Direct answer: use Microsoft Purview eDiscovery for an authorized legal, regulatory, or HR investigation; use Microsoft Graph for an approved repeatable application workflow; use the Teams meeting Recap for a meeting transcript; and use copy or print only for a convenience reference. The Teams admin center does not provide a general message-content export. North Brook Vault does not export Teams content or restore Teams chat or channel messages.
Do not begin by choosing PDF, PST, HTML, or JSON. First record the requester, authority, users, conversation type, dates, timezone, attachments, edits, reactions, deleted content, and required metadata. If the request could relate to litigation, employment action, regulation, or a legal hold, stop and route it through counsel and the approved Teams eDiscovery runbook.
Choose the Method
| Need | Method | Owner and prerequisites | Important limitation |
|---|---|---|---|
| Authorized investigation or preservation matter | Microsoft Purview eDiscovery case, search/collection, review, and export | Legal owner plus users with current eDiscovery roles and licenses | Results depend on sources, retention, holds, query, unindexed items, and export settings |
| Recurring application export or integration | Microsoft Graph chat/channel APIs or Teams Export APIs | Application owner, security review, approved consent, secret/certificate lifecycle | API access is not a legal workflow and does not prove completeness |
| Meeting transcript | Teams meeting Recap > Transcript > Download | Organizer/co-organizer or another user allowed by policy | Only available if transcription occurred and policy permits access |
| Short internal reference | Copy/paste or browser print | Authorized participant | Lazy loading, edits, reactions, attachments, deleted messages, and metadata may be missing |
| Readable PDF | Create a derivative from an approved native export | Investigation or records owner | PDF conversion can alter presentation and file properties; retain the native source and reports |
| Usage statistics | Teams admin center reports | Teams administrator | Reports provide aggregate activity, not message content |
Request and Owner Fields
- Request ID and purpose: [ticket/matter and approved purpose]
- Requesting owner: [name/title]
- Legal or HR authorization: [name/title, if applicable]
- Technical operator: [name/title]
- Users and conversation type: [1:1, group chat, meeting chat, standard/private/shared channel]
- Date range and timezone: [inclusive dates and zone]
- Required content: [messages, replies, edits, reactions, attachments, files, transcript]
- Required output and delivery: [native, review set, PDF derivative, secure destination]
- Retention and disposition: [owner, period, hold, deletion instruction]
Understand the Source Before Exporting
Live Teams message data remains in the Teams service, which Microsoft documents as Azure Cosmos DB. For eDiscovery, Microsoft 365 captures hidden compliance records in Exchange Online; Purview searches those compliance records rather than the live Teams data. Standard channel compliance records are associated with the team, while private and shared channel source handling differs. Files shared in chats are generally stored in the sharer's OneDrive; channel files are stored in the associated SharePoint site. Review Microsoft's current Teams eDiscovery source table before choosing sources.
This architecture is why one method cannot be assumed to reproduce every visible element in the Teams client. Scope messages and files separately. Validate the participant context, duplicate compliance copies, replies, edits, reactions, system messages, and attachments required by the request.
Procedure A: Authorized Purview Export
- Confirm written authority and whether preservation is required. IT should not make the legal determination.
- Use the current Microsoft Purview portal eDiscovery experience. Classic Content Search, eDiscovery Standard, and eDiscovery Premium interfaces were retired on August 31, 2025.
- Create or use the approved case, identify data sources, apply any counsel-authorized hold, and verify hold status.
- Search or collect with a documented date, source, participant, and message-type strategy. Scoping two users' mailboxes does not by itself isolate only the conversation between them.
- When a specific conversation is required, add results to a review set and validate conversation context before culling or export.
- Export with the chosen native and metadata options. Retain process reports and validate original timestamps using the item report rather than extracted ZIP file dates.
Procedure B: Microsoft Graph Workflow
For a known chat, Microsoft Graph supports GET /chats/{chat-id}/messages; channel message endpoints use the team and channel identifiers. Handle @odata.nextLink, throttling, retries, hosted content, attachments, replies, edits, deletions, and control messages as required. The current list chat messages documentation distinguishes delegated, application, and resource-specific permissions. Do not request tenant-wide Chat.Read.All when a less privileged supported model meets the approved use case.
- Document purpose, data minimization, app owner, retention, and security approval.
- Choose the least-privileged supported permission and consent model. Protect credentials and monitor app use.
- Export a controlled sample. Reconcile message counts, participants, dates, replies, attachments, and pagination.
- Write immutable run metadata alongside the output: app version, tenant, endpoint, query, start/end time, page count, errors, and hashes.
- Do not describe the result as complete or legally sufficient without validation by the responsible investigation and legal owners.
Procedure C: Meeting Transcript or PDF
Meeting transcripts are different from chat history. If transcription occurred, authorized users can open the past meeting, select Recap and Transcript, and download an available .docx or .vtt file. Access depends on meeting role and policy. Microsoft states that transcripts are stored in the organizer's OneDrive for Business; see the official transcript instructions.
For a PDF, preserve the approved native export and reports first, then render a derivative. Record the conversion tool, version, settings, operator, time, source hash, and PDF hash. A browser print of a chat is suitable only when the owner accepts that loaded content and metadata may be incomplete.
Evidence Checklist
- ☐ Written authority, purpose, users, dates, timezone, and requested content.
- ☐ Current Purview role/license or Graph application and consent record.
- ☐ Source map for chats, channels, files, meetings, and transcripts.
- ☐ Query/API parameters, pagination, run time, errors, and operator identity.
- ☐ Participant, date, message-count, reply, edit, reaction, and attachment validation.
- ☐ Native output, process reports, hashes, secure transfer receipt, and disposition instruction.
- ☐ PDF or other derivative linked to the retained native source.
Product and Legal Limitations
No export method automatically establishes authenticity, completeness, admissibility, or chain of custody. Counsel and the investigation owner must define the procedure and evidentiary requirements. Availability also depends on Microsoft configuration, policy, retention, holds, account state, source type, and previous collection.
North Brook Vault schedules backup of supported Teams objects and provides supported snapshot-browsing capabilities. It does not export Teams data to PST, PDF, ZIP, or a legal-discovery package, and it does not restore chat messages, channel messages, channel structure, or meeting transcripts. Review the broader Teams backup capability guide and the retention decision guide before treating preservation and recovery as equivalent.