Docs / Obsidian Mail Server / Compliance
Holds
A hold keeps mail that may be needed as evidence, for a lawsuit, an investigation or an audit. Held mail cannot be destroyed: when the person deletes it permanently, empties Deleted Items, purges Recoverable Items, deletes a folder, or a retention policy would delete it, the mail disappears from their view but is kept, out of sight, in the mailbox's Recoverable Items\Purges folder. People are not told they are on hold. Holds are under Holds.
Litigation hold
Litigation hold keeps everything in a person's mailbox and online archive.
- Open the person in Users & groups.
- On the Litigation hold card, check On litigation hold.
- Keep mail indefinitely, or for a number of days after each message arrived (for example 2555 days, about seven years). A note records the case or reference for your colleagues.
- Save.
The Holds page lists everyone on litigation hold, since when and by whom.
Query holds
A query hold (Exchange's In-Place Hold) keeps only mail that matches a search, in the mailboxes you choose, for example everything mentioning a project, or everything from one company in a date range.
- Open Holds and choose New hold.
- Name it and add the mailboxes: people, shared mailboxes, or a group (its members as they are now).
- Describe the mail to keep. Everything you fill in must match:
- Keywords: words and
"exact phrases"must all appear;ORgives alternatives,NOT wordor-word
excludes, parentheses group:
(merger OR acquisition) -newsletter.contract*matches words starting with contract.subject:,from:,to:andattachment:look in one place only (subject:"Q3 plan"). Keywords are searched in the subject, the message text, attachment names, and the text inside attachments (text, HTML, CSV, Word, Excel, PowerPoint).- From and Sent to or from: addresses, or
@example.comfor a whole domain. - Received from / until and Attachments.
Leave everything empty to keep all mail in those mailboxes.
- Keywords: words and
- Keep matching mail indefinitely or for a number of days after each message arrived, and choose Place hold.
What holds do and do not do
- Held mail is kept when it is destroyed. Moving mail between folders, or to the online archive, is not affected; neither is reading, flagging or categorizing.
- Mail that was already destroyed before the hold was placed cannot be brought back. Place holds early.
- A mailbox on hold cannot be removed: release its holds first, so no held mail is lost by accident.
- Releasing a hold makes the mail it kept removable again: it is purged 14 days later, unless another hold still covers it.
- Changes to message flags or calendar details are not versioned; the message itself is kept.
- Searching and exporting held mail is done with eDiscovery.
From the command line
oms hold litigation <address> on [--days 2555] [--note "Case 14"]
oms hold litigation <address> off
oms hold list <org>