Docs / Obsidian Mail Server / Compliance
eDiscovery
eDiscovery finds mail for legal cases, investigations and information requests, keeps it from being destroyed, and hands it over. It is Exchange's In-Place eDiscovery (Microsoft Purview eDiscovery Standard). Work happens in cases under eDiscovery.
Who can use it
Global and organization administrators, and people with the Discovery manager role (see Administrators). Discovery managers can search and export anyone's mail, so give the role only to the people handling cases; they can look at the rest of the admin center but change nothing there.
Every search, every message opened or downloaded, and every export is recorded in Change history.
A case, step by step
- Open a case: eDiscovery > New case, with a name and, if you like, a reference.
- Search: New search, then choose:
- Where: all mailboxes, or chosen people, shared mailboxes and groups (a group means its members).
- Include online archives and Include deleted and held mail (Recoverable Items: what people deleted
in the last 14 days, and everything holds kept). Both are on by default.
- What: the same search as for holds: keywords (
(merger OR acquisition) -newsletter,"exact phrase",
contract*,subject:,from:,to:,attachment:), senders, people involved, dates and attachments. Keywords are searched in the text of messages and of their attachments (text, HTML, CSV, Word, Excel, PowerPoint). An empty search finds everything in the chosen mailboxes. - The search runs in the background; the page shows how many items were found in which mailbox. Click a mailbox to see only its items, or Show results for all of them. Click a result to read it; Original (.eml) downloads it.
- Keep it: Hold what matches places a hold with the same search on the same mailboxes, so nothing that matches can be destroyed from now on (a hold on all mailboxes covers the mailboxes that exist at that moment).
- Hand it over: Export downloads a ZIP with one
.emlfile per message, arranged by mailbox and folder, plus:manifest.csv: where each message was found, its date, sender, subject, size and SHA-256 hash, so anyone
can check later that the files were not changed;
summary.txt: the case, what was searched, when and by whom, and the counts.
- Close the case when it is over: its holds turn off, and its searches stay readable and exportable. A closed case can be reopened, or deleted with everything in it.
Good to know
- What a search found can still be exported after the mail is deleted, until the search or its case is deleted.
- Change and search again runs a search again with new settings; its old results are replaced.
- Items that could not be read (for example damaged messages) are counted as could not be searched; they are not in the results.
- Calendar items, contacts and tasks are found by their subject; they export as a short message naming the folder.
- Searching many large mailboxes takes a while; the page updates by itself.
From the command line
oms ediscovery cases <org>
oms ediscovery search <org> "<case>" "<search name>" [--keywords "..."] [--from a,@domain] [--mailboxes a,b | --all]
oms ediscovery export <search-id> <file.zip>