Legal hold is one of those compliance tools that most IT teams don't think about until they need it urgently — and then the urgency makes it harder to do correctly. Understanding how legal holds work in Microsoft Teams before you receive a preservation obligation is significantly better than figuring it out under time pressure.

This article provides an overview of how in-place holds work for Teams content in Microsoft 365, how to apply them, and what to expect from a hold exercise.

What a Legal Hold Does

A legal hold (also called an in-place hold, litigation hold, or preservation hold) is a mechanism for preserving content in Microsoft 365 that would otherwise be deleted — either by users, by retention policies, or by automatic system cleanup processes. When a legal hold is applied to a user's mailbox or SharePoint site, the content in that location is preserved indefinitely, regardless of what the user does or what retention policies say.

The hold doesn't affect the user's experience of Teams. They can still delete messages from the Teams UI; those messages disappear from their view. But the compliance copy of the message is preserved in a hidden area of the Exchange mailbox (the "Preservation Hold Library" or similar internal folder). eDiscovery searches will find the preserved content even after the user has "deleted" it.

How to Apply a Legal Hold in Microsoft 365

Legal holds for Teams content are applied through Microsoft Purview eDiscovery, specifically through eDiscovery cases. The workflow:

  1. Create an eDiscovery case in Microsoft Purview > eDiscovery > Standard (or Premium for more advanced workflow).
  2. In the case, navigate to the Holds section and create a new hold.
  3. Select the content locations to hold: Exchange mailboxes of the relevant custodians (for chat messages), Exchange group mailboxes of the relevant teams (for channel messages), OneDrive accounts (for shared files), and/or SharePoint sites (for channel files).
  4. Optionally add a query to limit the hold to specific content (date ranges, keywords). An unbounded hold preserves everything in the specified locations.
  5. Enable the hold.
  6. Name the matter in the hold description so a later administrator can tell why the hold exists without opening a separate spreadsheet.
  7. Add the group mailboxes for relevant teams at the same time as the user mailboxes. A hold on people that skips team group mailboxes does not cover channel messages.

Once enabled, the hold is typically effective within 24 hours for Exchange-based content. Large SharePoint sites may take longer.

Scoping the Hold

Legal holds can be scoped by custodian (specific people), by location (specific teams or sites), and by query (specific date ranges or keywords). For most legal preservation scenarios, you'll want to start with a broad, custodian-based hold — include all the Exchange mailboxes and OneDrive accounts of the individuals involved in the matter — and then narrow scope as the legal team clarifies what's actually needed.

Resist the temptation to apply a query-based hold too narrowly from the start. If the query misses relevant content (because it uses different terminology, or because it doesn't capture all relevant date ranges), you may have a defensibility problem later. A broader, location-based hold that preserves more than necessary is generally safer than a narrow, query-based hold that might miss content.

Litigation Hold vs eDiscovery Hold

Microsoft 365 also has a legacy "litigation hold" setting that can be applied directly to a mailbox in Exchange admin. This is different from an eDiscovery case hold. Litigation hold (mailbox-level) is a broad, permanent hold that preserves all content in the mailbox indefinitely. It's simpler to apply but less flexible than an eDiscovery case hold.

For most governance purposes, using eDiscovery case holds is preferable: they're scoped to a case, they can be released when the legal matter concludes, and they provide better visibility into what's held and why. Litigation hold is appropriate when you need to preserve a specific person's communications indefinitely for regulatory compliance and a case-based approach is overkill.

Holds vs Retention Policies

Retention policies and legal holds work independently. A retention policy that says "delete Teams chats after 2 years" does not override a legal hold. Content under a hold is preserved regardless of the retention policy. When the hold is released, normal retention policy processing resumes for that content. Content that would have been deleted during the hold period is then subject to the retention policy from the release date.

Notifying Custodians

In regulated contexts and litigation scenarios, you may be required to notify custodians that their content is under legal hold. eDiscovery (Premium) includes a custodian communication workflow for this purpose. For eDiscovery (Standard), notification is a manual process — typically a written communication from legal to the affected individuals explaining the hold and their obligations under it.

Releasing a Legal Hold

When the legal matter concludes, the hold should be released. In the eDiscovery case, navigate to Holds and disable or delete the hold. After release, normal retention processing resumes. Content that was preserved during the hold is now subject to the applicable retention policies. If the retention policies say to delete content after a certain period, content that aged past that period during the hold may be eligible for deletion at the next retention processing cycle.

Maintain a record of holds applied, the scope of each hold, the legal matter they were applied for, the date applied, and the date released. This documentation is part of your defensible legal hold process and may be requested as evidence in litigation.

A Hold That Started Too Narrow and Could Not Be Widened Retroactively

An in-place hold preserves what is still there, and what arrives after the hold is on. It does not recover what a retention policy already deleted last month. The scope chosen on the first day is therefore the scope you will have to defend. Starting with four custodians because the list felt manageable, and adding a fifth custodian three weeks later, preserves the fifth person's content only from the day they were added. The gap is not visible in the hold's status page.

A regional bank's legal team asked IT to hold "the project mailbox" for a vendor dispute. The request was implemented as a hold on a shared mailbox that the project had stopped using. The working conversation was in Microsoft Teams: a private chat among three managers and a channel on the vendor team. Neither location was on the hold. By the time counsel asked for the chat, a 180-day delete policy had already removed the oldest month. The hold on the shared mailbox was healthy and irrelevant.

Translate every hold request into locations before enabling it. People mean mailboxes and OneDrives. Teams mean those mailboxes plus the group mailboxes and sites of the teams they use. Write the translation into the case notes and ask counsel to confirm it. A hold enabled against the wrong object is not a partial hold. It is a hold on something else.

Releasing the hold is part of the same record. When the matter closes, disable the hold and note the date. Content that was kept past its retention period becomes eligible for deletion after release, on the next retention cycle. People who expected the archive to remain forever need to hear that before the release, not after a search comes up empty.

Large holds have a cost in mailbox growth and in review volume. That cost is not a reason to narrow a hold below the matter. It is a reason to use a query only when counsel has agreed that the query's language is complete. A keyword hold that misses the product's internal name will look precise and will drop the documents that used the other name. If there is doubt, hold the location and narrow at review.

Check the hold's error report. A location that failed to apply is not held, even if the case says the hold is active. Custodians who leave the organisation still need their mailbox and OneDrive on the hold until the matter ends. Disabling the account is not a release. Do not delete a team that is under hold because it looks idle. Confirm the hold scope with the case owner first. A litigation hold set on the mailbox in Exchange and an eDiscovery hold set in Purview are different objects. Know which one you created. Document the query text if a query is used, including the date it was last edited. New teams created by a custodian after the hold starts are not automatically added. Periodic checks of the custodian's memberships belong on the case calendar. The hold description should include the locations in ordinary language, not only the case title. Confirm counsel saw the location list. A hold they did not understand is a hold they cannot defend. Check newly created teams for custodians on a schedule you can point to. Release notes belong in the case, with the date and the role that approved the release. A query hold and a location hold are different risks. Do not describe a query hold as complete preservation. Mailbox size growth on a long hold is expected. Warn the messaging team before they start deleting mail to save space. If a custodian uses a secondary account, that account is either in scope or explicitly out. Leaving it unmentioned is the failure mode.

Editorial Team

Editorial Team

GovernanceMastery

The GovernanceMastery editorial team brings together experience across enterprise Microsoft 365 deployments, compliance consulting, and IT security.