer has checked and marked for the right purpose.

346
00:15:25,360 --> 00:15:27,360
Access still matters all the way through.

347
00:15:27,360 --> 00:15:29,360
Only assigned case members should work with the matter,

348
00:15:29,360 --> 00:15:31,600
including the review and export stages.

349
00:15:31,600 --> 00:15:34,160
Permissions are not something you fix at the end.

350
00:15:34,160 --> 00:15:36,480
They need to be in place before the first search runs,

351
00:15:36,480 --> 00:15:39,760
because sensitive content can appear in the results immediately.

352
00:15:39,760 --> 00:15:43,280
For you, an export is not a download button for every search result.

353
00:15:43,280 --> 00:15:45,600
It is the last step in a careful chain of decisions.

354
00:15:45,600 --> 00:15:47,760
Someone defined the matter, selected the sources,

355
00:15:47,760 --> 00:15:50,320
protected the content, searched, reviewed, and sorted it.

356
00:15:50,320 --> 00:15:52,960
Only then does the right set move to the right people.

357
00:15:52,960 --> 00:15:54,720
That leads to the bigger picture.

358
00:15:54,720 --> 00:15:55,920
How the paths connect?

359
00:15:55,920 --> 00:15:58,720
From scattered work data to a defensible process.

360
00:15:58,720 --> 00:16:00,720
So here's the thing about eDiscovery.

361
00:16:00,720 --> 00:16:02,720
It's not one big search button.

362
00:16:02,720 --> 00:16:06,000
It's a process, a process that gives every search a purpose

363
00:16:06,000 --> 00:16:07,280
and a record of what happened.

364
00:16:07,280 --> 00:16:10,080
Let's break it down. The case defines the scope of the matter.

365
00:16:10,080 --> 00:16:12,080
Then the data sources tell you where to look.

366
00:16:12,080 --> 00:16:15,280
The hold makes sure content stays preserved while the case is active.

367
00:16:15,280 --> 00:16:16,960
The search narrows down the field.

368
00:16:16,960 --> 00:16:19,600
The reviewer separates what's relevant from what's not.

369
00:16:19,600 --> 00:16:23,600
And finally, the export hands the selected results to the people who need them.

370
00:16:23,600 --> 00:16:24,640
The order matters.

371
00:16:24,640 --> 00:16:27,360
Search before you define the scope, you get noise.

372
00:16:27,360 --> 00:16:28,800
Export before someone reviews.

373
00:16:28,800 --> 00:16:30,960
You might share way more than the case requires.

374
00:16:30,960 --> 00:16:32,800
Skip a hold when preservation is needed.

375
00:16:32,800 --> 00:16:36,240
The content could change or disappear before anyone can assess it.

376
00:16:36,240 --> 00:16:38,320
Let's go back to the office building analogy.

377
00:16:38,320 --> 00:16:40,960
Enter ID is the reception desk that controls who gets in.

378
00:16:40,960 --> 00:16:44,480
Microsoft 365 apps are the rooms where the daily work happens.

379
00:16:44,480 --> 00:16:48,640
Per view eDiscovery is like a key that only opens the rooms connected to the matter.

380
00:16:48,640 --> 00:16:51,920
And it records every step the case team took through those rooms.

381
00:16:51,920 --> 00:16:53,200
Why does that record matter?

382
00:16:53,200 --> 00:16:55,600
Because investigations involve more than just technology.

383
00:16:55,600 --> 00:16:58,560
IT manages the platform and makes sure the process runs correctly.

384
00:16:58,560 --> 00:17:02,800
But legal HR compliance security and business owners bring the actual question,

385
00:17:02,800 --> 00:17:05,840
the context, and the decisions about what happens next.

386
00:17:05,840 --> 00:17:08,160
No single group should try to do everything alone.

387
00:17:08,160 --> 00:17:09,760
That's a recipe for mistakes.

388
00:17:09,760 --> 00:17:12,080
Modern work also leaves connected trails everywhere.

389
00:17:12,080 --> 00:17:13,840
An email can point to a cloud file.

390
00:17:13,840 --> 00:17:16,880
A chat can involve a document stored somewhere else.

391
00:17:16,880 --> 00:17:19,280
A team discussion can lead to another shared location.

392
00:17:19,280 --> 00:17:22,080
That's why your source map matters just as much as your search words.

393
00:17:22,080 --> 00:17:24,960
Once your organization understands this connected path,

394
00:17:24,960 --> 00:17:27,200
you can prepare before the next request arrives.

395
00:17:27,200 --> 00:17:28,720
That's the real benefit.

396
00:17:28,720 --> 00:17:30,080
Actionable takeaways.

397
00:17:30,080 --> 00:17:32,160
Be ready before the request arrives.

398
00:17:32,160 --> 00:17:33,760
Start with a data map.

399
00:17:33,760 --> 00:17:36,000
Write down where your organization actually works,

400
00:17:36,000 --> 00:17:37,600
not where people think it works.

401
00:17:37,600 --> 00:17:41,600
Include exchange online for email, one drive for personal files,

402
00:17:41,600 --> 00:17:44,080
SharePoint for shared sites, and Teams,

403
00:17:44,080 --> 00:17:48,080
Microsoft 365 Groups and Viva Engage if your people use them.

404
00:17:48,080 --> 00:17:50,080
Keep the map simple.

405
00:17:50,080 --> 00:17:53,040
The goal is to help legal, HR, compliance,

406
00:17:53,040 --> 00:17:56,240
security, and IT answer one basic question quickly.

407
00:17:56,240 --> 00:17:59,040
Where could the records for this matter live?

408
00:17:59,040 --> 00:18:01,760
Next, check your PerView eDiscovery permissions.

409
00:18:01,760 --> 00:18:04,560
Only the people who actually need to handle sensitive cases

410
00:18:04,560 --> 00:18:07,520
should have access to cases, search results, and exports.

411
00:18:07,520 --> 00:18:10,240
Review the roles you've assigned and remove any access

412
00:18:10,240 --> 00:18:11,920
that doesn't have a clear reason.

413
00:18:11,920 --> 00:18:13,920
This is a good time to decide who does what,

414
00:18:13,920 --> 00:18:15,840
who can open a case, who can run a search,

415
00:18:15,840 --> 00:18:17,440
who can approve an export.

416
00:18:17,440 --> 00:18:18,880
Those decisions are much easier

417
00:18:18,880 --> 00:18:21,840
when there's no urgent request sitting in someone's inbox.

418
00:18:21,840 --> 00:18:24,240
After that, agree on a simple case naming pattern

419
00:18:24,240 --> 00:18:25,840
and a path for raising a matter.

420
00:18:25,840 --> 00:18:28,080
A case name could include the type of matter,

421
00:18:28,080 --> 00:18:29,760
a short subject, and a date.

422
00:18:29,760 --> 00:18:32,800
Keep it clear enough that the approved case team can tell one matter

423
00:18:32,800 --> 00:18:34,960
from another without opening every single case.

424
00:18:34,960 --> 00:18:36,320
Also agree on the first call.

425
00:18:36,320 --> 00:18:39,360
If HR receives an employee complaint, who contacts IT?

426
00:18:39,360 --> 00:18:42,800
If security finds a possible data exposure, when does legal join?

427
00:18:42,800 --> 00:18:44,720
If compliance receives a regulator request,

428
00:18:44,720 --> 00:18:46,800
who decides whether preservation is needed?

429
00:18:46,800 --> 00:18:49,600
You don't need a huge policy document before you start,

430
00:18:49,600 --> 00:18:51,680
you just need a clear path people can follow.

431
00:18:51,680 --> 00:18:53,600
Then practice with a small test case.

432
00:18:53,600 --> 00:18:56,480
Use a limited test data source and a short date range.

433
00:18:56,480 --> 00:18:58,640
Avoid real sensitive matters, create the case,

434
00:18:58,640 --> 00:19:01,680
confirm the right people can access it, run a narrow search,

435
00:19:01,680 --> 00:19:03,920
and see how the results move through your process.

436
00:19:03,920 --> 00:19:05,760
A practice run finds confusion early.

437
00:19:05,760 --> 00:19:07,280
Maybe the wrong people have permissions,

438
00:19:07,280 --> 00:19:09,360
maybe a team doesn't know where its files live,

439
00:19:09,360 --> 00:19:11,120
maybe the case name doesn't explain enough.

440
00:19:11,120 --> 00:19:12,880
Better to find those issues during a test

441
00:19:12,880 --> 00:19:14,640
than during a live investigation.

442
00:19:14,640 --> 00:19:16,880
Check licensing before you need advanced options.

443
00:19:16,880 --> 00:19:18,880
Content search and standard e-discovery

444
00:19:18,880 --> 00:19:21,280
usually come with e-3-level licensing.

445
00:19:21,280 --> 00:19:23,520
Premium review and analysis options generally need

446
00:19:23,520 --> 00:19:25,040
e-5 licensing or an add-on.

447
00:19:25,040 --> 00:19:26,560
Your exact setup can differ,

448
00:19:26,560 --> 00:19:28,720
so verify what your organization has

449
00:19:28,720 --> 00:19:31,200
before you promise a feature to legal or HR.

450
00:19:31,200 --> 00:19:33,520
And when a formal request or investigation begins,

451
00:19:33,520 --> 00:19:34,480
don't self-clean.

452
00:19:34,480 --> 00:19:37,360
Don't delete, move, or alter possible evidence.

453
00:19:37,360 --> 00:19:39,360
Raise the matter through the agreed path

454
00:19:39,360 --> 00:19:41,760
and let the right people decide what needs preserving.

455
00:19:41,760 --> 00:19:43,200
That's the practical system.

456
00:19:43,200 --> 00:19:46,480
Per view e-discovery turns scattered Microsoft 365 work

457
00:19:46,480 --> 00:19:48,240
into a controlled case process

458
00:19:48,240 --> 00:19:51,040
from the first question through the final handoff.

459
00:19:51,040 --> 00:19:52,880
Subscribe on your favorite podcast platform

460
00:19:52,880 --> 00:19:54,080
and share this knowledge nugget

461
00:19:54,080 --> 00:19:57,120
with someone starting their Microsoft 365 journey mode.

462
00:19:57,120 --> 00:19:59,120
One system, not just one search.

463
00:19:59,120 --> 00:20:01,680
Search finds the content and holds keep it available.

464
00:20:01,680 --> 00:20:04,320
Review separates useful material from keyword matches

465
00:20:04,320 --> 00:20:07,280
and export creates the handoff for the people handling the matter.

466
00:20:07,280 --> 00:20:10,400
Microsoft Per view e-discovery works best before a crisis.

467
00:20:10,400 --> 00:20:13,200
Make sure your data locations, access rules,

468
00:20:13,200 --> 00:20:15,440
and team responsibilities are already clear.

469
00:20:15,440 --> 00:20:17,920
Start with your data map and your case process

470
00:20:17,920 --> 00:20:19,600
because the right question means very little

471
00:20:19,600 --> 00:20:21,440
if nobody knows where the answer lives.

472
00:20:21,440 --> 00:20:24,960
Subscribe for more Microsoft knowledge nuggets on M365, FM,

473
00:20:24,960 --> 00:20:28,320
and share this with the person who still thinks teams files live inside teams.