Microsoft Purview eDiscovery legacy solutions

Caution

Microsoft retired all classic eDiscovery experiences on August 31, 2025. This retirement includes classic Content Search, classic eDiscovery (Standard).

The guidance in this article only applies to organizations hosted in Microsoft 365 operated by 21Vianet (China).

Electronic discovery, or eDiscovery, is the process of identifying and delivering electronic information that can be used as evidence in legal cases. You can use eDiscovery tools in Microsoft Purview to search for content in Exchange Online, OneDrive for Business, SharePoint Online, Microsoft Teams, Microsoft 365 Groups, and Viva Engage teams. You can search mailboxes and sites in the same eDiscovery search, and then export the search results. You can use Microsoft Purview eDiscovery (Standard) cases to identify, hold, and export content found in mailboxes and sites.

eDiscovery solutions

Microsoft Purview provides three eDiscovery solutions: Content search, eDiscovery (Standard).

Content Search eDiscovery (Standard)
- Search for content
- Keyword queries and search conditions
- Export search results
- Role-based permissions
- Search and export
- Case management
- Legal hold
  • Content search. Use the Content search tool to search for content across Microsoft 365 data sources and then export the search results to a local computer.
  • eDiscovery (Standard). eDiscovery (Standard) builds on the basic search and export functionality of Content search by enabling you to create eDiscovery cases and assign eDiscovery managers to specific cases. eDiscovery managers can only access the cases of which they're members. eDiscovery (Standard) also lets you associate searches and exports with a case and lets you place an eDiscovery hold on content locations relevant to the case.

Comparison of key capabilities

The following table compares the key capabilities available in Content search, eDiscovery (Standard).

Capability Content search eDiscovery (Standard)
Search for content Supported. Supported.
Keyword queries and search conditions Supported. Supported.
Search statistics Supported. Supported.
Export search results Supported. Supported.
Role-based permissions Supported. Supported.
Case management Supported.
Place content locations on legal hold Supported.
Custodian management
Legal hold notifications
Advanced indexing
Error remediation
Review sets
Support for cloud attachments and SharePoint versions
Optical character recognition
Conversation threading !
Collection statistics and reports
Review set filtering
Tagging
Analytics
Predictive coding models
Computed document metadata
Transparency of long-running jobs
Export to customer-owned Azure Storage location

Here's a description of each eDiscovery capability.

  • Search for content. Search for content that's stored in Exchange mailboxes, OneDrive for Business accounts, SharePoint sites, Microsoft Teams, Microsoft 365 Groups, and Viva Engage Teams. This includes content generated by other Microsoft 365 apps that store data in mailboxes and sites.
  • Keyword queries and search conditions. Create Keyword Query Language (KeyQL) search queries to search for content keywords that match query criteria. You can also include conditions to narrow the scope of your search.
  • Search statistics. After you run a search, you can view statistics of the estimated search results, such as the number and total size of items matching your search criteria. Other statistics include the top content locations that contain search results and the number of items that match different parts of the search query.
  • Export search results. Export search results to a local computer in your organization in a two-step process. When you export search results, items are copied from their original content location in Microsoft 365 to a Microsoft-provided Azure Storage location. Then you can download those items to a local computer.
  • Role-based permissions. Use role-based access control (RBAC) permissions to control what eDiscovery-related tasks that different users can perform. You can use a built-in eDiscovery-related role group or create custom role groups that assign specific eDiscovery permissions.
  • Case management. eDiscovery cases in eDiscovery (Standard) lets you associate specific searches and exports with a specific investigation. You can also assign members to a case to control who can access the case and view the contents of the case.
  • Place content locations on legal hold. Preserve content relevant to your investigation by placing a legal hold on the content locations in a case. This lets you secure electronically stored information from inadvertent (or intentional) deletion during your investigation.
  • Custodian management. Manage the people that you've identified as people of interest in the case (called custodians) and other data sources that may not be associated with a custodian. When you add custodians and non-custodial data sources to a case, you can place a legal hold on these data sources, communicate with custodians by using the legal hold notification process, and search custodian and non-custodial data sources to collect content relevant to the case.
  • Legal hold notifications. Manage the process of communicating with case custodians. A legal hold notification instructs custodians to preserve content that's relevant to the case. You can track the notices that were received, read, and acknowledged by custodians.
  • Advanced indexing. When you add custodial and non-custodian data sources to a case, the associated content locations are reindexed in a process called Advanced indexing. Advanced indexing ensures any content deemed as partially indexed is reprocessed to make it fully searchable when you collect data for an investigation.
  • Review sets. Add relevant data to a review set. A review set is a secure, Microsoft-provided Azure Storage location in the Azure cloud. When you add data to a review set, the collected items are copied from their original content location to the review set. Review sets provide a static, known set of content that you can search, filter, tag, analyze, and predict relevancy using predictive coding models. You can also track and report on what content gets added to the review set.
  • Support for cloud attachments and SharePoint versions. When you add content to a review set, you have the option to include cloud attachments or linked files. This means that the target file of a cloud attachment or linked file is added to the review set. You also have the option to add all versions of a SharePoint document to a review set.
  • Optical character recognition (OCR). When content is added to a review set, OCR functionality extracts text from images, and includes the image text with the content that's added to a review set. This lets you search for image text when you query the content in the review set.
  • Conversation threading. When chat messages from Teams and Viva Engage conversations are added to a review set, you can collect the entire conversation thread. This means that the entire chat conversation that contains items that match the collection criteria is added to the review set. This lets you review chat items in the context of the back-and-forth conversation.
  • Collection statistics and reports. After you create a collection estimate or commit a collection to a review set, you can view a rich set of statistics on the retrieved items, such as the content locations that contain the most items that matched the search criteria and the number of items returned by the search query. You can also preview a subset of the results.
  • Review set filtering. After content is added to a review set, you can apply filters to display only the set of items that match your filtering criteria. Then you can save the filter sets as a query, which lets you quickly reapply the saved filters. Review set filtering and saved queries help you quickly select content items that are most relevant to your investigation.
  • Tagging. Tags also help you omit non-relevant content and identify the most relevant content. When experts, attorneys, or other users review content in a review set, their opinions related to the content can be captured by using tags. For example, if the intent is to exclude unnecessary content, a user can tag documents with a tag such as "non-responsive". After content has been reviewed and tagged, a review set query can be created to exclude any content tagged as "non-responsive". This process eliminates the non-responsive content from subsequent steps in the eDiscovery workflow.
  • Predictive coding models. Use predictive coding models to reduce large volumes of case content to a relevant set of items that you can prioritize for review. This is accomplished by creating and training your own predictive coding models that help you prioritize the review of the most relevant items in a review set. The system uses the training to apply prediction scores to every item in the review set. This lets you filter items based on the prediction score, which allows you to review the most relevant (or non-relevant) items first.
  • Export to customer-owned Azure Storage location. When you export documents from a review set, you have the option to export them to an Azure Storage account managed by your organization.

eDiscovery roadmap

To see what eDiscovery features have been launched, are rolling out, or in development, see the Microsoft 365 Roadmap.

Training

Training your IT administrators, eDiscovery managers, and compliance investigation teams in the basics for Content search, eDiscovery (Standard) can help your organization get started more quickly using Microsoft Purview eDiscovery tools.