An eDiscovery request from legal that sweeps in Teams communications is a steep first exercise for IT teams who have not handled one before. Teams content will not export the way email does, it is scattered across Exchange and the file service, and the tooling to search and export it demands a the compliance portal licence along with a degree of ease in the compliance portal UI.
This piece works through the eDiscovery workflow applied to Teams content, focusing on the hands-on steps and the places people typically get confused.
Where eDiscovery Finds Teams Content
You need to know what you are actually searching before you start the search. From an eDiscovery standpoint, Teams content is spread over several places:
- Teams private chat and group chat messages: Held in the the mail service mailbox of every participant, in a hidden subfolder called "SubstrateHolds" or a similarly named internal folder. Searching them means aiming at the Exchange mailboxes of the users in those chats.
- Teams channel messages: Held in the mail service group mailbox of the cloud group behind the team. Searching one team's channel messages means aiming at the group mailbox attached to that team.
- Files shared in Teams chats: Held in the sender's the personal file store, so point the search at that personal file store location.
- Files shared in Teams channels: Held in the file service site associated with the team, so target that file service site.
- Meeting recordings: Held in the organiser's the personal file store for private meetings, or in the channel's the file service for channel meetings.
- Meeting recordings: For meetings held outside a channel, the organiser's the personal file store; for channel meetings, the channel's the file service library. A mailbox-only search will not return the recording file.
- Loop and other embedded components may hold content away from the classic chat blob. Where a matter turns on that content, confirm today's storage location against the product documentation before telling counsel the mailbox search is complete.
the compliance portal eDiscovery: Premium and Standard Compared
Two tiers of eDiscovery tooling come with the compliance portal:
eDiscovery (Standard) ships with the E3/E5 plans and certain other plans, delivering content search, case management and export. It covers most day-to-day eDiscovery requirements.
eDiscovery (Premium) requires the E5 plan or an add-on licence, adding advanced analytics such as near-duplicate detection, email threading and review sets, along with custodian management, holds management at scale and deeper workflow tooling. It suits large-scale litigation and complex investigations.
Ordinary IT-led eDiscovery requests, whether HR investigations, legal holds or regulatory enquiries, are normally handled adequately by eDiscovery (Standard).
Constructing a Content Search Over Teams Content
In the compliance portal, head to eDiscovery > Standard > Cases (or open a fresh case) > Searches. Two elements carry a content search: the locations being searched, and the query itself.
Locations that cover Teams content:
- Private and group chats: include the mail service mailboxes of the custodians, meaning the people in those chats
- Channel messages: include the mail service mailboxes of the cloud groups behind the teams concerned
- Files: include the custodians' personal file store locations and/or the file service sites of the teams concerned
The location picker does not oblige you to separate "Teams chats" from "Teams channels": search the correct mailboxes and both varieties of Teams Exchange content come back. The results tell the Teams content type apart by its content class.
Drafting the query:
Keyword Query Language (KQL) underpins content search, and Teams-specific content can be filtered on content class:
-- Search only Teams chat messages
kind:im
-- Search only Teams channel messages
kind:teams
-- Search for Teams content containing specific keywords
kind:im OR kind:teams AND "project Alpha" AND participants:[email protected]
-- Search for Teams content in a date range
kind:im AND received:2025-01-01..2025-06-30
Exporting What the Search Returned
After a search completes, its results can be exported for review. Exchange-based Teams content exports as PST, while the file service and the personal file store content exports as files. Within the PST, each chat or channel thread normally emerges as its own email-like item, with the message text as the body and attachments appearing as separate items.
The export tool in more recent compliance portal releases offers a Teams-specific export format that presents conversations in a clearer threaded layout. Check whether that option exists in your the compliance portal tenant before reverting to a straightforward PST export.
What Remains of Deleted Messages
Teams eDiscovery regularly raises the question of whether deleted messages can be retrieved. The answer depends on how retention is configured:
With a Teams retention policy in place, user-deleted messages persist as the compliance copy throughout the retention period. eDiscovery can still search and export them even though the Teams UI has stopped displaying them, and that compliance copy lives in the "SubstrateHolds" folder inside the user's Exchange mailbox.
Without a retention policy, deleted messages may not last. the mail service enforces a default deleted-item retention window of 14–30 days, and once that window closes, ordinary techniques may no longer retrieve them. That is one good reason to establish Teams retention policies ahead of need: not to hold content for longer, but to make certain that compliance copies survive for a defined span.
eDiscovery and Guest User Content
Guests taking part in Teams chats produce compliance content inside your tenant. When a guest posts a message in a Teams channel or chat, that text lands in the Teams service's compliance store, yet the guest's own exchange mailbox lives in their home tenant rather than yours and is not reachable directly by eDiscovery. Channel content is fine, because the group mailbox sits in your tenant, so guest messages there are discoverable through your normal eDiscovery process aimed at that group mailbox. Private chats with guests are only half discoverable: whatever your users' mailboxes hold is available, while the guest's half may stay beyond direct reach unless their organisation cooperates.
The Channel Nobody Searched Because Its Group Mailbox Was Missing
Teams eDiscovery fails in one particular, repeatable pattern: the custodian's mailbox gets searched, private chat shows up, and channel messages do not. Channel messages reside in the cloud group mailbox belonging to the team, never in the member's own mailbox. Build the location list purely from an HR roster of employee names and the search will look thorough while omitting the very channel where the relevant conversation actually ran.
Facing a contract dispute, a manufacturing firm searched four custodians and produced a thin chat history. The negotiation had taken place in a channel named after the customer, and that channel's messages sat in the group mailbox nobody had added as a location. Rerun with the same keywords but with the group mailbox included, and the exact thread counsel had been assured did not exist came back. The tool was not at fault; the location list had been incomplete.
Build the location list in two passes. The first pass covers people: custodians, their mailboxes, their personal file stores. The second pass covers teams: every team those people belong to that might carry relevant channel traffic, with the group mailbox and the file service site for each. Write the keyword query only once the locations are settled. A sharp keyword pointed at the wrong mailbox is still a miss, and the result count on its own makes that miss hard to see.
Somebody has to read the export. A PST packed with chat items is not a transcript until the thread order and the participants have been verified. Prefer whichever export option leaves Teams conversations readable, and open a sample before sending the full package to reviewers. A package reviewers cannot read gets returned, and the resulting delay is blamed on the hold rather than on the format.
Guest and external involvement limits what the host tenant can produce. A guest's messages posted into a host-tenant channel sit in the host group mailbox and are searchable there, but the guest's side of a private chat may reside in the other organisation. State that boundary plainly while the collection plan is being drafted, so counsel does not stumble over it after the production date.
Store the date range inside the saved search rather than relying on the case name to remember it. If content was still being deleted during the first collection, run the search again once a hold is in place. Renaming a channel does not relocate the group mailbox, so search by the group rather than by the current display name alone. A search returning nothing is a finding about the query or the locations; it is not, on its own, proof that the conversation never happened. Keep both the search and the export in the case record, because a search that is not saved will be rebuilt differently next time. Where premium review sets are not licensed, put that in the plan so reviewers know they are reading a standard export. Add the group mailbox even when the custodian swears they never use channels; the statement and the membership list are both worth holding. Save the query text into the case verbatim, character for character, since a paraphrase will not reproduce the same search. Open one exported item and confirm the participants are visible before you release the set. A team the custodian has since left still holds the messages from the period of their membership, because leaving does not strip them out of the group mailbox. Agree date ranges in writing; a day of slack on either side costs less than a second production. Where meetings feature in the matter, add recordings to the location list from the outset, since they are files and are often the clearest record. Flag any search that hit the tool's limit and had to be split, because a split search that drops a day in the middle leaves a gap.