Legal hold sits among those compliance tools that most IT teams ignore right up until the moment they urgently need it, and the urgency is precisely what makes it difficult to get right. Understanding in advance how legal holds work in Teams beats figuring it out against the clock by a comfortable margin.

This article outlines the behaviour of in-place holds over Teams content in the cloud suite, how to put them in place, and what running a hold exercise usually entails.

What a Legal Hold Really Achieves

A legal hold, variously called an in-place hold, a litigation hold or a preservation hold, is the mechanism for retaining content in the cloud suite that would otherwise disappear, whether at the hands of users, retention policies or automated cleanup. Put a legal hold on a user's mailbox or on a the file service site and everything there is preserved indefinitely, irrespective of user action or of what any retention policy instructs.

Nothing about the user's Teams experience changes. Messages can still be deleted in the Teams UI and they drop out of view, yet the compliance copy of each one is retained somewhere hidden in the Exchange mailbox, in the "Preservation Hold Library" or a comparable internal folder. eDiscovery searches continue to surface that preserved content even after the user has "deleted" it.

Placing a Legal Hold in the cloud suite

Teams content is placed under legal hold through eDiscovery in the compliance portal, working inside eDiscovery cases. The workflow goes like this:

  1. Create the eDiscovery case at compliance portal > eDiscovery > Standard, or Premium if you need the more advanced workflow.
  2. Within that case, go to the Holds section and set up a new hold.
  3. Select the content locations to place under hold: the Exchange mailboxes of the custodians concerned for chat messages, the Exchange group mailboxes of the teams concerned for channel messages, the personal file store accounts for shared files, and/or the the file service sites for channel files.
  4. Optionally attach a query so the hold covers only particular content by date range or keyword. A hold without a query preserves everything in the locations selected.
  5. Enable the hold.
  6. Write the matter into the hold description, so any future administrator can tell why it exists without hunting for a separate spreadsheet.
  7. Add the group mailboxes of the teams concerned alongside the user mailboxes. A hold covering only people, with team group mailboxes omitted, does not capture channel messages.

Once enabled, the hold usually becomes effective on Exchange-based content inside 24 hours. Large the file service sites may take longer.

Setting the Hold's Scope

Scope can be set by custodian, meaning named people; by location, meaning named teams or sites; and by query, meaning named date ranges or keywords. Most preservation situations call for starting broad on a custodian basis, sweeping in the Exchange mailboxes and personal file store accounts of everyone connected to the matter, then tightening as the legal team clarifies what is genuinely required.

Resist the pull toward an over-tight query-based hold from the start. Should the query miss relevant content, perhaps because the wording differs or a relevant date range is not spanned, defensibility becomes a problem further down the line. A broader location-based hold that preserves more than strictly necessary is usually safer than a narrow query-based hold that risks overlooking content.

eDiscovery Hold Compared with Litigation Hold

A legacy "litigation hold" setting also exists in the cloud suite and can be applied directly to a mailbox from Exchange admin. Do not confuse it with an eDiscovery case hold. The mailbox-level litigation hold is a blanket, open-ended hold preserving everything in that mailbox with no end date: simpler to apply, noticeably less flexible than a case hold.

Governance work is generally better served by eDiscovery case holds, since they attach to a case, can be released once the legal matter concludes, and show more clearly what is held and on what grounds. A litigation hold suits the narrower scenario in which one individual's communications must be preserved indefinitely for regulatory compliance and a case-based approach would be overkill.

Retention Policies and Holds Side by Side

Legal holds and retention policies run on different tracks. A policy stating "delete Teams chats after 2 years" does not override a hold: content under hold is kept whatever the policy instructs. When the hold comes off, ordinary retention processing restarts for that content, and anything that would have been deleted while the hold was running falls under the policy from the release date onwards.

Telling the Custodians

Regulated environments and litigation scenarios can oblige you to inform custodians that their content sits under legal hold. eDiscovery (Premium) includes a custodian communication workflow designed for exactly this. Under eDiscovery (Standard), notification is a manual exercise, typically a written message from legal to the people affected setting out the hold and the obligations it places on them.

Releasing a Legal Hold

Closing the legal matter should trigger release of the hold. Within the eDiscovery case, go to Holds and either disable it or delete it. Ordinary retention processing then resumes, and content preserved during the hold falls back under whichever retention policies apply. Where those policies call for deletion after a fixed period, content that aged beyond that point while held may become eligible for deletion at the next retention processing cycle.

Maintain a record of every hold applied: its scope, the legal matter behind it, the date it was put on and the date it came off. That documentation forms part of a defensible legal hold process and may be called for as evidence in litigation.

The Hold That Began Too Narrowly and Could Not Reach Backwards

An in-place hold preserves whatever is still present, plus whatever arrives once the hold is running. It cannot recover what a retention policy deleted the previous month, which makes the scope you pick on day one the scope you will have to defend. Begin with four custodians because that list felt manageable and add a fifth three weeks later, and only that fifth person's content from the day of addition is preserved. The gap does not appear on the hold's status page.

The legal team at a regional bank asked IT to place "the project mailbox" on hold for a vendor dispute. IT implemented it as a hold on a shared mailbox the project had stopped using. The live conversation was in Teams: a private chat between three managers plus a channel on the vendor team. Neither location was covered. By the time counsel asked for the chat, a 180-day delete policy had already swept away the oldest month. The shared-mailbox hold was healthy and irrelevant.

Convert every hold request into locations before you switch it on. People translate to mailboxes and personal file stores; teams translate to those mailboxes plus the group mailboxes and sites of the teams in use. Write that translation into the case notes and have counsel confirm it. A hold applied to the wrong object is not a partial hold. It is a hold on something else.

The release belongs in the same record. When the matter closes, disable the hold and log the date. Content kept past its retention period turns deletable at the next retention cycle once the hold is released. Anyone expecting the archive to persist forever needs to hear that beforehand, not after a search comes back empty.

Broad holds carry a cost in mailbox growth and review volume, but that cost is no reason to scope a hold below the size of the matter. It is a reason to reach for a query only once counsel has agreed the query's language is complete. A keyword hold that omits the product's internal name looks precise while dropping every document that used the other name. When in doubt, hold the location and narrow at review.

Review the hold's error report, because a location that failed to apply is not held at all, whatever the case says about the hold being active. Custodians who leave still need their mailbox and their personal file store kept under hold until the matter finishes; disabling the account is not a release. Never delete a team under hold simply because it looks idle, and confirm the hold scope with the case owner first. A litigation hold applied to the mailbox in Exchange and an eDiscovery hold applied in the compliance portal are separate objects, so know which one you created. Where a query is used, document its text along with the date it was last edited. Teams a custodian creates after the hold begins are not added automatically, so put periodic checks of the custodian's memberships on the case calendar. The hold description should name the locations in ordinary language rather than repeating the case title, and counsel should be confirmed as having seen the location list, since a hold they did not understand is a hold they cannot defend. Release notes belong in the case with the date and the role that approved the release. Query holds and location holds carry different risks, so do not present a query hold as complete preservation. Mailbox growth over a long hold is expected; warn the messaging team before they start deleting mail to free up space. If a custodian uses a secondary account, that account is either in scope or explicitly out, and leaving it unmentioned is the failure mode.

Editorial Team

Editorial Team

Governance Consult Services

The Governance Consult Services editorial team combines hands-on experience of enterprise cloud suite deployments with compliance consulting and IT security backgrounds.