Skip to content

Microsoft 365 · Purview · Legal Hold · Custodian Collection

eDiscovery and forensic collection

The hold went out three weeks ago. Nobody has confirmed who received it, nobody has checked whether the mailboxes are actually preserved, and the production is due in two.

A hold nobody confirmed is not a hold.

Preservation in Microsoft 365 fails in ordinary ways. A custodian is named in the notice but never placed on hold in the tenant. A hold is applied to a mailbox and not to the OneDrive behind it. Someone leaves, the license is reclaimed, and the mailbox goes with it. A retention policy that predates the matter keeps running underneath everything, deleting on schedule, because nobody checked whether the hold outranked it.

None of that shows up in a status meeting. It shows up months later, when a gap in a production has to be explained and the tenant cannot say what it preserved or when. The work of eDiscovery is mostly the work of proving preservation happened, in a form that survives someone else asking.

Collection is the easy half. Documenting it is the half that gets tested.

Scope

What gets collected and how

Microsoft 365 and Purview

Collection through Purview eDiscovery: scoped search across Exchange Online, SharePoint, OneDrive, and Teams, review set creation, and export. Search terms and date ranges are documented with the result they produced, so scope can be shown rather than described.

Legal hold placement and administration

Hold placement in the tenant, custodian notification, acknowledgment tracking, and release when the obligation ends. Holds are verified against the retention policies already running, not assumed to take precedence over them.

Custodian collection

Endpoint, mailbox, and file share collection for named custodians, targeted to the scope the matter actually requires. Each custodian is documented as a separate record, with hash values captured at acquisition and verified at delivery.

Cloud account collection

Collection from cloud file stores, collaboration platforms, and third party accounts where a matter extends past the corporate tenant. Described by capability rather than by tool, because the stack changes and the obligation does not.

Export and load file packaging

Deduplication, culling, format conversion, and load file generation packaged for the review platform your team already uses, including Relativity and Nuix. Delivered so it loads on the first attempt.

Review platform where you need one

Not every firm keeps a platform standing for the matters that only need one. Where a matter requires it, a review environment is provided, and the collected set is loaded and ready for your team to search.

Background

Built from scratch, not learned from a datasheet

The Purview eDiscovery program 4n6PI works from was built from nothing at a global public company: tenant configuration, hold policy, custodian workflow, search protocol, export standards, and the documentation that made each of those defensible when opposing counsel asked how it worked. That is operator knowledge rather than vendor familiarity.

The difference is visible in the failure cases. Knowing which Purview search returns what, where a retention policy quietly wins, why an export splits the way it does, and what a Teams message looks like once it is out of the tenant is not in the product documentation. It is what you learn from running the program through real matters and then having to explain the results.

Engage

When to call

  • A hold has issued and someone needs to confirm it is actually in place in the tenant
  • A production deadline is fixed and the collection has not started
  • A custodian has left the company and the mailbox needs to be preserved before the license is reclaimed
  • An export from Purview will not load into the review platform and nobody can say why
  • In-house counsel needs a collection performed and documented, without adding headcount to do it
  • A matter reaches cloud accounts and file stores that sit outside the corporate tenant

Working inside your tenant

This work is performed on a per matter basis inside your existing environment, under written work authorization and the access your administrators grant. Nothing is installed that stays behind, and access is released when the engagement closes.

Pricing

Hourly, with collection priced apart from analysis

Endpoint and cloud collection and eDiscovery support are billed at $150 per hour. Storage media is passed through at cost with no markup. Where the matter also involves device imaging, those are published flat rates: $2,500 per mobile device and $1,500 per drive, detailed on the forensic collection page.

Collection and analysis stay separately priced here as everywhere else. You can take the collected and processed set and review it yourself, or engage 4n6PI to perform the investigation, and you pay for analysis only when the matter calls for it. A standing retainer puts rates and billing terms in place before the next hold issues, at no cost to establish.

Start with the hold

If a hold is already out, the useful first step is confirming what is preserved and what is still on a retention clock. That conversation is free and takes about thirty minutes.