Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT159
  • Created: 27th May 2026
  • Updated: 27th May 2026
  • Contributor: The ITM Team

Microsoft Litigation Hold

Microsoft Litigation Hold allows investigators to preserve Exchange Online mailbox evidence associated with a subject or other relevant custodian. When applied to a mailbox, Litigation Hold preserves mailbox content, including deleted items and original versions of modified items, so that evidence remains available for later search, review, and export through Microsoft Purview or Exchange eDiscovery workflows.

 

This detection is relevant where a subject may attempt anti-forensic activity involving email deletion, mailbox cleanup, calendar manipulation, or modification of Microsoft 365 communication artifacts stored in Exchange. It may also assist Teams investigations where relevant chat messages are stored in participant mailboxes, although it should not be treated as a complete Teams preservation strategy without confirming the associated Teams, SharePoint, OneDrive, and group locations.

 

Investigators should document when Litigation Hold was requested, when it was applied, which mailboxes were included, whether the hold was indefinite or time-limited, and any known preservation gaps. Where the investigation involves multiple custodians, suspected recipients, or co-conspirators, each relevant mailbox should be assessed for inclusion.

 

Litigation Hold preserves mailbox evidence but does not restrict the subject’s access or prevent continued activity. It should therefore be treated as an evidence preservation mechanism, not a containment control.

Sections

ID Name Description
AF027Clear Email Artifacts

A subject clears email artifacts to hide evidence of their activities, such as deleting emails, auto-forwarding rules, or other mailbox rules.

AF027.001Email Deletion

The subject deliberately deletes emails - either sent, received, or both - with the intent to obstruct investigative visibility, remove evidence of policy violations, or eliminate traces of communication relevant to an insider event. While routine inbox maintenance is common, patterns of targeted deletion may indicate purposeful concealment.

AF030.003Use of Disappearing or Self-Deleting Messages

A subject enables or uses a communication feature that automatically deletes messages after they are read, after a defined period, or when a conversation is closed, with the intention of reducing the communication evidence available to investigators.

 

The subject may use disappearing-message functionality within an approved corporate platform or through a non-corporate messaging application. Automatic deletion may be configured for an individual conversation, group, channel, workspace, or account. The subject may also change an existing conversation from persistent retention to temporary retention before exchanging information connected to an infringement.

 

This behavior differs from the manual deletion of corporate or non-corporate messages because the removal mechanism is established before or during the communication. Messages may disappear without a separate deletion action being performed after each message is sent.

 

Investigators should examine when the disappearing-message setting was enabled, who enabled it, the configured retention period, which participants were involved, and whether the setting was changed shortly before sensitive or suspicious communications occurred. The ordinary availability of an ephemeral messaging feature does not establish anti-forensic intent; classification should require evidence that the feature was deliberately used to reduce investigative visibility.

AF030.005Administrative Deletion of Communication Messages

A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.

 

The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.

 

This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.

 

Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.

 

The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event.

AF030.006Deletion of Communication Containers

A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.

 

Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.

 

The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.

 

Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed.