Obsidian SuiteDocumentation
Obsidian Mail Server: all chapters

Docs / Obsidian Mail Server / Compliance

Retention policies

Retention policies decide how long mail is kept: Deleted Items emptied after 30 days, mail older than two years moved to the online archive, everything deleted after seven years, and so on. They are Exchange's messaging records management (MRM). Set them up under Retention policies. The retention assistant applies them every hour; Apply now runs it at once.

The quick start

On a new server, Create the standard policy sets up Exchange's Default MRM Policy and makes it the default for everyone:

  • Deleted Items and Junk Email are emptied after 30 days. The mail stays recoverable for 14 more days (see Recover deleted items in webmail).
  • Mail older than 2 years moves to the online archive, for people who have one (see Users). Without archiving leaves this out.
  • People can pick personal tags for their own folders and messages: 1 Week Delete, 1 Month Delete, 6 Month Delete, 1 Year Delete, 5 Year Delete, Never Delete, and archive after 1 year, 5 years or never.

Tags

A tag says what happens to a message after it has been kept a while, counted from when it arrived:

ActionWhat happens
Delete (recoverable)The message moves to Recoverable Items, where the person or an administrator can restore it for 14 days
Delete permanentlyThe message is removed at once
Move to the online archiveThe message moves to the same folder in the person's online archive

A tag's period can also be never: a Never Delete tag on a folder keeps its mail whatever the default says.

Tags come in three kinds:

KindApplies to
All mail (default)Every message without another tag. A policy can have one that deletes and one that archives.
One default folderInbox, Sent Items, Deleted Items, Junk Email, Drafts, Calendar... and its subfolders. Folder tags delete; they do not archive.
People choose (personal)Tags people put on their own folders or messages in webmail (Assign policy).

Tags do nothing until they are in a policy. Turning a tag off (Tag is in use unchecked) stops it everywhere.

Which tag wins

For each message, the first of these that exists decides when it is deleted:

  1. A personal tag on the message itself.
  2. A personal tag on its folder, or on a folder above it.
  3. The folder tag of the default folder it is in (for example Deleted Items).
  4. The policy's default tag.

Moving to the archive works the same way with archive tags (steps 1, 2 and 4). When a message is due for both, it is deleted. Mail in the online archive keeps its tags, and deletion tags go on applying there.

Recoverable Items is never touched by tags: it has its own 14-day deleted-item retention.

Policies

A policy is a set of tags. The default policy applies to every mailbox without a policy of its own; a person's page in Users & groups has a Retention card to choose another policy.

Mailboxes

  • Retention hold (on the person's Retention card) pauses the assistant for that mailbox, for example while someone is on long leave and cannot look after their mail. Nothing is deleted or archived until it is turned off.
  • Retention runs as the server, so its deletions do not appear in the mailbox audit log.

What people see

In webmail, a message shows when it will be deleted or archived and why ("Deleted on 3 March 2028, 1 Year Delete, from the folder"). Assign policy in the message toolbar and Folder policy above the message list apply personal tags; Folder policy clears a message's own tag so it follows its folder again.

From the command line

oms retention list <org>
oms retention standard <org> [--archive-years 2 | --no-archive]
oms retention mailbox <address> <policy-name|default> [--hold | --no-hold]
oms retention run [<org>]