Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Identify and
Preserve
Search and
Process
Review Produce
eDiscovery Overview
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Quick Investigation
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Advantages: in-place, real time, more content
Capabilities: In-Place Hold, Query, and Export
Exchange Admin Center
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
1. In-Place Hold
In-Place Hold
1. In-Place Hold
ItemUpdated
ItemDeleted
Site on in-place
hold?
Allow Item Edit/
Delete to Complete
No
Yes
Placecurrent
version in
preservation hold
library.
Last modified date older
than preservation date?
Site on in-place
hold?
Yes
Yes
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Query Based
Preservation Feature
enabled?
Site on in-place
hold?
End
No
Yes No Keep Item
Does item match union of
hold search queries?
Does item have search
indexing errors?
No
Yes
NoDelete Item
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
User A Mailbox
Recoverable Items
Deletions
Inbox
Purges
Versions
Audits
Deleted Items
…
DiscoveryHold
Calendar Logging
(6a) Messages purged by
DIRW Policy (or
maintained for Litigation
Hold)
(5) Message Edited
(3) Message deleted
(4a) Message “purged”
by user (Litigation Hold /
Single Item Recovery)
Lifecycle
of
mailbox
items (4b) Message “purged”
by user (In-Place Hold)
(6c) MFA evaluates item
against hold queries set on
mailbox
(6b) Mailboxes with SIR
and In-Place Hold enabled
have expired messages
moved
(1) Message
delivered
(2) Message
moved to
Deleted Items
Mailbox on in-place
hold?
End
No
Yes
Keep Item
Does item match union of
hold search queries?
Does item have search
indexing errors?
No
Yes
NoDelete Item
Lync archives content into Exchange mailboxes when user is on In-Place Hold
Includes instant messaging and meeting content
In-Place Hold, eDiscovery, MRM of Lync data consolidated to Exchange tools
Lync 2010 Exchange 2010
Compliance
Archive
Compliance
New Lync New Exchange
Single In-Place data store for Exchange & Lync compliance
User A Mailbox
Recoverable Items
Deletions
Deleted Items
Inbox
Versions
Purges
DiscoveryHolds
Server side archiving
All Lync modalities
captured (PC, mobile,
web, OWA)
User A on hold
2. Query
Query
2. Query
Exchange
Sharepoint Farm 1 Hub
eDiscovery Center
SSA
Proxy
Search Service Application
Services Farm
Search
service
Cases
Sources
Queries
eDiscovery Sets
Exports
Query
Actions
Interface
Exchange
Web
Services
Hold
ReleaseHold
GetStatus
MailboxCopy
SharePoint Farm 2
Timer
job
SSA Proxy
Fed Query
USE TO EXAMPLE
AND Find content that contains all of the words or
phrases it separates.
risk and value and VAR finds content that
contains all three words.
OR Find content that contains either of the words
or phrases it separates.
risk OR VAR finds all the content that contains
either word.
NOT Exclude content that contains the term within
a phrase.
Executive NOT Summary finds all the content
that contains the phrase Executive, unless the
content also contains the term Summary.
( ) Group words or phrases to show the order in
which they are applied.
(Risk AND management) OR (VAR or Value-
at-risk)
NEAR(n) Finds words that are near each other, where n
equals the number of words apart. If no
number is specified, the default distance is 8
words.
Mid Near(5) Office finds Mid and Back Office
and Mid-Office and Mid, Back, and Front
Office.
“ “ Search for specific phrases. “risk management” finds the exact phrase
* at the end of
word
Find terms that contain the root word and
any additional letters.
risk* finds risk, risks, risked, risking, and risky
KEYWORDS EXAMPLE RESULTS
“Executive Briefing” Any content that contains the words “Executive
Briefing” together, anywhere in the document, page, or
message.
“Executive Briefing” AND “Executive Summary” Any content that contains the words “Executive
Briefing” together, anywhere in the document, page, or
message, or any content that contains the words
“Executive Summary” together.
filename:budget Any file with budget in its filename, such as 2014
budget projections.docx, 2015 budget priorities.pptx,
2014 budget planning.xlsx, 2014 budget review.xlsx,
and so on
filename:2014 budget filetype:xlsx Excel worksheets that contain the phrase 2014 budget,
such as “2014 budget planning.xlsx” and “2014 budget
review.xlsx”
NEAR(n)
Auditing
3. Export
Export
3. Export
Export Client
Export Data
Query
Download
Exchange
Sharepoint Farm 1 Hub
eDiscovery Center
SSA
Proxy
Search Service Application
Services Farm
Search
service
Cases
Sources
Queries
eDiscovery Sets
Exports
Query
Actions
Interface
Exchange
Web
Services
Discovery Web
Service
Hold
ReleaseHold
GetStatus
MailboxCopy
SharePoint Farm 2
Timer
job
SSA
Fed
Fed
Query
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Internals of eDiscovery for Office 365, Exchange, and Sharepoint
Internals of eDiscovery for Office 365, Exchange, and Sharepoint

More Related Content

PDF
Converis presentation: ORCID and CRIS webinar December 2014
ODP
2014 CrossRef Annual Meeting Flash Update: CrossRef Metadata Search
PDF
Pure presentation: ORCID and CRIS webinar December 2014
PDF
CrossRef Annual Meeting 2012 ORCID Laure Haak
PPTX
Overview of eDiscovery in Sharepoint, Exchange, Lync and Office 365
PDF
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
PDF
E Discovery and Archiving in Microsoft Office 365 - Presented by Atidan
PPTX
Information Governance and ediscovery in office 365 ediscovery deep dive
Converis presentation: ORCID and CRIS webinar December 2014
2014 CrossRef Annual Meeting Flash Update: CrossRef Metadata Search
Pure presentation: ORCID and CRIS webinar December 2014
CrossRef Annual Meeting 2012 ORCID Laure Haak
Overview of eDiscovery in Sharepoint, Exchange, Lync and Office 365
Microsoft Exchange 2013 archiving, e discovery, compliance and data loss prev...
E Discovery and Archiving in Microsoft Office 365 - Presented by Atidan
Information Governance and ediscovery in office 365 ediscovery deep dive

Viewers also liked (12)

PPTX
Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...
DOCX
Security and Compliance In Microsoft Office 365 Whitepaper
PPTX
SharePoint Saturday NL 2016 - Security & Compliance
PPTX
Security and Compliance for Exchange Online in Office 365
PPSX
Robert Brzezinski - Office 365 Security & Compliance: Cloudy Collaboration......
PPTX
Office 365 in Focus. Security and Governance Strategies from the Experts - We...
PDF
Learning about Security and Compliance in Office 365
PPTX
Protecting Your Data In Office 365
PPTX
Intelligent Security, Compliance and Privacy in Office 365
PPTX
Office 365 security concerns, EU General Data Protection Regulation (GDPR)
PPTX
Office 365 ediscovery fr
PDF
How to Become a Thought Leader in Your Niche
Edge pereira oss304 tech ed australia regulatory compliance and microsoft off...
Security and Compliance In Microsoft Office 365 Whitepaper
SharePoint Saturday NL 2016 - Security & Compliance
Security and Compliance for Exchange Online in Office 365
Robert Brzezinski - Office 365 Security & Compliance: Cloudy Collaboration......
Office 365 in Focus. Security and Governance Strategies from the Experts - We...
Learning about Security and Compliance in Office 365
Protecting Your Data In Office 365
Intelligent Security, Compliance and Privacy in Office 365
Office 365 security concerns, EU General Data Protection Regulation (GDPR)
Office 365 ediscovery fr
How to Become a Thought Leader in Your Niche
Ad

Similar to Internals of eDiscovery for Office 365, Exchange, and Sharepoint (20)

PPTX
eDiscovery in SharePoint 2013 - DIWUG
PPTX
Haystack 2018 - Algorithmic Extraction of Keywords Concepts and Vocabularies
PPT
Oops Concepts
PPT
Classification, Tagging & Search
PPT
Lit Reviews for the Health Sciences
PPT
RefWorks Advanced Search And Lookups
 
PDF
Joseph Busch - Ai vs automation workshop
PPTX
Important SAS Tips and Tricks for A Grade
PPTX
Planning and writing assignments (arts example)
PDF
Python Namespace.pdf
PDF
Scoping Level of Effort and Getting the Right Resources for the Job
PDF
IR with lucene
PPTX
Creativity vs Best Practices
ODP
The search engine index
PPT
Using metadata repositories with search
PPTX
Planning and writing assignments (business example)
PDF
M.c.a (sem iii) paper - i - object oriented programming
PPTX
Empowering the business for eDiscovery in Office 365 - BRK2112
PPT
Step by step search process for Research Ethics
PDF
Part 1.2 Understanding the relevance of your search with Elasticsearch and Ki...
eDiscovery in SharePoint 2013 - DIWUG
Haystack 2018 - Algorithmic Extraction of Keywords Concepts and Vocabularies
Oops Concepts
Classification, Tagging & Search
Lit Reviews for the Health Sciences
RefWorks Advanced Search And Lookups
 
Joseph Busch - Ai vs automation workshop
Important SAS Tips and Tricks for A Grade
Planning and writing assignments (arts example)
Python Namespace.pdf
Scoping Level of Effort and Getting the Right Resources for the Job
IR with lucene
Creativity vs Best Practices
The search engine index
Using metadata repositories with search
Planning and writing assignments (business example)
M.c.a (sem iii) paper - i - object oriented programming
Empowering the business for eDiscovery in Office 365 - BRK2112
Step by step search process for Research Ethics
Part 1.2 Understanding the relevance of your search with Elasticsearch and Ki...
Ad

More from Quentin Christensen (12)

PPTX
Overview of Compliance in SharePoint, Exchange, and Office 365
PPTX
Take the fud out of implementing share point
PPTX
Personal and team development models
PPTX
User Experience 101
PPTX
SharePoint 2013 Records Management and eDiscovery
PPTX
Private Equity: Managing Organizations Like the Pros
PPTX
PowerPoint on PowerPoints
PPTX
Market based management: getting results from your organization
PPTX
Hiring Talent: Interviewing to Find the Right People
PPTX
Guerilla Human Computer Interaction and Customer Based Design
PPTX
Authoring Software Product Guidance and Documentation
PPTX
Database information architecture
Overview of Compliance in SharePoint, Exchange, and Office 365
Take the fud out of implementing share point
Personal and team development models
User Experience 101
SharePoint 2013 Records Management and eDiscovery
Private Equity: Managing Organizations Like the Pros
PowerPoint on PowerPoints
Market based management: getting results from your organization
Hiring Talent: Interviewing to Find the Right People
Guerilla Human Computer Interaction and Customer Based Design
Authoring Software Product Guidance and Documentation
Database information architecture

Recently uploaded (20)

PDF
CCleaner 6.39.11548 Crack 2025 License Key
PPTX
Introduction to Windows Operating System
PDF
AI/ML Infra Meetup | Beyond S3's Basics: Architecting for AI-Native Data Access
PPTX
Cybersecurity: Protecting the Digital World
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
PDF
DNT Brochure 2025 – ISV Solutions @ D365
PDF
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
PDF
How to Make Money in the Metaverse_ Top Strategies for Beginners.pdf
PDF
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
PDF
Designing Intelligence for the Shop Floor.pdf
PDF
AI Guide for Business Growth - Arna Softech
PDF
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
PDF
Wondershare Recoverit Full Crack New Version (Latest 2025)
PDF
iTop VPN Crack Latest Version Full Key 2025
PDF
MCP Security Tutorial - Beginner to Advanced
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
DOCX
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
PPTX
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
PPTX
GSA Content Generator Crack (2025 Latest)
PPTX
assetexplorer- product-overview - presentation
CCleaner 6.39.11548 Crack 2025 License Key
Introduction to Windows Operating System
AI/ML Infra Meetup | Beyond S3's Basics: Architecting for AI-Native Data Access
Cybersecurity: Protecting the Digital World
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
DNT Brochure 2025 – ISV Solutions @ D365
AI-Powered Threat Modeling: The Future of Cybersecurity by Arun Kumar Elengov...
How to Make Money in the Metaverse_ Top Strategies for Beginners.pdf
DuckDuckGo Private Browser Premium APK for Android Crack Latest 2025
Designing Intelligence for the Shop Floor.pdf
AI Guide for Business Growth - Arna Softech
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
Wondershare Recoverit Full Crack New Version (Latest 2025)
iTop VPN Crack Latest Version Full Key 2025
MCP Security Tutorial - Beginner to Advanced
Advanced SystemCare Ultimate Crack + Portable (2025)
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
AMADEUS TRAVEL AGENT SOFTWARE | AMADEUS TICKETING SYSTEM
GSA Content Generator Crack (2025 Latest)
assetexplorer- product-overview - presentation

Internals of eDiscovery for Office 365, Exchange, and Sharepoint

  • 7. Advantages: in-place, real time, more content Capabilities: In-Place Hold, Query, and Export
  • 13. ItemUpdated ItemDeleted Site on in-place hold? Allow Item Edit/ Delete to Complete No Yes Placecurrent version in preservation hold library. Last modified date older than preservation date? Site on in-place hold? Yes Yes
  • 15. Query Based Preservation Feature enabled? Site on in-place hold? End No Yes No Keep Item Does item match union of hold search queries? Does item have search indexing errors? No Yes NoDelete Item
  • 17. User A Mailbox Recoverable Items Deletions Inbox Purges Versions Audits Deleted Items … DiscoveryHold Calendar Logging (6a) Messages purged by DIRW Policy (or maintained for Litigation Hold) (5) Message Edited (3) Message deleted (4a) Message “purged” by user (Litigation Hold / Single Item Recovery) Lifecycle of mailbox items (4b) Message “purged” by user (In-Place Hold) (6c) MFA evaluates item against hold queries set on mailbox (6b) Mailboxes with SIR and In-Place Hold enabled have expired messages moved (1) Message delivered (2) Message moved to Deleted Items
  • 18. Mailbox on in-place hold? End No Yes Keep Item Does item match union of hold search queries? Does item have search indexing errors? No Yes NoDelete Item
  • 19. Lync archives content into Exchange mailboxes when user is on In-Place Hold Includes instant messaging and meeting content In-Place Hold, eDiscovery, MRM of Lync data consolidated to Exchange tools Lync 2010 Exchange 2010 Compliance Archive Compliance New Lync New Exchange Single In-Place data store for Exchange & Lync compliance
  • 20. User A Mailbox Recoverable Items Deletions Deleted Items Inbox Versions Purges DiscoveryHolds Server side archiving All Lync modalities captured (PC, mobile, web, OWA) User A on hold
  • 22. Query
  • 24. Exchange Sharepoint Farm 1 Hub eDiscovery Center SSA Proxy Search Service Application Services Farm Search service Cases Sources Queries eDiscovery Sets Exports Query Actions Interface Exchange Web Services Hold ReleaseHold GetStatus MailboxCopy SharePoint Farm 2 Timer job SSA Proxy Fed Query
  • 25. USE TO EXAMPLE AND Find content that contains all of the words or phrases it separates. risk and value and VAR finds content that contains all three words. OR Find content that contains either of the words or phrases it separates. risk OR VAR finds all the content that contains either word. NOT Exclude content that contains the term within a phrase. Executive NOT Summary finds all the content that contains the phrase Executive, unless the content also contains the term Summary. ( ) Group words or phrases to show the order in which they are applied. (Risk AND management) OR (VAR or Value- at-risk) NEAR(n) Finds words that are near each other, where n equals the number of words apart. If no number is specified, the default distance is 8 words. Mid Near(5) Office finds Mid and Back Office and Mid-Office and Mid, Back, and Front Office. “ “ Search for specific phrases. “risk management” finds the exact phrase * at the end of word Find terms that contain the root word and any additional letters. risk* finds risk, risks, risked, risking, and risky
  • 26. KEYWORDS EXAMPLE RESULTS “Executive Briefing” Any content that contains the words “Executive Briefing” together, anywhere in the document, page, or message. “Executive Briefing” AND “Executive Summary” Any content that contains the words “Executive Briefing” together, anywhere in the document, page, or message, or any content that contains the words “Executive Summary” together. filename:budget Any file with budget in its filename, such as 2014 budget projections.docx, 2015 budget priorities.pptx, 2014 budget planning.xlsx, 2014 budget review.xlsx, and so on filename:2014 budget filetype:xlsx Excel worksheets that contain the phrase 2014 budget, such as “2014 budget planning.xlsx” and “2014 budget review.xlsx”
  • 32. Export Client Export Data Query Download Exchange Sharepoint Farm 1 Hub eDiscovery Center SSA Proxy Search Service Application Services Farm Search service Cases Sources Queries eDiscovery Sets Exports Query Actions Interface Exchange Web Services Discovery Web Service Hold ReleaseHold GetStatus MailboxCopy SharePoint Farm 2 Timer job SSA Fed Fed Query

Editor's Notes

  • #11: In-place hold helps you protect content that is important for legal events.
  • #18: The Deletions folder replaces the ptagDeletedOnFlag view that was displayed when a user accessed the Recover Deleted Items tool.  When a user soft deletes or performs an Outlook hard delete against an item, the item is moved to the Recoverable Items\Deletions folder.  When the user accesses Outlook/OWA Recover Deleted Items, the RPC Client Access service translates the request and returns the Recoverable Items\Deletions folder view. At this point you may be thinking, how is this any different than in previous versions of Exchange?  With short-term preservation deleted items will still be moved into the Recoverable Items folder structure.   However, the data cannot be purged until deletion timestamp is past the deleted item retention window.  Even if the end user attempts to purge the data, the data is retained.  Consider this example by a malicious user: User sends or receives a message that is legally incriminating. User deletes the message.  The message is moved to the Deleted Items folder. The user empties the deleted items folder. The user accesses the Recover Deleted Items functionality in Outlook or OWA. The user then selects the item and deletes the item.  At this point the user believes he has removed the incriminating evidence.  And this is a key strength in this work flow as the end user's actions are not interrupted or prevented; in other words, the end user's work flow is not impaired with single item recovery enabled. However, the message was not purged from the mailbox store.  Instead the message was moved from the Recoverable Items\Deletions folder to the Recoverable Items\Purges folder.  All store hard-deleted items end up in this folder when single item recovery is enabled.  The Recoverable Items\Purges folder is not visible to the end user, meaning that they do not see data retained in this folder in the Recover Deleted Items tool. When the message deletion timestamp has exceeded the deleted item retention window, Records Management will purge the item. Not only does short term preservation prevent purging of data before the deleted item retention window has expired, but it also enables versioning functionality.  Essentially when an item is changed, a copy-on-write is performed to preserve the original version of the item.  The original item is placed in the Recoverable Items\Versions folder.  This folder is not exposed to the end user.   What triggers a copy-on-write? For messages and posts (IPM.Note* and IPM.Post*), copy-on-write will capture changes in the subject, body, attachments, senders/recipients, and sent/received dates. For other types of items, copy-on-write will occur for any change to the item except for moves between folders and read/unread status changes.\ Drafts will be exempt from copy-on-write to prevent excessive copies when drafts are auto-saved.  The data stored in the Recoverable Items\Versions folder is indexed and discoverable by compliance officers.
  • #20: Conversation history will be client side archiving If user is on hold, then data will be stored in exchange With Exchange 2010, management of data was completely separate from the data stored in Lync. Lync data was stored in SQL and queries were executed to get discovery data. With Exchange 2013, the ability for you to have Lync archive all user content into Exchange user mailboxes. There is no longer a need to have a SQL database for management of compliance data. From an on-premises admin standpoint this enables you to have a unified storage model that is completely based on mailboxes. This now enables compliance officers to no longer have to manage and use two different experiences for managing Lync and Exchange data. We capture all Lync data – meetings, IM, whiteboards, transcripts, attachments, etc. All of that gets stored in the user mailbox when the mailbox is on hold.
  • #21: I have a user who is currently on hold in Exchange. Tis user participates in a meeting via Lync. The Exchange and Lync services share the attributes in code so both are aware of the fact that the user is on hold. Lync on the server side will capture the conversation or anything associated with the user’s participation in the meeting. Lync will package that up as a transcript and write that into the user’s mailbox, specifically into the Recoverable Items\Purges folder. This folder is indexed and available for discovery. Lync uses EWS to write the data. When the user is on hold, all conversation archiving happens from the server side, not from the client side. This is to ensure that there’s no repudiation of the data. By doing server side, any Lync data is preserved regardless of modality.
  • #37: The in-place approach helps you reduce costs by only retaining copies of content that changes. By leveraging the search systems of SharePoint and Exchange, you can run up to date queries any time, and we support all different types of SharePoint, Exchange, and Lync content to help you meet your eDiscovery needs.