detections
- ID: DT158
- Created: 27th May 2026
- Updated: 27th May 2026
- Contributor: The ITM Team
Microsoft Purview eDiscovery Hold
Microsoft Purview eDiscovery Hold allows investigators to preserve Microsoft 365 evidence associated with a subject, recipient, group, or investigation scope. A hold can preserve Exchange mailbox content, Teams messages, SharePoint files, OneDrive content, Microsoft 365 Group data, and related collaboration artifacts before they are deleted, edited, expired, or otherwise lost.
This detection is particularly relevant where the subject may attempt anti-forensic activity such as message deletion, message modification, or removal of shared files. When applied early and scoped correctly, an eDiscovery hold can preserve deleted messages, prior versions of edited Teams messages, mailbox artifacts, shared files, and related metadata for later search, review, and export.
For Teams investigations, investigators should ensure the hold includes the relevant participant mailboxes, Team mailbox, associated SharePoint site, and OneDrive accounts used to share files. The hold should be documented in the investigative timeline, including when it was requested, when it became active, which locations were included, and any known preservation gaps.
An eDiscovery hold preserves evidence but does not restrict the subject’s access or prevent continued activity. It should therefore be treated as an evidence preservation mechanism, not a containment control.
Sections
| ID | Name | Description |
|---|---|---|
| AF033 | Message Modification | The subject edits previously sent digital communication records in order to alter, obscure, or remove evidence of prior activity, coordination, intent, or disclosure. These records may include messages exchanged through collaboration platforms, internal messaging systems, or external communication applications.
Communication artifacts often provide investigators with critical context surrounding insider events, including planning, intent, relationships between individuals, and the sequence of actions leading to an infringement. Modifying a message after it has been sent can preserve the appearance of a normal communication thread while changing the evidentiary content available to investigators.
Message modification may occur before, during, or after an infringement. In some cases, subjects edit messages shortly after sending them to remove threatening, coercive, inappropriate, or policy-violating language. In other cases, a subject may transmit sensitive information, credentials, instructions, or confidential data as message text, then modify the message to benign content after it has been read or copied by the intended recipient.
This behavior is especially significant where the communication platform does not retain prior message versions, where edit history is excluded from standard exports, or where preservation controls were not in place at the time of the edit. Even where the original message content cannot be recovered, the act of editing a message may itself become a significant investigative indicator, particularly when correlated with alert timing, recipient activity, data access, or other case events. |
| AF030 | Message Deletion | The subject deletes digital communication records in order to remove evidence of prior activity, coordination, or intent. These records may include messages exchanged through collaboration platforms, internal messaging systems, or external communication applications.
Communication artifacts often provide investigators with critical context surrounding insider events, including planning, intent, and relationships between individuals. Deleting these records can reduce the available evidentiary timeline and hinder reconstruction of events.
Message deletion may occur before, during, or after an infringement. In some cases, subjects remove messages immediately after sending them to eliminate records of inappropriate requests or instructions. In other cases, deletion occurs after an alert, disciplinary action, or investigation has begun.
Because communication platforms often retain administrative logs of message deletion events, the act of deleting messages may itself become a significant investigative indicator. |
| AF030.001 | Deletion of Corporate Communication Messages | The subject deletes messages from organization-managed communication platforms such as enterprise collaboration tools, internal messaging systems, or other corporate communication environments.
These platforms commonly contain operational discussions, requests for information, coordination between staff, or exchanges relating to sensitive work activities. Deleting messages from these systems may remove evidence of policy violations, improper instructions, or coordination with other individuals.
In many enterprise platforms, message deletion events generate administrative audit artifacts. While the message content may no longer be visible to users, deletion activity can often still be identified through platform audit logs, retention systems, or administrative investigation tools. |
| AF030.003 | Use of Disappearing or Self-Deleting Messages | A subject enables or uses a communication feature that automatically deletes messages after they are read, after a defined period, or when a conversation is closed, with the intention of reducing the communication evidence available to investigators.
The subject may use disappearing-message functionality within an approved corporate platform or through a non-corporate messaging application. Automatic deletion may be configured for an individual conversation, group, channel, workspace, or account. The subject may also change an existing conversation from persistent retention to temporary retention before exchanging information connected to an infringement.
This behavior differs from the manual deletion of corporate or non-corporate messages because the removal mechanism is established before or during the communication. Messages may disappear without a separate deletion action being performed after each message is sent.
Investigators should examine when the disappearing-message setting was enabled, who enabled it, the configured retention period, which participants were involved, and whether the setting was changed shortly before sensitive or suspicious communications occurred. The ordinary availability of an ephemeral messaging feature does not establish anti-forensic intent; classification should require evidence that the feature was deliberately used to reduce investigative visibility. |
| AF030.004 | Bulk Deletion of Message History | A subject deletes a substantial volume of messages, conversations, threads, channels, or communication history to remove or materially reduce the records available for investigation.
Bulk deletion may involve selecting and deleting multiple messages, repeatedly deleting individual messages within a short period, clearing an entire conversation, removing channel history, deleting archived communications, or using scripts, administrative tools, application programming interfaces, or automation to remove content at scale.
The behavior may occur after the subject becomes aware of an investigation, disciplinary process, access review, audit, legal dispute, or anticipated offboarding. It may also occur immediately before the subject conducts another infringement where prior communications could reveal planning, coordination, relationships, or intent.
The significance of bulk deletion should be assessed against the subject’s normal messaging activity, the amount of content removed, the time period affected, the platforms involved, and whether the deleted communications related to known subjects, external parties, sensitive projects, or active investigations.
Investigators should identify deletion event volume, timestamps, conversation identifiers, affected participants, client or application source, administrative actions, and any corresponding data preserved through retention or legal-hold systems. |
| AF030.005 | Administrative Deletion of Communication Messages | A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.
The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.
This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.
Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.
The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event. |
| AF030.006 | Deletion of Communication Containers | A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.
Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.
The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.
Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed. |