Everything You NEED to Know about Purview eDiscovery for the MS-900 exam

Are you studying for the MS-900 Certification exam or just want to better understand eDiscovery in the Microsoft Cloud? This Clip, part of the MS-900 path on Pluralsight, is for you!

Full MS-900 Course on Pluralsight

Video Summary

Here are the key points from the video:

  • Introduction to eDiscovery: It involves identifying, collecting, and producing electronically stored information (ESI) for legal cases, including emails, documents, presentations, databases, voicemails, audio and video files, social media, and websites.
  • Six Stages of eDiscovery: The process includes identification, preservation, collection, processing, review, and production, ensuring relevant data is properly handled and prepared for legal proceedings.
  • Microsoft’s eDiscovery Tools: Microsoft offers three tools: Content Search, eDiscovery Standard (formerly Core eDiscovery), and eDiscovery Premium (formerly Advanced eDiscovery). These tools vary in functionality and licensing requirements, with eDiscovery Premium covering all six stages.
  • Content Search Demo: The demo shows how to use Content Search in the Microsoft compliance portal, including creating a new search, specifying where to search (e.g., Exchange mailboxes, SharePoint sites), and setting conditions like keywords.
  • Search Results: The demo concludes with viewing the search results, highlighting how Content Search can find specific messages in Teams chats, demonstrating its usefulness in locating relevant content for legal cases.

For more information, read the transcript blog below, or watch the video above!

Video Transcript

The next compliance tool we will cover is Microsoft Purview eDiscovery. Before talking about Microsoft specifically, let’s discuss eDiscovery in general as an industry term. Electronic Discovery, mostly called eDiscovery, is the electronic aspect of identifying, collecting, and producing electronically stored information in response to a request for production in a lawsuit or investigation. Electronically stored information includes but is not limited to, emails, documents, presentations, databases, voicemail, audio and video files, social media, and websites.

Electronic Discovery is made up of six stages. The first one is identification. The identification phase is when potentially responsive documents are identified for further analysis and review. Next, we have the preservation stage. During preservation, data identified as potentially relevant is placed in a legal hold. This ensures that the data cannot be destroyed. Once documents have been preserved, collection can begin. Collection is the transfer of data from a company to its legal counsel, who will determine the relevance and disposition of the data. Our fourth stage is the processing stage. During the processing stage, native files are prepared to be loaded into a document review platform. Often, this phase also involves the extraction of text and metadata from the native files. We then have our review stage, where specific documents are reviewed, and only data that is relevant to the case is kept. Lastly, the production phase is where documents are exported in their native format or an industry-standard format and turned over to opposing counsel. Those are the basic stages of eDiscovery.

Now, let’s see why that is relevant for us in the Microsoft world. Microsoft actually has three tools for eDiscovery. The first one is Content Search. The second one is the eDiscovery Standard, which was previously called Core eDiscovery. The third one is eDiscovery Premium, which was previously called Advanced eDiscovery. What are the big differences between them from a functionality perspective? It’s all about the features. Content Search is the most basic one and can help you with the identification and collection stages. eDiscovery Standard helps you with the identification, preservation, and collection stages. Finally, eDiscovery Premium can help you with all six stages. You might ask yourself, why does Microsoft have three tools when they have one that can do it all? If your guess is licensing, you are correct. The more features, the more licensing is required.

Now that we have seen the theory, let’s head over to the lab and check out Content Search in action. I am now in the lab environment. Let me open up the browser here, where I’m back in the compliance portal. Under solutions, let’s take a look at Content Search. What I will do for this demo is create a new search. For this demo, we will search for project CT1-123. Let’s take a look. We’ll call it CT1-123 Leaks. Here we can enter a description. Let’s click on next, and then we need to tell Content Search where to search for this information. I’ll say look in the Exchange mailboxes, the SharePoint sites, and public folders. I can also choose which ones. Maybe I’d want to search everything else except the site and the team where those conversations should be. So we can decide what services to search in, as well as what specific sites, teams, and mailboxes we want to filter for this search.

Now, let me click on next. Here, I have my conditions. What do I want to search for? For this demo, I’ll just search for the keyword CT1-123. I can also add more conditions, such as the sender, subject, file type, and things like that. We will keep it simple. Let’s click on next. We have a summary of everything we have configured, and now let’s click on submit. After we click on submit, my search will be created. It shows up over here, and as you can see on the status, the search is starting. So what I will do now is pause the recording for the 2 to 5 minutes it will take for this search to finish. It might take longer depending on how much content you have, but in this demo tenant, I do not have a lot of content, so it should be quite fast.

Great, so it just finished. Let me take a look at the items it found. It will take a few seconds to load. Again, it shouldn’t be too long, but if everything goes fine, we should have some Teams messages in here that Content Search has found. There we go, it finished loading, and here’s an example that we see from a Teams message. I have, “Hello Vanessa, don’t tell anyone, but our new product called CT1-123 will launch at the end of September.” So it was able to find this message in a Teams chat, and as you can see, the keyword is highlighted in here. This is an example of an eDiscovery tool, the most basic one in Microsoft’s eDiscovery solutions, but this gives you an idea of how you’re able to find all of the content that relates to a topic that you might need for a legal case. This is it for this demo. Now let’s head back to the slides and talk about Microsoft Purview Audit.

Blogs and Videos