Microsoft SC-401: When Retention Meets eDiscovery

A departing executive deletes a folder of sensitive emails while an investigation is underway. What happens to those messages depends on more than the user’s delete command. They might be subject to a retention policy, a retention label, an eDiscovery hold or several preservation mechanisms at once. These controls have different purposes and lifecycles. The original Microsoft SC-401 topical plan combines eDiscovery and records management because administrators responsible for protecting information must understand how preservation, deletion and investigation requirements interact.

SC-401’s current study scope explicitly includes data loss prevention and retention; Microsoft has flagged further exam updates in October 2026. The exact examination emphasis on eDiscovery tasks should be checked against the study guide associated with a booked date. The technical distinction matters regardless: retention is a governed lifecycle policy, while an eDiscovery hold preserves potentially relevant material for a specific case. Treating them as interchangeable leads to bad deletion decisions and expensive investigations.

Retention is an information-lifecycle decision

Organizations retain records because contracts, regulations and business processes require information to exist for a defined period. They also delete records to reduce risk and storage burden when keeping them is no longer justified. A retention policy can broadly cover a workload or location, while retention labels support content-specific requirements and may enable additional records-management behaviors. The correct mechanism depends on whether the rule follows a repository, a class of documents or a particular business event.

For example, an organization might retain routine internal correspondence for a moderate period, but keep executed customer contracts according to a separate schedule. If every mailbox and site inherits the longest period, the organization may preserve large quantities of unnecessary material. If the period is too short, required evidence can disappear before a dispute arises. Before implementation, records owners should document the record series, trigger for retention, legal rationale, authorized disposition and process for reviewing exceptions.

Retention labels are not the same thing as sensitivity labels. A sensitivity label communicates classification and can enforce protection such as encryption or sharing restrictions. A retention label determines lifecycle treatment, including preservation and, where configured, disposition behavior. A highly confidential draft may have a short retention requirement; a public contract can have a lengthy one. Administrators should avoid expressing both dimensions through one confusing label taxonomy when the controls serve different purposes.

A hold is scoped to a case and lasts until released

An eDiscovery hold preserves content that may be relevant to an investigation or legal matter. Its scope can involve specific mailboxes, OneDrive accounts, SharePoint sites and supported collaboration locations. The hold is normally governed by the case, not by a fixed routine retention schedule. When content is subject to both preservation mechanisms, an active eDiscovery hold can prevent permanent deletion even if the normal retention period has ended.

That precedence is essential in operational troubleshooting. An administrator may remove a retention label, initiate a purge and be surprised that messages remain in a recoverable location. The missing fact could be a case hold, another retention policy or a delay hold. Repeated deletion attempts are not a responsible fix. Identify every applicable preservation source, review its status and coordinate with the owner who has authority to release it.

Legal preservation needs careful scoping. A hold on every repository for an indefinite period can create unnecessary cost and confidentiality exposure. A hold that excludes shared team content relevant to a case can undermine an investigation. Work with custodians, legal professionals and business owners to select the appropriate people, locations and time periods. Verify the actual status of a hold before relying on it; submission of a request does not guarantee that every targeted location is immediately preserved.

The underlying workloads store information differently

Exchange, SharePoint, OneDrive and Microsoft Teams present different content models. A conversation may span chat messages, channel posts, linked files and recordings or transcripts subject to separate storage and retention behavior. A custodian’s mailbox alone will not necessarily contain every artifact needed to understand the discussion. Teams and Microsoft 365 group information can involve both mailbox and site locations. Investigators need a location map before they can confidently declare the collection complete.

Content can also exist in multiple versions. A user may replace a SharePoint document repeatedly, move it into another site or create copies that are governed by different policies. Legal requirements may call for earlier versions or context around a transaction. Workload-specific preservation mechanisms can hold content in recoverable or preservation locations that ordinary users do not see. A search of the current visible folder is therefore not a reliable measure of everything retained.

External collaboration introduces further questions. An organization may retain messages sent to guests while having limited control over a copy held in the guest’s own tenant. Retention settings in one tenant should not be assumed to govern every recipient’s environment. Case plans must distinguish what the organization controls from what may require cooperation, separate preservation or contractual procedures. Those limitations belong in legal and technical planning, not as surprises during collection.

Records are more than files with a long expiration date

Some records require stronger controls over modification or deletion, additional disposition review, or an event-based start to their retention period. A signed agreement’s lifecycle may begin at execution, while a personnel record’s lifecycle may be tied to the end of employment. If the administrator starts every clock on file creation, the configured rule may diverge from the intended legal schedule. Records managers should define the event, evidence for that event and who is responsible for declaring it.

Declaring a document a record can limit changes and deletion in ways ordinary retention does not. The exact effect depends on the selected record-management capabilities and configuration. This can protect evidentiary integrity, but it may interrupt workflows if the organization labels drafts too early. Pilot representative documents at each lifecycle stage, including revisions, execution, transfer and final disposition. Good records management respects both the need for trustworthy historical information and the realities of how documents are created.

Disposition review is not just a scheduled “delete now” button. Reviewers may need context to decide whether the record remains necessary because of active business needs, legal holds or unresolved disputes. Keep an audit trail of approvals, exceptions and the final action. The objective is a defensible lifecycle, not simply high deletion throughput. A growing backlog of records awaiting review is a process problem that should be owned and measured.

Searching a case is not the same as proving completeness

eDiscovery commonly involves identifying sources, preserving data, collecting responsive material, reviewing it and delivering appropriately scoped results. Search terms can miss relevant data because of language variation, incomplete indexing or file formats that require special processing. A narrow keyword query can retrieve useful evidence while still overlooking a conversation referred to only by a project nickname. Investigators need defensible search strategies and documentation of limitations.

Metadata can explain context that extracted text does not. Custodian, creation time, modification history, message participants, attachment relationships and access events may matter to a dispute. Exporting a text fragment without associated metadata can make it harder to establish authenticity or sequence. Preserve case notes describing collection scope, filters, tool versions and any failures. A reviewer should be able to reproduce the reasoning behind an inclusion or exclusion decision.

Restricted access is critical because case searches may expose highly sensitive content unrelated to the allegation. Apply role separation and least privilege across case administrators, custodians, reviewers and exporters. Content collected for one purpose should not quietly become a general-purpose employee-monitoring database. Data minimization and controlled distribution protect the integrity of an investigation and the people whose information happens to appear in the results.

Preservation does not establish confidentiality by itself

A retained document may still be overshared or readable by unauthorized users. Retention settings preserve content; they do not replace sensitivity labels, access permissions or DLP controls. In a sensitive case, an investigator might require both continued preservation and temporary restrictions on who can reach a document. Changes to permissions should be coordinated so responders do not inadvertently alter the evidence or obstruct necessary collection.

Encryption can also complicate review. A file protected by usage rights may be properly preserved in storage yet not directly readable by every investigator or processing tool. Access must be granted through legitimate compliance and decryption mechanisms where supported. The relationship between encryption and access becomes operationally important when the original author is unavailable. Test preservation and recovery paths for protected material before a time-sensitive case begins.

Organizations adopting AI assistants should also remember that a search or generated answer can reveal information through existing access permissions. Retention is not a solution to oversharing. Data ownership, permission review, sensitivity protection, legal preservation and deletion governance need coordinated implementation, with each control independently tested against its intended outcome.

Test the policy with deliberate lifecycle scenarios

A realistic pilot might create an ordinary working document, label it as a regulated record after approval, place its custodian on an eDiscovery hold, then simulate user deletion and eventual case release. The administrator should verify which content survives, what locations reflect the preservation, and which retention obligation remains after the hold ends. Record actual system behavior and any propagation delays instead of assuming that the control worked because its status appears enabled.

For SC-401 preparation, reason from the business requirement to the appropriate lifecycle tool. A routine seven-year record rule is a different problem from preserving communications for litigation; sensitivity is different again from retention duration. A good administrator can tell which control applies, why a deletion attempt did not remove content, what can safely be released and which decision belongs to legal or records-management owners rather than the security engineer alone.