Locating, holding, reviewing and exporting electronic information to serve as evidence in investigations or lawsuits. Microsoft Purview covers Teams, Exchange, OneDrive, SharePoint and other sources, and E5 unlocks extra premium capabilities.
Also called electronic discovery.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains eDiscovery in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Premium
Hosting plan for Azure Functions that keeps instances pre-warmed to avoid cold starts and supports VNet integration. Executions time out after 30 minutes by default, which host.json can extend.
Related terms
- A5
The highest Microsoft 365 plan for education, equivalent to E5 for schools and universities. It includes premium Purview and Defender capabilities, for example Endpoint DLP, Audit (Premium), Insider Risk Management and the premium eDiscovery features.
- Cloud attachments
Shared links to SharePoint or OneDrive documents posted in Teams, Outlook or Viva Engage, or used by Copilot. eDiscovery can pick them up, and retention labels applied automatically can save a copy of each newly shared document.
- Compliance boundaries
An eDiscovery arrangement using role groups together with search permissions filters, so each agency's eDiscovery managers only see their own agency's cases and can only search its sites, mailboxes and OneDrive accounts.
- Content search
Purview's eDiscovery tool for finding content in mailboxes, Teams, sites and Copilot interactions. Since Microsoft retired the classic version, every search sits within an eDiscovery case, which can be one the system generates.
- Copilot activity history
Every prompt a person gives Copilot is saved together with its reply and any citations, alongside other Microsoft 365 content. Users can clear theirs via My Account; admins handle it through eDiscovery searches and Purview retention.
- Double Key Encryption
Label-based encryption requiring two keys, one kept in Azure and one in the organisation's own DKE service, so Microsoft is unable to decrypt the data. Because services such as search, eDiscovery and Copilot cannot read protected content, it suits only a small amount of highly sensitive data.
- eDiscovery Manager
Members of this Purview role group can set up and run eDiscovery cases they own, including searching, holding and exporting content. eDiscovery Administrator is a subgroup of it.
- HYOK
An on-premises-held key used for encrypting content. Co-authoring, search, eDiscovery and DLP can't work on content protected like this, and Microsoft recommends Double Key Encryption as the replacement.