Direct answer: use the current Microsoft Purview portal to create a case, preserve sources when authorized, search or collect Teams compliance records and related files, validate conversations in a review set when context matters, and export content with its process reports. Do not use retired Core, Standard, Premium, or classic Content Search navigation. Microsoft retired the classic experiences on August 31, 2025.
This runbook is operational guidance, not legal advice. Counsel or another authorized legal owner decides whether a duty to preserve exists, which custodians and sources are in scope, what may be collected, and how evidence is handled. Purview features and reports can support a documented process; they do not establish completeness, authenticity, admissibility, privilege treatment, or a legal conclusion.
Source Decision Table
| Teams content | eDiscovery source to evaluate | Related files | Validation owner |
|---|---|---|---|
| 1:1 and group chats | Exchange compliance records captured for chat participants | Usually the sharer's OneDrive | eDiscovery operator |
| Standard channel messages | Compliance records associated with the team/group | Team SharePoint site | Teams and eDiscovery operators |
| Private channel messages | Mailboxes of private-channel members included according to current Microsoft guidance | Dedicated channel SharePoint site | Teams and eDiscovery operators |
| Shared channel messages | System source associated with the shared channel; cross-tenant context may matter | Dedicated channel SharePoint site | Teams and legal owners |
| Meeting chat | Chat participant compliance records | Shared files in OneDrive or SharePoint according to context | eDiscovery operator |
| Meeting recording and transcript | Organizer's OneDrive and the meeting's applicable sources | Recording/transcript files and metadata | Meeting owner and eDiscovery operator |
Teams message data remains in the Teams service, which Microsoft documents as Azure Cosmos DB. Exchange Online stores hidden compliance records captured for eDiscovery; Purview does not search the live Teams message store. That distinction affects duplication, context, and what a user sees in Teams versus an eDiscovery result. Use Microsoft's current Teams content-location table for source selection rather than assuming every channel has a mailbox that an operator should locate manually.
Case and Owner Fields
- Case/matter ID: [approved identifier]
- Legal owner: [name/title]
- Preservation authority and date: [instruction/reference]
- eDiscovery manager: [name/title]
- Technical operator: [name/title]
- Custodians and non-custodial sources: [users, teams, sites, OneDrives]
- Conversation types: [1:1, group, meeting, standard/private/shared channel]
- Date range and timezone: [inclusive range and zone]
- Privilege/privacy restrictions: [approved handling instructions]
- Export recipient and disposition: [authorized recipient, retention, deletion]
Step 1: Verify Access and Licensing
- In the Microsoft Purview portal, confirm that the operator has only the eDiscovery roles required for case management, hold, search, review, and export. Global Administrator is not the routine operating role.
- Confirm the licenses available to the users and investigators. Premium-feature access affects custodians, collections, review sets, conversation reconstruction, analytics, and other workflow options.
- Open the eDiscovery solution, select Cases, and create or open the authorized case. Record case membership before adding sources.
Microsoft's current eDiscovery permissions reference separates case, hold, review, and export capabilities. Review access after the matter ends.
Step 2: Preserve Authorized Sources
- Do not place a hold based only on an IT request. Obtain the authorized preservation instruction and scope.
- In the case, open Hold policies, create the policy, add the approved Exchange, OneDrive, SharePoint, team, or group sources, and apply any approved condition filters.
- Apply the hold and wait for processing. Verify every source's hold status and retain the hold report or process record. Investigate failed or missing sources before collection.
- Record other preservation controls that may apply, including retention policies, retention labels, Litigation Hold, delay holds, or inactive mailboxes.
An eDiscovery hold preserves in-scope content, but content owners can generally continue to modify or delete the live original; preserved copies are retained in the applicable hidden preservation location. Hold behavior varies by workload. See Microsoft's hold-management guidance. Do not state that a hold blocks all user modification.
Step 3: Search, Collect, and Validate Context
- Create a search or collection inside the case. Select the approved sources explicitly; include file locations when attachments, recordings, or transcripts are required.
- Document the KeyQL query and condition builder settings. Microsoft documents
kind:im AND kind:microsoftteamsfor narrowing certain searches to Teams chat compliance records, but operators must test current syntax and results in their tenant. - Generate statistics or preview permitted results before export. Compare source counts, date distribution, errors, and unindexed items with the request.
- Do not assume that searching both users returns only messages between those two users. It can include their other conversations. For a specific chat, collect an appropriately scoped set into a review set, organize Teams conversations, and validate participant and conversation metadata.
- Sample the beginning, middle, and end of the date range. Check timezone, participants, replies, edits, reactions, attachments, duplicate compliance copies, and gaps.
Microsoft explains conversation reconstruction and HTML transcript behavior in Review Microsoft Teams content in a review set. Culling decisions remain the responsibility of the authorized investigation team.
Step 4: Export and Record Evidence
- Choose direct search export or review-set export according to the approved delivery need. Export formats depend on source, workflow, and selected options; do not promise a fixed PST, HTML, or JSON package.
- Record export settings, operator, start/end time, item and location counts, errors, and warnings. Download the process reports with the content.
- Use the Items report and internal metadata to verify original timestamps. Local ZIP extraction tools can change filesystem dates.
- Hash the received package using the organization's approved method, restrict access, encrypt transfer where required, and obtain a recipient receipt.
- Keep any PDF or readability conversion as a derivative linked to the retained native export and process reports.
Evidence Checklist
- ☐ Written matter authority, scope, custodians, sources, dates, timezone, and handling restrictions.
- ☐ Case membership and eDiscovery role/license record.
- ☐ Hold policy, source list, successful status, failures, and approval.
- ☐ Search/collection query, settings, statistics, locations, and unindexed-item treatment.
- ☐ Review-set validation of the requested conversations and participant context.
- ☐ Export settings, Summary, Settings, Locations, Items, errors, and warning reports as generated.
- ☐ Package hash, operator, secure transfer record, recipient, and disposition instruction.
- ☐ Closed-case access review and documented hold release when authorized.
Limitations and North Brook Vault Boundary
Results depend on when content existed, applicable retention or holds, source configuration, account state, guest or cross-tenant context, indexing, licensing, query design, and export choices. A deleted account does not create one universal 30-day outcome: held or inactive mailbox content, prior exports, archives, and other approved sources can change what remains available. Conversely, neither Purview nor a backup can recover content that the relevant system never captured.
North Brook Vault is not an eDiscovery or legal-hold system. It does not export Teams content to PST, PDF, ZIP, or a legal-discovery package, and it does not restore Teams chat messages, channel messages, channel structure, or meeting transcripts. Backup data should not be called the "only path" without checking Purview, holds, inactive sources, prior collections, and approved archives. See the Teams export method guide, Teams backup capability guide, and retention control guide.