Direct answer: Microsoft Purview retention, eDiscovery holds, native recovery, Microsoft 365 Backup, and independent backup are separate controls. Use retention to preserve or dispose of content according to an approved schedule. Use a hold to preserve content for an authorized matter. Use native recovery or a tested backup service to restore supported operational data. Do not infer one control's scope, time window, or restore behavior from another.
This guide is a planning aid, not legal advice. Retention periods, suspension of deletion, privacy requests, and evidence obligations depend on the organization, record class, contracts, jurisdiction, and facts. Legal or records-management owners must approve the schedule; technical owners must prove that the configured controls behave as approved.
Choose the Control by Required Outcome
| Required outcome | Primary control to evaluate | What it does not prove | Accountable owner |
|---|---|---|---|
| Keep a record for an approved minimum period | Purview retention policy or retention label | That the item can be restored to its original application state | Legal or records management |
| Delete content after an approved period | Purview retention and disposition configuration | That every copy, backup, export, or third-party system is covered | Privacy and records management |
| Preserve potentially relevant content for a matter | Purview eDiscovery hold, authorized by counsel | Completeness, admissibility, or a legal conclusion | Legal |
| Undo recent user deletion | Workload-specific recycle bin, Recoverable Items, or native restore | A universal recovery window across Exchange, SharePoint, OneDrive, and Teams | M365 operations |
| Recover after corruption or destructive change | Native recovery and/or tested backup | Coverage of untested object types, permissions, versions, or metadata | Service owner |
| Demonstrate that a control operated | Policy export, process report, audit event, job result, and recovery test | Compliance or certification by itself | Control owner |
Microsoft documents how retention behaves differently in Exchange Online and in SharePoint and OneDrive. For example, Exchange uses Recoverable Items locations, while SharePoint and OneDrive can use the Preservation Hold library. Recycle-bin and deletion behavior are workload-specific; there is no general "93-day Microsoft 365" rule.
Build the Retention Control Record
Create one row for each record class, not one row for an entire tenant. A controlled operating process starts with the business record and its owner, then maps it to locations and controls. Use these required fields:
- Record class and description: [for example, executed customer agreement]
- Business owner: [name and title]
- Legal/records approver: [name and title]
- Technical control owner: [name and team]
- Authoritative source: [law, contract, policy, or approved business need]
- Trigger and period: [creation, termination, case closure, or another approved event]
- Locations: [mailboxes, sites, OneDrives, Teams content, exports, and other systems]
- Hold and exception rules: [who can suspend disposition and how]
- Recovery requirement: [object, recovery point, destination, and target time]
- Evidence and review date: [where records are kept and when the row expires for review]
Do not turn framework names into fixed technology settings. HIPAA's contingency-plan requirements include retrievable copies and restoration procedures, but the organization still has to determine scope and implementation; see the HHS audit protocol. GDPR Article 32 includes the ability to restore availability and access to personal data in a timely manner as appropriate to risk; it does not prescribe one backup interval. See the official GDPR text. A SOC 2 report is an examination of a service organization's system and controls, not a regulation or a universal daily-backup rule.
Run the Control-Mapping Procedure
- Inventory the record. Identify the authoritative copy, duplicates, shared locations, owners, and downstream exports. Do not begin with a product setting.
- Approve the rule. Legal or records management records the source, trigger, period, hold behavior, and disposition authority. Resolve conflicts with privacy, contractual, or jurisdictional requirements.
- Map the technology. Document the exact Purview policy or label, included and excluded locations, adaptive or static scope, license, and expected preservation or deletion behavior.
- Map recovery separately. Define the required object types, recovery points, restore destinations, and fidelity. Use the RTO and RPO worksheet rather than setting targets from a vendor default.
- Test before enforcement. Use non-production or approved test content. Verify creation, edit, deletion, hold, policy removal, disposition, and recovery behavior for each workload.
- Approve and monitor. Record the configuration, approvers, test evidence, exceptions, job failures, and next review date in the organization's control register.
Evidence Checklist
- ☐ Counsel- or records-approved retention source, record class, trigger, period, and review date.
- ☐ Purview policy export or screenshots showing scope, settings, mode, and successful distribution.
- ☐ Test results for Exchange, SharePoint, OneDrive, and applicable Teams content rather than one extrapolated result.
- ☐ Hold report and matter authorization when disposition is suspended.
- ☐ Backup job history, retained recovery point, item-level errors, and a representative restore result.
- ☐ Exception owner, business reason, compensating control, expiry, and approval.
- ☐ Evidence location protected from unauthorized alteration and accessible to the designated reviewer.
North Brook Vault Boundary and Limitations
North Brook Vault provides policy-driven retention for supported backup snapshots and selective restore for supported object types. It does not make a tenant compliant, issue a compliance report, provide legal-hold administration, or establish the organization's retention schedule. Its managed storage does not currently expose native Object Lock configuration or enforcement. A snapshot date also does not prove complete capture or restore fidelity; validate required objects during a pilot and record the result in the organization's backup and recovery policy.
Decision gate: approve production retention only when the legal rule, technical scope, deletion behavior, recovery requirement, evidence owner, and exception path are all documented. If any field is unknown, keep the control in design or simulation rather than claiming coverage.