Legal & eDiscovery

Microsoft Teams eDiscovery with Purview: Current Runbook

Published Jul 26, 20268 min readBy Audit Lead

Direct answer: use the current Microsoft Purview portal to create a case, preserve sources when authorized, search or collect Teams compliance records and related files, validate conversations in a review set when context matters, and export content with its process reports. Do not use retired Core, Standard, Premium, or classic Content Search navigation. Microsoft retired the classic experiences on August 31, 2025.

This runbook is operational guidance, not legal advice. Counsel or another authorized legal owner decides whether a duty to preserve exists, which custodians and sources are in scope, what may be collected, and how evidence is handled. Purview features and reports can support a documented process; they do not establish completeness, authenticity, admissibility, privilege treatment, or a legal conclusion.

Source Decision Table

Teams contenteDiscovery source to evaluateRelated filesValidation owner
1:1 and group chatsExchange compliance records captured for chat participantsUsually the sharer's OneDriveeDiscovery operator
Standard channel messagesCompliance records associated with the team/groupTeam SharePoint siteTeams and eDiscovery operators
Private channel messagesMailboxes of private-channel members included according to current Microsoft guidanceDedicated channel SharePoint siteTeams and eDiscovery operators
Shared channel messagesSystem source associated with the shared channel; cross-tenant context may matterDedicated channel SharePoint siteTeams and legal owners
Meeting chatChat participant compliance recordsShared files in OneDrive or SharePoint according to contexteDiscovery operator
Meeting recording and transcriptOrganizer's OneDrive and the meeting's applicable sourcesRecording/transcript files and metadataMeeting owner and eDiscovery operator

Teams message data remains in the Teams service, which Microsoft documents as Azure Cosmos DB. Exchange Online stores hidden compliance records captured for eDiscovery; Purview does not search the live Teams message store. That distinction affects duplication, context, and what a user sees in Teams versus an eDiscovery result. Use Microsoft's current Teams content-location table for source selection rather than assuming every channel has a mailbox that an operator should locate manually.

Case and Owner Fields

Step 1: Verify Access and Licensing

  1. In the Microsoft Purview portal, confirm that the operator has only the eDiscovery roles required for case management, hold, search, review, and export. Global Administrator is not the routine operating role.
  2. Confirm the licenses available to the users and investigators. Premium-feature access affects custodians, collections, review sets, conversation reconstruction, analytics, and other workflow options.
  3. Open the eDiscovery solution, select Cases, and create or open the authorized case. Record case membership before adding sources.

Microsoft's current eDiscovery permissions reference separates case, hold, review, and export capabilities. Review access after the matter ends.

Step 2: Preserve Authorized Sources

  1. Do not place a hold based only on an IT request. Obtain the authorized preservation instruction and scope.
  2. In the case, open Hold policies, create the policy, add the approved Exchange, OneDrive, SharePoint, team, or group sources, and apply any approved condition filters.
  3. Apply the hold and wait for processing. Verify every source's hold status and retain the hold report or process record. Investigate failed or missing sources before collection.
  4. Record other preservation controls that may apply, including retention policies, retention labels, Litigation Hold, delay holds, or inactive mailboxes.

An eDiscovery hold preserves in-scope content, but content owners can generally continue to modify or delete the live original; preserved copies are retained in the applicable hidden preservation location. Hold behavior varies by workload. See Microsoft's hold-management guidance. Do not state that a hold blocks all user modification.

Step 3: Search, Collect, and Validate Context

  1. Create a search or collection inside the case. Select the approved sources explicitly; include file locations when attachments, recordings, or transcripts are required.
  2. Document the KeyQL query and condition builder settings. Microsoft documents kind:im AND kind:microsoftteams for narrowing certain searches to Teams chat compliance records, but operators must test current syntax and results in their tenant.
  3. Generate statistics or preview permitted results before export. Compare source counts, date distribution, errors, and unindexed items with the request.
  4. Do not assume that searching both users returns only messages between those two users. It can include their other conversations. For a specific chat, collect an appropriately scoped set into a review set, organize Teams conversations, and validate participant and conversation metadata.
  5. Sample the beginning, middle, and end of the date range. Check timezone, participants, replies, edits, reactions, attachments, duplicate compliance copies, and gaps.

Microsoft explains conversation reconstruction and HTML transcript behavior in Review Microsoft Teams content in a review set. Culling decisions remain the responsibility of the authorized investigation team.

Step 4: Export and Record Evidence

  1. Choose direct search export or review-set export according to the approved delivery need. Export formats depend on source, workflow, and selected options; do not promise a fixed PST, HTML, or JSON package.
  2. Record export settings, operator, start/end time, item and location counts, errors, and warnings. Download the process reports with the content.
  3. Use the Items report and internal metadata to verify original timestamps. Local ZIP extraction tools can change filesystem dates.
  4. Hash the received package using the organization's approved method, restrict access, encrypt transfer where required, and obtain a recipient receipt.
  5. Keep any PDF or readability conversion as a derivative linked to the retained native export and process reports.

Evidence Checklist

Limitations and North Brook Vault Boundary

Results depend on when content existed, applicable retention or holds, source configuration, account state, guest or cross-tenant context, indexing, licensing, query design, and export choices. A deleted account does not create one universal 30-day outcome: held or inactive mailbox content, prior exports, archives, and other approved sources can change what remains available. Conversely, neither Purview nor a backup can recover content that the relevant system never captured.

North Brook Vault is not an eDiscovery or legal-hold system. It does not export Teams content to PST, PDF, ZIP, or a legal-discovery package, and it does not restore Teams chat messages, channel messages, channel structure, or meeting transcripts. Backup data should not be called the "only path" without checking Purview, holds, inactive sources, prior collections, and approved archives. See the Teams export method guide, Teams backup capability guide, and retention control guide.

Validate supported Teams backup scope