Technology

How Litigation Hold in Microsoft 365 Actually Works (and Where It Breaks)

JamesJames Sep 27, 2026 7 min read
Microsoft 365

Three weeks before a trial, a paralegal asked me for every email between two executives and an outside vendor. We had issued a hold six months earlier. The mailbox we needed had been deleted by the employee’s manager during a routine cleanup, and nobody had noticed, because nothing in our process pointed at the recycle bin.

That is the quiet risk sitting inside most Microsoft 365 tenants. The retention engine is powerful, the audit trail is real, and the interface makes everything feel handled. What’s missing is usually a human being who can explain which lever is actually pulled and why. A hold isn’t a setting you flip once. It’s a small system, and systems drift. The good news: you can learn the whole thing in an afternoon. Here’s what matters, what people get wrong, and how to sleep at night.

What a hold actually does inside a mailbox

When you place a mailbox on hold, Microsoft 365 stops permanently deleting items. The mailbox keeps accepting new mail, users keep deleting things, and those deleted items move to the Recoverable Items folder, which is invisible in Outlook but fully searchable by an administrator. If someone purges from the deleted items view, the content shifts into a deeper subfolder. It doesn’t vanish unless the hold is removed and the retention clock expires.

That distinction matters more than people expect. Users believe “I deleted it” means gone. In a held mailbox, it means hidden from them, not from a search. Counsel who doesn’t understand this will ask for the wrong thing, and IT will answer the wrong question.

There are two paths into hold state. You can apply it per mailbox, which is precise and painful to maintain at scale, or through a policy that targets groups, sites, and shared locations. Most organizations end up mixing both, which is exactly how gaps appear. If your tenant is large, the per-mailbox approach will quietly rot: people leave, mailboxes get recreated, and new hires never inherit the setting.

Retention policies beat cherry picking

I’ll say the unpopular thing. For almost every organization past a few hundred employees, policy based retention is the right default and manual mailbox holds are the exception. Not because policy is more sophisticated, but because it survives turnover.

A retention policy attaches to identities you already manage, so a new sales director inherits coverage the day their account is created. Manual holds don’t do that. They wait for someone to remember.

NIST publishes widely used guidance on protecting organizational records and information, and the underlying principle there applies squarely to holds: controls belong to a process, not to an individual’s memory. You can read more at NIST. I’ve watched a two person legal team maintain flawless coverage across thousands of mailboxes using policy, and I’ve watched a fifteen person department lose evidence with manual holds. Headcount wasn’t the variable. Design was. The tradeoff is cost and scope. Policy based retention preserves things you’d rather not pay to store, and broad policies can create review volume you never wanted. That’s a real bill, and it’s still cheaper than a spoliation finding.

Preservation is only half the job

Storing data is the simple part. Finding it, and showing a court that you found all of it, is where teams struggle. A hold that nobody can search is a liability with a receipt. Practitioners in this field have spent years documenting the collection and preservation side of the work, and the discipline around it has matured considerably. The Electronic Discovery Reference Model community is a reasonable starting point if you want to see how identification, preservation, and collection fit together.

The framework won’t run a search for you, but it will stop you from skipping the step where most holds quietly fail. The practical version: run a test search on a held mailbox before you need it. Target a known thread, confirm the results, and note the date. That single habit catches dead scopes, licensing gaps, and misconfigured connectors months before a deadline.

The three settings that fail quietly

Scope drift. A policy built on a distribution list breaks the moment someone builds a new group. Keep the identity source in one place and review it quarterly.

License gaps. Some hold features depend on the plan assigned to the account. A contractor on a lighter license may not be covered the way a full time employee is. Audit the plan mix, not just the user list.

Deleted site collections. SharePoint and Teams content lives in its own preservation model. A perfectly held mailbox doesn’t protect the Teams channel where the actual decision was made. If your matter touches collaboration tools, plus the hold to those locations too.

There’s a fourth one I’d rank nearly as high. Nobody documents who authorized the hold, when, and for what matter. Six months later, that answer is guesswork.

A five step routine that holds up

  1. Map the custodians. Name the people and the systems, not just the mailboxes. Include Teams, SharePoint, and any shared drive the matter touches.
  2. Choose the mechanism. Policy for coverage at scale, manual hold for narrow or short lived matters. Write down which you picked and why.
  3. Verify with a search. Confirm that held content is retrievable, and keep the query and the date in the matter file.
  4. Notify and record. Send the hold notice, log the response, and set a reminder to follow up with anyone who hasn’t confirmed.
  5. Review before release. Releasing a hold is the most dangerous click in the whole process. Require a second set of eyes and a written reason.

Steps three and five are the ones people skip. They’re also the two that show up in depositions.

Why this keeps landing on IT’s desk

Legal owns the obligation. IT owns the switches. That split is where most disputes start, and it’s usually a vocabulary problem, not a competence problem. Legal asks for “everything about the project.” IT hears a request for a query they can’t write. A shared glossary fixes more than any tool. Define custodian, matter, scope, and release in writing, once, and keep it somewhere both teams can find it. Then run a joint tabletop twice a year using a fake matter. Twenty minutes of practice catches more than a policy rewrite.

If your organization has already moved eDiscovery work into Microsoft 365 itself, it’s worth knowing that the platform’s own documentation describes how holds interact with retention labels and where the boundaries sit. Start with Microsoft rather than a forum thread.

One more thing worth saying plainly. Vendors showing up at this link are selling eDiscovery platforms, and the honest ones will tell you the software doesn’t fix a broken process. If your Litigation Hold in Microsoft 365 setup is sound, tooling makes the work faster. If it isn’t, tooling makes the failure louder.

The part that actually protects you

Nobody gets credit for a hold that works. There’s no dashboard, no quarterly win, just an absence of disaster. That’s probably why it gets neglected until a deadline forces the issue.

So here’s the question I’d put to your team this month, and it takes one meeting to answer: if a custodian’s mailbox were deleted tomorrow, could you show, in writing, exactly what happened next? If the answer needs a phone call to confirm, your setup is running on luck. Pick one mailbox, run the whole test, and write down what you find.

Share Article
James
About the Author

James

Jesran is a U.S.-based SEO strategist and digital marketing expert known for helping businesses grow through search optimization, online visibility, and smart content strategies. With deep experience in technical SEO and local search, he simplifies complex marketing concepts into clear, actionable insights for brands of all sizes.

View all articles

Leave a Comment