Exchange Online gives you four different ways to keep (or get rid of) mail: Microsoft Purview retention policies, retention labels, the older Exchange MRM retention tags, and litigation hold. They overlap just enough to be confusing, and picking the wrong one leads to surprises such as mail that never expires or a leaver's mailbox that quietly disappears. In this post I'll explain what each tool is for, which one wins when they disagree, how to create a retention policy and a litigation hold, and how to prove with PowerShell that a mailbox is actually protected.
How it works: four tools, four jobs#
| Tool | What it does | Where it applies | Use it for |
|---|---|---|---|
| Purview retention policy | Retain, delete, or retain-then-delete everything in a location for a period | Whole mailboxes (also shared, room and equipment mailboxes), plus SharePoint, OneDrive, Teams and more | The organisation-wide baseline, for example "keep all mail 7 years, then delete" |
| Purview retention label | Same actions, but stamped on an individual item or folder; travels with the item inside the tenant | Email, documents | Exceptions and records: contracts, HR files, disposition review |
| Exchange MRM (retention tags and an MRM policy) | Moves items to the archive mailbox or deletes them after an age; one MRM policy per mailbox | Exchange mailboxes only | Archiving (the Default MRM Policy moves mail to the archive after two years); Microsoft calls it a legacy feature for everything else |
| Litigation hold | A mailbox property that preserves everything, including deleted and edited items, indefinitely or for a number of days | One mailbox (and its archive) | Legal preservation of specific people; needs Exchange Online Plan 2 |
When several of these apply to the same item, Microsoft's principles of retention decide the outcome, in this order: retention always wins over deletion; the longest retention period wins; for deletion, an explicit label beats an implicit policy, and a scoped policy beats an org-wide one; finally the shortest deletion period wins. eDiscovery holds and litigation holds sit under the first rule, so nothing is purged while any hold is active. The practical reading is simple: adding a hold or a retention policy can only make an item live longer, never shorter.
Licensing (as published in the Microsoft Purview service description, so re-check it): retention policies on Exchange mailboxes are covered by Microsoft 365 E3/E5, Office 365 E3/E5, Business Premium, Exchange Online Plan 2 and Exchange Online Archiving. Adaptive scopes need an E5-level licence (Microsoft 365 E5, Office 365 E5, or the Purview add-ons). Litigation hold needs Exchange Online Plan 2, or Plan 1 plus Exchange Online Archiving. Inactive mailboxes need no licence at all.
Step 1: Create a retention policy for Exchange mailboxes#
In the Microsoft Purview portal go to Solutions › Data Lifecycle Management › Policies › Retention policies › New retention policy. Name it, keep the default of Full directory for admin units, then choose the scope type:
- Static: the default All mailboxes covers every current and future mailbox, including inactive ones. You can instead include or exclude specific recipients (groups are expanded once, at save time, and don't update later), but then inactive mailboxes are no longer supported and per-policy limits apply.
- Adaptive: the policy follows a query built on attributes such as Department, Country or region, Job title or CustomAttribute1-15. Scopes are created first under Settings › Roles and scopes › Adaptive scopes, run daily, and can take up to five days to populate, so create them a few days before you need them. Adaptive scopes can also target or exclude inactive mailboxes with
IsInactiveMailboxin the advanced query builder.
Turn on the Exchange mailboxes location, then decide: retain for a period and do nothing, retain and then delete, or only delete. For Exchange the age is based on the received date (or sent date for outgoing mail). Allow up to seven days for the policy to reach mailboxes, and note that mailboxes under 10 MB aren't processed.
The same policy from Security & Compliance PowerShell:
Connect-IPPSSession
New-RetentionCompliancePolicy -Name "Mail - keep 7 years" -ExchangeLocation All
New-RetentionComplianceRule -Name "Mail - keep 7 years rule" -Policy "Mail - keep 7 years" `
-RetentionDuration 2555 -RetentionComplianceAction KeepAndDelete
Get-RetentionCompliancePolicy "Mail - keep 7 years" -DistributionDetail | Format-List Name, DistributionStatusStep 2: Put a mailbox on litigation hold#
Use litigation hold when legal asks you to preserve specific people; for routine "keep everything" requirements Microsoft recommends a retention policy instead. In the Microsoft 365 admin center open Users › Active users, select the user, and on the Mail tab choose Manage litigation hold. In PowerShell:
Connect-ExchangeOnline
# Indefinite hold
Set-Mailbox -Identity adele@contoso.com -LitigationHoldEnabled $true
# Time-based hold: items are kept 2555 days from the date they were received or created
Set-Mailbox -Identity adele@contoso.com -LitigationHoldEnabled $true -LitigationHoldDuration 2555
Get-Mailbox -Identity adele@contoso.com | Format-List LitigationHoldEnabled, LitigationHoldDuration, LitigationHoldDate, LitigationHoldOwnerWithout a duration the LitigationHoldDuration property reads Unlimited. The admin center warns that the change can take up to 240 minutes to apply. The hold also covers the archive mailbox, and it raises the Recoverable Items quota from 30 GB to 100 GB (110 GB with auto-expanding archiving).
What happens to retained items#
Nothing is copied anywhere. Items stay in place; what changes is what happens when a user deletes or edits them. A deleted item goes to Recoverable Items\Deletions as usual. When the user purges it, or the deleted-item retention window ends, litigation hold keeps it in Purges for the hold duration, and a retention policy keeps it until a timer job confirms no policy or label still requires it. Editing an item under hold saves a copy of the original first (the Versions folder), on every change. Teams and other cloud data retained in the mailbox live in SubstrateHolds. For a retain-and-delete policy, expired items are permanently removed within 14 days of the end of the period (configurable up to 30). Because all of this lands in Recoverable Items, mailboxes on hold need an archive enabled before the folder fills up; the Managed Folder Assistant can't purge anything from a held mailbox.
Inactive mailboxes#
If a mailbox is covered by a retention policy or label that retains (not delete-only), a litigation hold, or an eDiscovery hold when the user account is deleted, it becomes an inactive mailbox instead of being removed after 30 days. Its content stays searchable in eDiscovery for as long as the retention settings apply. An MRM policy does not make a mailbox inactive. Microsoft recommends retention policies for this job and warns against changing a user's UPN or primary SMTP address before deletion, because you may later be unable to remove the inactive mailbox from the policy.
Verify#
Get-Mailbox -Identity adele@contoso.com | Format-List LitigationHoldEnabled, InPlaceHolds, ComplianceTagHoldApplied,
DelayHoldApplied, DelayReleaseHoldApplied, RetentionPolicy, RetentionHoldEnabled
Get-OrganizationConfig | Select-Object -ExpandProperty InPlaceHolds
# History of holds applied to the mailbox
$ht = Export-MailboxDiagnosticLogs -Identity adele@contoso.com -ComponentName HoldTracking
$ht.MailboxLog | ConvertFrom-JsonRead InPlaceHolds like this: mbx is a retention policy on this mailbox, skp a Skype policy, grp a Microsoft 365 Groups policy, -mbx means the mailbox is excluded from an org-wide policy, and UniH is an eDiscovery hold. The suffix tells you the action: :1 delete (or a label policy), :2 hold, :3 hold then delete. An empty InPlaceHolds doesn't mean no hold; org-wide policies only show up on Get-OrganizationConfig. Look the GUID up (without prefix or suffix) with Get-RetentionCompliancePolicy <guid> -DistributionDetail in Security & Compliance PowerShell, or use Policy lookup in the Purview portal. ComplianceTagHoldApplied is True once any retained-label has been applied in the mailbox, and Start-ManagedFolderAssistant -Identity adele@contoso.com asks the assistant to process the mailbox sooner than its normal cycle.
Tips & gotchas#
- Removing a hold doesn't purge anything for 30 days. Exchange sets
DelayHoldAppliedorDelayReleaseHoldAppliedand treats the mailbox as held until that expires;Set-Mailbox -RemoveDelayHoldAppliedclears it early (Legal Hold role required). - Don't confuse MRM with retention. An MRM deletion tag can't delete anything a Purview policy or hold protects, and
RetentionHoldEnabledpauses MRM processing altogether. - Static scope with includes: if you remove the last included recipient, the policy silently reverts to All. Turn the location off instead.
- Delete-only policies don't create inactive mailboxes, and neither does removing the policy afterwards: once the retention settings stop applying, the inactive mailbox becomes eligible for deletion.
- Preservation Lock makes a policy irreversible; test everything before you lock it.