Skip to content

Purview eDiscovery · Legal Hold · Defender Advanced Hunting

Microsoft Purview and Defender support

The hold notice went out last week. Somebody still has to place the custodians, confirm the locations are covered, and be able to show months from now exactly when each one was placed. Usually that somebody has a full-time job already.

The licensing was never the hard part.

Most organizations already own everything they need. Purview is sitting in the tenant, Defender is deployed across the fleet, and the capability is fully paid for. What is missing is the person who has run a matter through it end to end and knows which of the twenty ways to search will produce a defensible export and which will quietly miss half a mailbox. So a hold gets placed and never verified. A search returns forty thousand items and nobody can explain the query that produced them. A hunting question gets asked once and never turned into anything reusable.

The tools work. What they need is somebody who has driven them under a deadline.

Purview

eDiscovery and legal hold

Case setup and structure

Cases created and scoped so that custodians, holds, searches, and exports stay attributable to a single matter. Structure decided at the start, because it cannot be reorganized later without losing the record of what was done and when.

Legal hold configuration and administration

Custodians placed, non-custodial locations added, hold scope documented, and coverage verified against the mailboxes, sites, and Teams the matter actually reaches. Hold notifications and acknowledgments tracked and retained.

Content search and query refinement

Keyword, date, participant, and location searches built and iterated against statistics, so the collection is narrow enough to review and wide enough to be responsive. Every query and its result count is recorded.

Review sets and processing

Collected content loaded into review sets with deduplication, near-duplicate detection, email threading, and error remediation for items that fail processing. Exceptions are reported rather than dropped.

Export and production packaging

Exports produced in the format the receiving review platform expects, with load files, metadata fields, and native and text output reconciled against the export summary before anything is handed over.

Workflow build and remediation

For organizations standing up an internal program, the intake, hold, collection, and handoff procedures written down and tested against a live matter, so the process survives the departure of whoever built it.

Defender

Threat hunting and advanced hunting queries

Defender for Endpoint holds the telemetry that answers scope questions faster than any endpoint examination can, provided the right question is asked inside the retention window. That window is short, and it is the reason hunting engagements are scheduled early rather than after the forensic work is finished.

  • Advanced hunting query development. Queries written against process, network, file, registry, and identity tables to surface execution, persistence, and lateral movement that automated detections did not raise on their own.
  • Alert triage and scope determination. Alerts worked to a conclusion: which are noise, which are related to each other, which devices and accounts are actually involved, and how far back the earliest related activity goes.
  • Fleet-wide indicator sweeps. Hashes, paths, and destinations recovered from an endpoint examination turned into tenant-wide queries, so a finding on one host becomes an answer about the whole estate.
  • Reusable detection logic. Queries handed over documented and parameterized, so the internal team can rerun them after the engagement instead of reopening the same question next quarter.
  • Retention documented. Where the telemetry does not reach back far enough to answer a question, that limit is stated in the findings.

Engagement model

Inside your tenant, on your licensing

4n6PI works within the Microsoft 365 environment the organization already owns. No product is resold, nothing is exported to infrastructure on our side unless the matter calls for a delivered production, and access is scoped to the engagement and removed when it ends.

  • What you need in place. Purview eDiscovery entitlement at the level the matter requires, Defender for Endpoint entitlement covering advanced hunting for hunting work, and the ability to grant scoped roles for the duration.
  • A named internal contact. One administrator who can grant access and answer questions about how the tenant is configured. That single relationship determines how quickly the work starts.
  • Per matter, by written authorization. Engagements are scoped, authorized, and closed out. This is not standing administration of the tenant.
  • Actions logged. Everything performed is recorded in the tenant audit log under the account granted, so the client retains an independent account of what was done.

Where the depth comes from

4n6PI built an enterprise Purview eDiscovery program from scratch at a global public company: case structure, hold procedure, collection standards, export packaging, and the handoff to counsel, run against live litigation rather than designed on paper. Most consultancies have used the product. Fewer have owned the program.

Engage

When to call

  • A hold has issued and the organization needs custodians placed and coverage documented this week
  • Opposing counsel has served requests that reach mailboxes, Teams, SharePoint, and OneDrive
  • A search is returning far too much or obviously too little and nobody can tell which
  • An export has to arrive in a review platform in a specific format by a specific date
  • An incident needs tenant-wide scoping and the internal team does not write hunting queries
  • An internal eDiscovery program exists on paper and has never been tested against a real matter

Where a matter also reaches devices outside the tenant, the same engagement can extend to forensic collection and endpoint investigation.

A hold nobody verified is not a hold

It looks identical to a working one until the day somebody asks for the audit trail. Verification takes an afternoon. Explaining its absence takes considerably longer.