Compliance, Retention, Auditing, and Investigations
Compliance Manager, Communication Compliance, Information Barriers, retention, Records Management, eDiscovery, and Microsoft Purview Audit
Suggested study time: 48 minutes • Beginner level • Aligned with the SC-900 study guide and official Microsoft Learn documentation
By João Ricardo Dutra••Complete material
1. Introduction: from documentary obligation to continuous compliance
For much of corporate history, compliance meant filing documents, filling out checklists, and preparing folders for periodic audits. The digitalization of business has altered this model. Emails, messages, cloud files, meetings, identities, and administrative actions began to generate evidence at a continuous pace, making an approach based solely on manual controls and annual reviews insufficient.
The growth of data protection laws, sectoral rules, internal investigations, and litigation has also increased the need to demonstrate not only that a policy exists, but that it has been implemented, tested, monitored, and documented. In this context, compliance platforms have emerged that are capable of connecting requirements, controls, retention, auditing, and investigation.
For the reader, understanding this ecosystem helps answer practical questions: how long should a document be kept? Who changed a setting? How to preserve evidence when an investigation begins? How to prevent communication between areas with a conflict of interest? How to measure progress in relation to a standard? These decisions protect organizations, citizens, clients, and the very reliability of digital services.
Central idea
Compliance is not a permanent state. It is a continuous process of interpreting requirements, implementing controls, producing evidence, monitoring activities, and correcting deviations.
Figure 1 - The Compliance Manager organizes requirements, controls, actions, and evidence in a continuous flow.
2. Overview of Microsoft Purview compliance solutions
Microsoft Purview brings together security, compliance, risk, and data governance capabilities. In this chapter, the focus is on solutions that help assess obligations, communications, manage the information lifecycle, preserve evidence, and investigate activities.
Solution
Main question
Expected result
Compliance Manager
What requirements and actions need to be met?
Assessments, controls, evidence, improvement actions, and risk-based scoring.
Communication Compliance
Are there communications that indicate a breach of conduct or regulatory rule?
Alerts, contextual review, and corrective actions.
Information Barriers
Which groups can or cannot communicate and collaborate?
Separation between segments due to conflict of interest or confidentiality.
Data Lifecycle Management
What should be kept or eliminated and for how long?
Retention policies and labels.
Records Management
Which items require formal treatment as records?
Immutability, file plan, retention by event, and controlled disposition.
eDiscovery
Which data should be preserved, searched, reviewed, and exported?
Cases, holds, searches, review sets, and evidence packages.
Audit
Who did what, when, where, and in which service?
Searchable records for investigation, security, and compliance.
Do not confuse Compliance Manager organizes compliance posture. Retention governs the lifecycle. eDiscovery preserves and collects evidence for a case. Audit records activities. The solutions complement each other, but they are not interchangeable.
3. Microsoft Purview Compliance Manager
The Compliance Manager is a solution to assess and manage compliance in cloud and multicloud environments. It offers pre-built assessments for standards and regulations, allows custom assessments, and centralizes tracking of the work needed to reduce data protection risks and demonstrate progress.
The tool does not interpret laws on behalf of the organization nor does it replace legal experts, auditors, or risk managers. Its role is to transform abstract requirements into an operational framework: controls, actions, responsible parties, tests, evidence, notes, and status.
Fundamental elements
Regulation or standard: source of requirements, such as a law, certification, norm, or internal policy.
Regulatory model: reusable structure that maps requirements to controls and actions.
: grouping of controls applicable to a standard and the selected scope.
: requirement that defines a technical, organizational, or procedural measure.
: recommended activity to implement, test, or document a .
Evidence: documentation, capture, report, or other material that supports the conclusion about the action.
: risk-based indicator that measures progress in improvement actions.
Shared responsibility
The Compliance Manager differentiates controls managed by Microsoft, controls managed by the customer, and shared controls. This distinction follows the cloud responsibility model.
4. Evaluations, regulatory models, and controls
An is the space in which an organization monitors its position regarding a regulation, standard, or policy. It brings together controls, in-scope services, actions, scoring, and evidence. A company can maintain separate assessments for different regions, business units, or environments, as long as the structure represents the actual scope.
Regulatory models provide a reusable foundation. Some are provided by Microsoft; others can be customized for internal policies or specific requirements. The availability of models depends on licensing. In current scenarios, it is also possible to build custom models from regulatory documents, but all mapping must be reviewed by responsible experts.
Type of control
Main responsible
Conceptual example
Managed by Microsoft
Microsoft
Operation and audit of service cloud infrastructure controls.
Managed by the client
Client organization
Set internal policy, configure retention, train users, or review accesses.
Shared
Microsoft and client
Microsoft protects the platform; the customer configures and governs the use of the service.
The same can appear in several assessments. The Compliance Manager seeks to avoid artificial counting of repeated work, linking actions and controls so that progress is monitored more consistently. Even so, the organization must verify whether an implementation truly satisfies each regulatory context.
Test point
The presence of a in the catalog does not mean it has been implemented. It is necessary to assign responsibility, status, test, gather evidence, and review periodically.
5. Improvement Actions and
Improvement actions are recommended tasks that help implement controls. They can be technical, such as changing a configuration, or non-technical, such as creating a procedure, conducting training, or producing documentation. Each action can have an owner, deadline, notes, evidence, and test status.
When an action offers an automatic test, the Compliance Manager can use signals from connected services to verify if the configuration has been implemented. Automation reduces manual work, but it does not eliminate the need to validate scope, exceptions, and operational effects.
How to interpret the
The adds points for improvement actions considering risk factors and type of action. The score helps prioritize efforts, compare progress, and show areas that need attention. It starts from a data protection baseline and changes as actions are implemented and tested.
Correct interpretation
Incorrect interpretation
Progress indicator and risk-based prioritization.
Automatic certificate of legal compliance.
View that depends on the scope, actions, and registered evidence.
Proof that no requirement was violated.
Management tool to support audits and continuous improvement.
Independent auditor substitute or legal opinion.
Score that can change with product, configuration, and requirements.
Universal number comparable between companies without context.
Examination trap A high score does not guarantee compliance. It represents progress in completing recommended actions and should be interpreted within the scope of the assessment.
6.
Microsoft Purview helps detect, capture, review, and address communications that may be inappropriate or inconsistent with internal and regulatory requirements. Scenarios include sharing confidential information, offensive language, harassment, threats, conflicts of interest, and communications subject to financial market rules.
Policies can evaluate messages in supported channels, including Exchange, Teams, and other integrated services. Current features may also cover interactions with generative artificial intelligence applications, depending on connectors, licensing, and availability.
Privacy by design
Pseudonymization of user names by default in review experiences.
Role-based access to separate administration, analysis, and investigation.
Reviewers need to be explicitly defined in the policy.
Review and remediation actions are audited.
Policies must have a legitimate purpose, proportional scope, and documented governance.
Figure 2 - converts policy matches into a controlled flow of analysis and remediation.
7. Policies and investigations in
A policy defines who is in scope, which channels will be analyzed, what conditions generate a match, and what percentage of the content will be presented for review. Microsoft provides templates for common scenarios, and organizations can create custom policies.
Component
Function
Users and groups in scope
They determine which communications can be evaluated.
Channels
They define origins such as email, chat, collaboration, or connected applications.
Conditions
They can use types of confidential information, classifiers, words, domains, and other signals.
Sampling
Controls the amount of content presented for review.
Reviewers
People authorized to analyze alerts and corresponding items.
Actions
Notify, flag, document, remove messages in supported scenarios or escalate to eDiscovery.
Alerts are generated when messages meet the conditions. The reviewer analyzes the context, classifies the item, records notes, and chooses a proportional action. In more serious cases, the content may be escalated to a formal investigation in eDiscovery.
Difference for DLP
DLP controls the use and transfer of sensitive data. analyzes risks present in communications and provides a review flow for conduct or regulatory obligations. A message can trigger both solutions for different reasons.
8.
is a compliance solution that restricts communication and collaboration between groups and users. It is common in organizations subject to conflict of interest rules, segregation of duties, or the need to prevent teams involved in sensitive operations from exchanging information.
The model starts with segments defined by account attributes, such as department, location, role, or team. Next, policies such as block or allow determine which segments can interact. Once configured and activated, the policies are applied to the supported services.
Figure 3 - Segments and policies turn separation requirements into technical constraints on communication and collaboration.
Concept
Objective description
Segment
Set of users or groups defined by organizational attributes.
Blocking policy
Prevents communication between specified segments.
Permission Policy
Allows a segment to communicate only with defined segments.
Application
Process that distributes and implements policies in the services.
Organization mode
Define capabilities as support for one or multiple segments per user.
Operational principle Use the fewest number of policies necessary and test the effects. A poorly designed rule can prevent legitimate collaboration, meetings, file sharing, or people discovery.
9. Data Lifecycle Management
Microsoft Purview Data Lifecycle Management provides features to retain necessary content and eliminate content that has lost value. Retention meets regulatory, contractual, historical, and operational obligations; controlled deletion reduces cost, exposure to attacks, and liability associated with data kept without need.
Retention policies are the central mechanism for applying broad rules in workloads such as Exchange, SharePoint, OneDrive, Teams, and other supported services. Retention labels allow more granular decisions at the item level.
Possible results of a retention setup
Retain for a period and allow deletion after that period.
Retain for a period and automatically delete at the end.
Retain indefinitely as long as there is an obligation.
Delete content after a period, without requiring a minimum retention.
Start the period from creation, modification, labeling, or business event, depending on the feature. When users edit or delete content subject to retention, the service preserves a copy in a protected location. In SharePoint and OneDrive, this may involve the Preservation Library; in Exchange, the Recoverable Items area; in Teams messages and other services, hidden retention locations maintain the necessary evidence.
Retention is not backup
Backup seeks to restore data after failure or loss. Retention applies the obligation to preserve or delete content according to policy. One resource does not automatically replace the other.
10. Retention Policies
A applies the same setting at the level of a container or location. Examples: all messages from certain mailboxes, all documents from certain sites, or all messages from selected channels.
Static and adaptive scopes
Static scopes are defined directly in the policy and change when an administrator alters the selection. Adaptive scopes use attributes and queries to dynamically include or remove users, groups, or sites. This reduces maintenance in organizations with frequent changes, but requires reliable attributes and careful testing.
Characteristic
Retention policy
Application unit
Container or location.
Inheritance
Content in the container receives the configuration automatically.
Typical use
Broad and uniform rule by workload, group, user, or site.
Application by the user
Normally invisible and automatic.
Limitation
Lower granularity for items with different business values in the same container.
A policy can be configured to retain, delete, or retain and then delete. The exact behavior varies by workload, item type, and when the period starts. In a real deployment, it is essential to validate the specific documentation for Exchange, SharePoint, OneDrive, Teams, and other services.
Example
A policy can retain all mailbox content from a regulated area for seven years. It does not require each user to label each message.
11. Retention labels and label policies
Retention labels apply rules at the level of documents, emails, or other supported items. They allow different content in the same location to have distinct periods, triggers, and outcomes. A contract can be retained by one rule, while a temporary draft on the same site follows another.
Figure 4 - Retention policies act broadly by location; labels act with item-level granularity.
Create, publish, and apply
Creating the label defines retention and deletion behavior. Publishing the label through a policy makes it available to selected users and locations. The application can be manual, default for a location, or automatic based on information types, keywords, searchable properties, trainable classifiers, and other supported mechanisms.
Element
Paper
Retention label
Contains the rule applied to the item.
Publishing policy
Makes labels available for users and locations.
Automatic application policy
Finds content that meets conditions and applies the label.
Standard label
Applies a label to new items in a configured location, according to support.
Withholding per event
The period begins when a business event occurs, such as the termination of a contract.
Do not confuse Sensitivity label classifies and can protect access. Retention label controls the lifecycle and can declare a record. An item can receive both.
12. Records Management
Records Management extends retention for content that must be treated as formal records. A represents evidence of business activity or decision and requires stricter controls on alteration, deletion, traceability, and disposition.
Figure 5 - Records Management connects classification, immutability, retention, and controlled disposition.
Main capabilities
Declare items as records or regulatory records by retention labels.
Organize labels and requirements in a file plan.
Apply withholding based on business events.
unlocking, editing, moving, or deleting according to the type of .
Perform disposition reviews before permanent deletion.
Maintain proof of disposition and auditable trail. Regulatory records receive stronger restrictions and should only be used when required. Improper configuration can prevent legitimate deletions or generate excessive retention. Therefore, legal, records managers, security, privacy, and data owners should participate in the taxonomy.
Essential distinction
Every may be held, but not every held item is a . Records Management adds formal classification, immutability , and disposition process.
13. Precedence, conflicts, and legal holds
The same item may be subject to multiple policies, labels, and holds. Microsoft 365 resolves conflicts according to preservation principles: retention tends to prevail over deletion, and the longer period usually wins when multiple settings require preservation. Explicit and granular settings may take precedence in specific scenarios.
For the SC-900, it is more important to understand the logic than to memorize all the rules: the service aims to prevent a deletion setting from destroying content still required by another retention or investigation obligation.
Mechanism
Main purpose
Typical scope
Retention policy
Continuous governance of the life cycle.
Locations, users, groups, and workloads.
Retention label
Granular governance by value or item type.
Document, email, or item.
eDiscovery hold
Preserve relevant content for a specific investigation.
Sources and consultations of the case.
Exchange Litigation Hold
Preserve mailbox content in a legal scenario.
Mailbox.
Backup/recovery
Restore content after incident or error.
It depends on the service and the continuity strategy.
Be careful when closing cases Closing or deleting an eDiscovery case may release associated holds. Before closing, confirm if any other obligation still requires preservation.
14. Microsoft Purview eDiscovery
Electronic discovery, or eDiscovery, is the process of identifying, preserving, collecting, reviewing, and delivering electronically stored information as evidence in legal, regulatory, security, or internal investigations. The quality of the process depends on a defensible scope, access , proper preservation, and documentation of decisions.
Microsoft Purview eDiscovery searches data in services such as Exchange Online, SharePoint, OneDrive, Teams, Microsoft 365 Groups, and other supported locations. The classic experience of Content Search, eDiscovery Standard, and eDiscovery Premium was retired in August 2025. The current experience is unified in the Microsoft Purview portal, with basic or premium capabilities enabled according to licensing and case configuration.
And the term custodian?
In investigations, a custodian is the person who owns or controls potentially relevant data. In the classic product model, custodians were central objects in the Premium flow. In the current experience, the case is the central unit, and people, groups, and locations are added as data sources. The legal concept remains valid, but technical management has changed.
Figure 6 - The current case focuses on sources, preservation, search, review, and export.
15. Cases, permissions, data sources, and holds
A case brings together all the elements related to an investigation: members, roles, searches, data sources, holds, review sets, processes, and exports. Access must follow the principle of least privilege, because the content may include private communications, personal data, intellectual property, and confidential information.
Data sources
Data sources represent people, groups, and locations related to the case. By selecting a user or group, eDiscovery can identify mailboxes, OneDrive, sites, groups, and other associated locations. The investigator refines the selection to reduce unnecessary collection.
Holds
A preserves content to prevent permanent deletion while the investigation is active. It can be broad or based on a query. Preservation occurs in the source services, keeping versions or copies in protected locations. Holds should be reviewed throughout the case to avoid excessive scope or loss of evidence.
Stage
Control question
Create case
Which fact, request, or alert justifies the investigation?
Set members
Who can administer, search, review, and export?
Add fonts
Which users, groups, sites, and mailboxes may contain relevant ESI?
Apply hold
Which content should be preserved and for how long?
Audit the case
Are the actions, changes, and exports documented?
Proportional preservation Preserving everything can increase cost and privacy risk; preserving too little can destroy evidence. The scope must be justifiable and reviewed.
16. Searches, review sets, analysis, and export
Searches locate items by keywords, properties, participants, dates, item types, and other conditions. A well-designed query reduces false positives and facilitates a defensible review. Samples and query reports help adjust the scope before collecting large volumes.
Results can be exported directly or added to a when premium features are available. The copies items and metadata to Microsoft-managed storage, isolated by case, offering filters, viewers, tags, near-duplicate detection, email threading, themes, and other analyses.
Component
Use
Search
Identify responsive content in the sources.
Hold
Preserve relevant data at the source.
Review set
Gather a processed copy for analysis and marking.
Tag
Classify items by relevance, privilege, subject, or decision.
Analytics
Reduce volume and group similar or related content.
Export
Generate a package of items and reports for delivery or external analysis.
Process
Monitor search, collection, analysis, and export tasks.
Exports must preserve metadata and reports necessary for the chain of custody. The team needs to document who initiated the process, which filters were used, what was included, how the package was transferred, and who received access.
Search is not isolated proof
An item found needs to be interpreted in context. Authenticity, completeness, chronology, legal privilege, and chain of custody continue to be responsibilities of the investigative process.
17. Microsoft Purview Audit
Microsoft Purview Audit offers an integrated solution to search for user and administrator activities across various Microsoft services. The captures thousands of operations, such as access, creation, deletion, sharing, configuration changes, administrative actions, and investigation events.
Audit helps security, IT, compliance, internal risk, and legal teams answer questions such as: who accessed a file? Who changed a policy? When was a message forwarded? Which administrator performed an action? At which IP address or application did the event occur?
Conceptual anatomy of an event
Field
Example of information
Actor
User, administrator, application, or service that performed the action.
Activity
Operation performed, such as access, download, deletion, or modification.
Date and time
Recorded moment, usually in UTC.
Service
Exchange, SharePoint, Entra, Teams, Purview, or another service.
Object
File, message, account, policy, site, or affected resource.
Context
IP, client, identifiers, result, and additional properties.
Searches can be filtered by period, users, activities, services, and other attributes. Results can be exported for analysis. Retention and the types of events available vary by license, service, and policy.
Audit and monitoring
Audit records activities for investigation. It does not replace SIEM, real-time alerts, DLP, or preventive controls, although these systems can consume audit events.
18. Audit (Standard) and Audit (Premium)
Figure 7 - Audit (Premium) includes the features of Standard and expands retention, events, and investigation.
Capacity
Audit (Standard)
Audit (Premium)
Unified audit log
Yes
Yes
Portal search and export
Yes
Yes
Thousands of searchable events
Yes
Yes
General standard retention
180 days for supported events
Includes Standard
Default retention of Entra, Exchange, OneDrive, and SharePoint
According to standard capacity
One year for covered events and licensed users
Custom retention policies
No
Yes
Retention of up to ten years
No
With additional leave and policy; it is not retroactive
High-value events and insights
Limited
Expanded
Greater API access capacity
No
Yes
In Premium, custom policies can set retention by service, activity, or user and use priorities. Records prior to the creation of a ten-year policy are not preserved retroactively. For investigations, this reinforces the importance of planning retention before an incident.
Exam trap
Audit (Premium) is not a separate product that replaces Standard; it includes the capabilities of Standard and adds more advanced retention, events, and investigation features.
19. Integrated practical scenario
Consider a financial institution that is preparing an acquisition operation. The investment banking and market analysis teams need to be separated to avoid conflicts of interest. A message in Teams seems to contain project data sent to an unauthorized group. The organization needs to investigate without destroying evidence and without exposing content to unnecessary people.
Figure 8 - Different solutions contribute to prevention, preservation, investigation, and governance.
Step-by-step application
restrict communication between the defined segments and reduce new improper exchanges.
generates an alert because the message matches the confidential information or conflict of interest policy.
The reviewer confirms relevance and escalates the case to eDiscovery.
eDiscovery creates the case, defines members, adds users and locations as sources, and applies holds to preserve content.
Searches identify messages, files, and meetings; relevant items are added to the for analysis and tagging.
Audit reconstructs accesses, shares, changes, and administrative actions.
Retention and Records Management maintain mandatory records and allow controlled disposal at the end of the deadlines.
Compliance Manager records improvement actions, responsible parties, and evidence generated after the investigation.
Result
The organization reduces immediate risk, preserves the chain of evidence, limits access to the investigation, and turns the conclusions into verifiable improvements.
20. Comparisons and pitfalls of the SC-900
Confused concepts
Difference
compliance score vs certification
Score measures progress in actions; it does not certify compliance.
Communication Compliance vs DLP
Communication Compliance reviews communication and conduct; DLP controls data movement.
Information Barriers vs RBAC
IB restricts communication between segments; RBAC defines permissions over resources.
Sensitivity vs. retention label
Sensitivity protects/classifies; retention governs keeping and excluding.
Retention policy vs label
Policy acts by location; label acts by item.
Retention vs eDiscovery hold
Retention is continuous governance; hold is preservation related to investigation.
eDiscovery vs Audit
eDiscovery locates and preserves content; Audit records activities.
Audit (Standard) vs Premium
Premium includes Standard and adds extended retention and investigation.
Classic custodian vs. current source
Custodian is a person of interest; the current experience centralizes sources and data in the case.
Records Management vs. inactive file
Records Management applies formal controls, immutability, and audited disposition.
Statements that deserve suspicion
“A of 100% ensures legal compliance.”
“ replaces DLP and labels.”
"All retained content is automatically a ."
“Deleting a file removes the copy protected by retention or .”
“Audit (Premium) only changes the interface.”
“eDiscovery is just a search for keywords.”
“Holds should remain indefinitely, even after the obligation is closed.”
21. Quick review for the SC-900 exam
Term
Objective memorization
Compliance Manager
Evaluations, controls, improvement actions, evidence, and score.
compliance score
Risk-based progress; not a guarantee of compliance.
Communication Compliance
Detects and treats risks in communications.
Information Barriers
Restricts communication and collaboration between segments.
Data Lifecycle Management
Retains what is necessary and eliminates what has lost value.
Retention policy
Broad rule applied at the location or container level.
Retention label
Granular rule applied at the item level.
Records Management
Manages records, immutability, file plan, and disposition.
eDiscovery
Preserves, searches, reviews, and exports ESI in cases.
Hold
Prevents permanent deletion of relevant content.
Review set
Space for analysis, tagging, and analytics of collected items.
Audit (Standard)
Event search and standard retention.
Audit (Premium)
Extended retention, policies, events, and advanced investigation.
Final mind map Evaluate = Compliance Manager. Communicate responsibly = Communication Compliance. Separate groups = Information Barriers. Retain and delete = Data Lifecycle. Formalize records = Records Management. Preserve and collect = eDiscovery. Reconstruct actions = Audit.
22. Conclusion
Modern compliance depends on an integrated set of capabilities. The Compliance Manager transforms requirements into assessments, controls, and actions. and reduce communication risks. Data Lifecycle Management and Records Management govern retention and disposition. eDiscovery preserves and organizes evidence. Audit provides the timeline of activities.
The main takeaway is that none of these solutions, on their own, proves compliance. An organization needs to interpret obligations, set scopes, assign responsibilities, test controls, protect the privacy of investigated individuals, maintain evidence, and review policies. Technology makes the process more consistent, but governance and human judgment remain indispensable.
In my , the greatest value of Microsoft Purview lies in connecting activities that previously existed in separate tools and teams. When legal, security, privacy, IT, and business share criteria and evidence, compliance ceases to be a rushed preparation for audits and becomes part of the organization's daily operations.
Next step on the trail
In Chapter 17, the study progresses to data governance and discovery with Microsoft Purview Data Map and Unified Catalog.
23. Review questions
Question 1: Which statement correctly describes the ?
A) It is an automatic legal certification. B) Measures progress in improvement actions based on risk. C) Replaces external audits. D) Measures only the quantity of retained documents.
Commented answer
Correct answer: B. The helps prioritize and track actions, but it does not guarantee absolute compliance.
Question 2: Which feature is most suitable for applying the same retention rule to all
mailboxes of a group?
A) B) Sensitivity label C) D)
Commented answer
Correct answer: A. Retention policies operate at the site or container level and are suitable for broad rules.
Question 3: What is the main purpose of an eDiscovery ?
A) Increase the . B) Block communication between departments. C) Preserve relevant content to prevent deletion during an investigation. D) Encrypt all exported files.
Commented answer
Correct answer: C. The preserves content from case sources while the investigative obligation exists.
Question 4: What capability is characteristic of Audit (Premium) compared to Standard?
A) No event search. B) Extended retention and custom audit retention policies. C) eDiscovery replacement. D) Creation of sensitivity labels.
Commented answer
Correct answer: B. Audit (Premium) includes Standard and adds longer retention, policies, and advanced investigation features.
24. Essential Glossary
Term
Meaning
Assessment
Grouping of controls for a standard, regulation, or policy.
compliance score
Risk-based scoring to track improvement actions.
Control
Technical, organizational, or procedural measure related to a requirement.
Improvement action
Recommended task to implement or test a control.
Communication Compliance
Solution to detect and address risks in communications.
Information Barriers
Policies that restrict collaboration between segments.
Retention policy
Retention rule applied to location or container.
Retention label
Retention rule applied to the item.
Record
Formal content subject to record controls.
Disposition review
Review before permanent deletion of records.
ESI
Electronically stored information used as evidence.
Hold
Preservation to prevent deletion during investigation.
Review set
Set processed for review, marking, and analysis.
Unified audit log
Searchable repository of user and administrator activities.
Official references consulted
Microsoft Learn - Study guide for Exam SC-900: Microsoft Security, Compliance, and Identity Fundamentals. Skills measured as of July 28, 2026.
Microsoft Learn - Microsoft Purview Compliance Manager; Compliance Manager scoring; Working with improvement actions.
Microsoft Learn - Microsoft Purview data compliance solutions.
Microsoft Learn - overview, planning, configuration, and investigation.
Microsoft Learn - overview and policy configuration.
Microsoft Learn - Data Lifecycle Management; retention policies and retention labels.
Microsoft Learn - Records Management, file plan and .
Microsoft Learn - eDiscovery overview, workflow, cases, data sources, holds, searches, review sets and export.
Microsoft Learn - Audit solutions overview; Audit (Standard) and Audit (Premium).
Note about update
The classic eDiscovery experience was retired on August 31, 2025. Features, names, licensing, retention periods, and portals may change. For actual deployment, always check the current documentation and applicable legal obligations.