Exchange OnlineHow-to

Retention policies, labels, MRM and litigation hold in Exchange Online: which one does what

Purview retention policies vs retention labels vs Exchange MRM tags vs litigation hold: what each does, what wins in a conflict, licensing, how to set them up and how to prove a mailbox is really on hold.

Exchange Online gives you four different ways to keep (or get rid of) mail: Microsoft Purview retention policies, retention labels, the older Exchange MRM retention tags, and litigation hold. They overlap just enough to be confusing, and picking the wrong one leads to surprises such as mail that never expires or a leaver's mailbox that quietly disappears. In this post I'll explain what each tool is for, which one wins when they disagree, how to create a retention policy and a litigation hold, and how to prove with PowerShell that a mailbox is actually protected.

How this guide is organised: How it works → Step-by-step → What happens to retained items → Inactive mailboxes → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (2 steps: Create a retention policy for Exchange mailboxes; Put a mailbox on litigation hold). 3. What happens to retained items. 4. Inactive mailboxes. 5. Verify. 6. Tips & gotchas. Toolbox: Get-OrganizationConfig, Get-RetentionCompliancePolicy, Start-ManagedFolderAssistant, Users › Active users, InPlaceHolds.1How it works2Step-by-step3What happens to retaineditems1Create a retention policyfor Exchange mailboxes2Put a mailbox onlitigation hold4Inactive mailboxes5Verify6Tips & gotchasTOOLBOXGet-OrganizationConfigGet-RetentionCompliancePolicyStart-ManagedFolderAssistantUsers › Active usersInPlaceHoldsHow this guide is organised: How it works → Step-by-step → What happens to retained items → Inactive mailboxes → Verify → Tips & gotchasFlow diagram of the article's sections in reading order: 1. How it works. 2. Step-by-step (2 steps: Create a retention policy for Exchange mailboxes; Put a mailbox on litigation hold). 3. What happens to retained items. 4. Inactive mailboxes. 5. Verify. 6. Tips & gotchas. Toolbox: Get-OrganizationConfig, Get-RetentionCompliancePolicy, Start-ManagedFolderAssistant, Users › Active users, InPlaceHolds.1How it works2Step-by-step1Create a retention policy for Exchangemailboxes2Put a mailbox on litigation hold3What happens to retained items4Inactive mailboxes5Verify6Tips & gotchasTOOLBOXGet-OrganizationConfigGet-RetentionCompliancePolicyStart-ManagedFolderAssistantUsers › Active usersInPlaceHolds
At a glance: how this guide is organised · 2 steps · 5 key settings and tools

How it works: four tools, four jobs#

ToolWhat it doesWhere it appliesUse it for
Purview retention policyRetain, delete, or retain-then-delete everything in a location for a periodWhole mailboxes (also shared, room and equipment mailboxes), plus SharePoint, OneDrive, Teams and moreThe organisation-wide baseline, for example "keep all mail 7 years, then delete"
Purview retention labelSame actions, but stamped on an individual item or folder; travels with the item inside the tenantEmail, documentsExceptions and records: contracts, HR files, disposition review
Exchange MRM (retention tags and an MRM policy)Moves items to the archive mailbox or deletes them after an age; one MRM policy per mailboxExchange mailboxes onlyArchiving (the Default MRM Policy moves mail to the archive after two years); Microsoft calls it a legacy feature for everything else
Litigation holdA mailbox property that preserves everything, including deleted and edited items, indefinitely or for a number of daysOne mailbox (and its archive)Legal preservation of specific people; needs Exchange Online Plan 2

When several of these apply to the same item, Microsoft's principles of retention decide the outcome, in this order: retention always wins over deletion; the longest retention period wins; for deletion, an explicit label beats an implicit policy, and a scoped policy beats an org-wide one; finally the shortest deletion period wins. eDiscovery holds and litigation holds sit under the first rule, so nothing is purged while any hold is active. The practical reading is simple: adding a hold or a retention policy can only make an item live longer, never shorter.

Licensing (as published in the Microsoft Purview service description, so re-check it): retention policies on Exchange mailboxes are covered by Microsoft 365 E3/E5, Office 365 E3/E5, Business Premium, Exchange Online Plan 2 and Exchange Online Archiving. Adaptive scopes need an E5-level licence (Microsoft 365 E5, Office 365 E5, or the Purview add-ons). Litigation hold needs Exchange Online Plan 2, or Plan 1 plus Exchange Online Archiving. Inactive mailboxes need no licence at all.

Step 1: Create a retention policy for Exchange mailboxes#

In the Microsoft Purview portal go to Solutions › Data Lifecycle Management › Policies › Retention policies › New retention policy. Name it, keep the default of Full directory for admin units, then choose the scope type:

  • Static: the default All mailboxes covers every current and future mailbox, including inactive ones. You can instead include or exclude specific recipients (groups are expanded once, at save time, and don't update later), but then inactive mailboxes are no longer supported and per-policy limits apply.
  • Adaptive: the policy follows a query built on attributes such as Department, Country or region, Job title or CustomAttribute1-15. Scopes are created first under Settings › Roles and scopes › Adaptive scopes, run daily, and can take up to five days to populate, so create them a few days before you need them. Adaptive scopes can also target or exclude inactive mailboxes with IsInactiveMailbox in the advanced query builder.

Turn on the Exchange mailboxes location, then decide: retain for a period and do nothing, retain and then delete, or only delete. For Exchange the age is based on the received date (or sent date for outgoing mail). Allow up to seven days for the policy to reach mailboxes, and note that mailboxes under 10 MB aren't processed.

The same policy from Security & Compliance PowerShell:

PowerShell
Connect-IPPSSession
New-RetentionCompliancePolicy -Name "Mail - keep 7 years" -ExchangeLocation All
New-RetentionComplianceRule -Name "Mail - keep 7 years rule" -Policy "Mail - keep 7 years" `
    -RetentionDuration 2555 -RetentionComplianceAction KeepAndDelete
Get-RetentionCompliancePolicy "Mail - keep 7 years" -DistributionDetail | Format-List Name, DistributionStatus

Step 2: Put a mailbox on litigation hold#

Use litigation hold when legal asks you to preserve specific people; for routine "keep everything" requirements Microsoft recommends a retention policy instead. In the Microsoft 365 admin center open Users › Active users, select the user, and on the Mail tab choose Manage litigation hold. In PowerShell:

PowerShell
Connect-ExchangeOnline
# Indefinite hold
Set-Mailbox -Identity adele@contoso.com -LitigationHoldEnabled $true
# Time-based hold: items are kept 2555 days from the date they were received or created
Set-Mailbox -Identity adele@contoso.com -LitigationHoldEnabled $true -LitigationHoldDuration 2555
Get-Mailbox -Identity adele@contoso.com | Format-List LitigationHoldEnabled, LitigationHoldDuration, LitigationHoldDate, LitigationHoldOwner

Without a duration the LitigationHoldDuration property reads Unlimited. The admin center warns that the change can take up to 240 minutes to apply. The hold also covers the archive mailbox, and it raises the Recoverable Items quota from 30 GB to 100 GB (110 GB with auto-expanding archiving).

What happens to retained items#

Nothing is copied anywhere. Items stay in place; what changes is what happens when a user deletes or edits them. A deleted item goes to Recoverable Items\Deletions as usual. When the user purges it, or the deleted-item retention window ends, litigation hold keeps it in Purges for the hold duration, and a retention policy keeps it until a timer job confirms no policy or label still requires it. Editing an item under hold saves a copy of the original first (the Versions folder), on every change. Teams and other cloud data retained in the mailbox live in SubstrateHolds. For a retain-and-delete policy, expired items are permanently removed within 14 days of the end of the period (configurable up to 30). Because all of this lands in Recoverable Items, mailboxes on hold need an archive enabled before the folder fills up; the Managed Folder Assistant can't purge anything from a held mailbox.

Inactive mailboxes#

If a mailbox is covered by a retention policy or label that retains (not delete-only), a litigation hold, or an eDiscovery hold when the user account is deleted, it becomes an inactive mailbox instead of being removed after 30 days. Its content stays searchable in eDiscovery for as long as the retention settings apply. An MRM policy does not make a mailbox inactive. Microsoft recommends retention policies for this job and warns against changing a user's UPN or primary SMTP address before deletion, because you may later be unable to remove the inactive mailbox from the policy.

Verify#

PowerShell
Get-Mailbox -Identity adele@contoso.com | Format-List LitigationHoldEnabled, InPlaceHolds, ComplianceTagHoldApplied,
    DelayHoldApplied, DelayReleaseHoldApplied, RetentionPolicy, RetentionHoldEnabled
Get-OrganizationConfig | Select-Object -ExpandProperty InPlaceHolds
# History of holds applied to the mailbox
$ht = Export-MailboxDiagnosticLogs -Identity adele@contoso.com -ComponentName HoldTracking
$ht.MailboxLog | ConvertFrom-Json

Read InPlaceHolds like this: mbx is a retention policy on this mailbox, skp a Skype policy, grp a Microsoft 365 Groups policy, -mbx means the mailbox is excluded from an org-wide policy, and UniH is an eDiscovery hold. The suffix tells you the action: :1 delete (or a label policy), :2 hold, :3 hold then delete. An empty InPlaceHolds doesn't mean no hold; org-wide policies only show up on Get-OrganizationConfig. Look the GUID up (without prefix or suffix) with Get-RetentionCompliancePolicy <guid> -DistributionDetail in Security & Compliance PowerShell, or use Policy lookup in the Purview portal. ComplianceTagHoldApplied is True once any retained-label has been applied in the mailbox, and Start-ManagedFolderAssistant -Identity adele@contoso.com asks the assistant to process the mailbox sooner than its normal cycle.

Tips & gotchas#

  • Removing a hold doesn't purge anything for 30 days. Exchange sets DelayHoldApplied or DelayReleaseHoldApplied and treats the mailbox as held until that expires; Set-Mailbox -RemoveDelayHoldApplied clears it early (Legal Hold role required).
  • Don't confuse MRM with retention. An MRM deletion tag can't delete anything a Purview policy or hold protects, and RetentionHoldEnabled pauses MRM processing altogether.
  • Static scope with includes: if you remove the last included recipient, the policy silently reverts to All. Turn the location off instead.
  • Delete-only policies don't create inactive mailboxes, and neither does removing the policy afterwards: once the retention settings stop applying, the inactive mailbox becomes eligible for deletion.
  • Preservation Lock makes a policy irreversible; test everything before you lock it.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)