When legal sends an eDiscovery request that includes Teams communications, there's a learning curve for IT teams that haven't done it before. Teams content doesn't export the same way email does, the content locations are distributed across Exchange and SharePoint, and the tools for searching and exporting it require a Microsoft Purview licence and some familiarity with the Purview UI.

This article walks through the eDiscovery process for Teams content, focusing on the practical steps and the common points of confusion.

Where Teams Content Lives for eDiscovery Purposes

Before running a search, you need to know what you're searching. Teams content for eDiscovery is distributed across several locations:

  • Teams private chat and group chat messages: Stored in the Exchange Online mailbox of each participant. Specifically, in a hidden subfolder called "SubstrateHolds" (or similar internal folder names). To search these, you target the Exchange mailboxes of the users involved in the chats.
  • Teams channel messages: Stored in the Exchange Online group mailbox of the Microsoft 365 group backing the team. To search channel messages for a specific team, you target the group mailbox associated with that team.
  • Files shared in Teams chats: Stored in the sender's OneDrive. Target the sender's OneDrive location.
  • Files shared in Teams channels: Stored in the SharePoint site associated with the team. Target the SharePoint site.
  • Meeting recordings: Stored in the organiser's OneDrive (for private meetings) or the channel's SharePoint (for channel meetings).
  • Meeting recordings: The organiser's OneDrive for meetings outside a channel, or the channel's SharePoint library for channel meetings. A search that only targets mailboxes will not return the recording file.
  • Loop and other embedded components may store content outside the classic chat blob. If a matter turns on that content, confirm the current storage location in the product documentation before telling counsel the mailbox search is complete.

Microsoft Purview eDiscovery: Standard vs Premium

Microsoft Purview offers two levels of eDiscovery tooling:

eDiscovery (Standard) — included with Microsoft 365 E3/E5 and some other plans. Provides content search, case management, and export. Suitable for most routine eDiscovery needs.

eDiscovery (Premium) — requires Microsoft 365 E5 or an add-on licence. Adds advanced analytics (near-duplicate detection, email threading, review sets), custodian management, holds management at scale, and more sophisticated workflow tools. Appropriate for large-scale litigation and complex investigations.

For standard IT-driven eDiscovery requests (HR investigations, legal holds, regulatory requests), eDiscovery (Standard) is usually sufficient.

Creating a Content Search for Teams Content

In Microsoft Purview, navigate to eDiscovery > Standard > Cases (or create a new case) > Searches. A content search has two key components: the locations to search and the query.

Locations for Teams content:

  • For private/group chats: add the Exchange Online mailboxes of the custodians (the people involved in the chats)
  • For channel messages: add the Exchange Online mailboxes of the Microsoft 365 groups for the relevant teams
  • For files: add the OneDrive locations of the custodians and/or the SharePoint sites for the relevant teams

You don't need to separate "Teams chats" from "Teams channels" explicitly in the location picker — both types of Teams Exchange content can be found by searching the appropriate mailboxes. The Teams content type is distinguished in search results by its content class.

Building the query:

Content search uses Keyword Query Language (KQL). For Teams-specific content, you can filter by content class:

-- Search only Teams chat messages
kind:im

-- Search only Teams channel messages
kind:microsoftteams

-- Search for Teams content containing specific keywords
kind:im OR kind:microsoftteams AND "project Alpha" AND participants:[email protected]

-- Search for Teams content in a date range
kind:im AND received:2025-01-01..2025-06-30

Exporting Search Results

After running a search, you can export the results for review. Teams content exports in PST format (for Exchange-based content) or as files (for SharePoint/OneDrive content). Each Teams chat or channel conversation thread is typically exported as an individual email-like item in the PST, with the message content as the email body and attachments as separate items.

There's a dedicated Teams export format option in newer versions of the Purview export tool that presents Teams conversations in a more readable threaded format. Check whether this option is available in your Purview environment before defaulting to raw PST export.

What Gets Preserved for Deleted Messages

One of the most common questions in Teams eDiscovery: can we recover deleted messages? The answer depends on the retention configuration:

If a Teams retention policy is in place, messages deleted by users are preserved in the compliance copy for the duration of the retention period. These are searchable and exportable through eDiscovery even though they don't appear in the Teams UI. The compliance copy is in the "SubstrateHolds" folder in the user's Exchange mailbox.

If no retention policy is in place, deleted messages may not be preserved. Exchange Online has a default deleted item retention period (14–30 days), but after that period, messages may not be recoverable through standard means. This is one of the arguments for implementing Teams retention policies proactively — not to keep content longer, but to ensure compliance copies are preserved for a defined period.

Guest User Content in eDiscovery

Guest users' participation in Teams chats creates compliance content in your tenant. When a guest sends a message in a Teams channel or chat, the message content is stored in the Teams service's compliance store — but the guest's exchange mailbox (in their home tenant, not yours) is not directly accessible for eDiscovery. For content in Teams channels (where the group mailbox is in your tenant), guest messages are discoverable through your normal eDiscovery process targeting the group mailbox. For private chats with guests, the content stored in your users' mailboxes (their side of the conversation) is discoverable; the guest's side may not be directly accessible without engagement with the guest's organisation.

A Search That Missed the Channel Because the Group Mailbox Was Omitted

eDiscovery for Microsoft Teams fails in a specific, repeatable way: the custodian's mailbox is searched, chat turns up, and channel messages do not. Channel messages live in the Microsoft 365 group mailbox for the team, not in the member's mailbox. A search built only from the HR list of employee names will look thorough and will omit the channel where the relevant conversation happened.

A manufacturing company responding to a contract dispute searched four custodians and produced a thin chat history. The negotiation had been in a channel named after the customer. That channel's messages sat in the group mailbox, which was never added as a location. The second search, with the group mailbox included and the same keywords, returned the thread counsel had been told did not exist. The tool had not been wrong. The location list had been incomplete.

Build the location list in two passes. Pass one is people: custodians, their mailboxes, their OneDrives. Pass two is teams: every team those people belong to that could hold relevant channel traffic, plus the group mailbox and the SharePoint site for each. Keyword the query only after the locations are listed. A clever keyword against the wrong mailbox is still a miss, and it is a miss that is hard to see from the result count alone.

Exports need a reader. A PST full of chat items is not a transcript until someone confirms the thread order and the participants. Prefer the export option that keeps Teams conversations readable, and open a sample before sending the whole package to a reviewer. A package that reviewers cannot read will come back, and the delay will be blamed on the hold rather than on the format.

Guest and external participation limits what the host tenant can produce. Messages posted by a guest into a channel in the host tenant are in the host group mailbox and are searchable there. The guest's side of a private chat may live in the other organisation. Say that boundary out loud when the collection plan is written, so counsel does not discover it after the production date.

Include the date range in the saved search, and do not rely on the case name to remember it. Re-run the search after a hold is placed if content was still being deleted during the first collection. Channel renames do not move the group mailbox. Search by the group, not by the current display name alone. A zero-result search is a finding about the query or the locations. It is not, by itself, proof that the conversation never happened. Keep the search and the export in the case record. A search that is not saved will be rebuilt differently next time. If premium review sets are not licensed, say so in the plan. Reviewers should know they are reading a standard export. Add the group mailbox even if the custodian says they never use channels. The statement and the membership list are both worth having. Save the query text in the case, character for character. A paraphrase will not rerun the same search. Open one exported item and confirm the participants are visible before you ship the set. A team the custodian left still holds messages from the period they were a member. Leaving does not remove them from the group mailbox. Date ranges should be agreed in writing. A day either side is cheaper than a second production. If the matter includes meetings, put recordings on the location list at the start. They are files, and they are often the clearest record. Note when a search hits the limit of the tool and had to be split. A split search that loses a day in the middle is a gap.

Derek Osei

Derek Osei

IT Security & Compliance Analyst

Derek works at the intersection of Microsoft Teams security and regulatory compliance.