An eDiscovery collection has to answer a legal or investigative question while respecting limits on who can search, which locations may be searched, and which material belongs in the matter. Microsoft Purview eDiscovery supports searches, cases, holds, review sets, and exports under assigned permissions. In large or multi-entity organizations, compliance boundaries can further restrict the content locations and cases accessible to particular investigation teams. Those boundaries are security and governance controls, not synonyms for search filters or for the substantive legal scope of a matter.
A reliable design separates three decisions. Legal counsel and the case team define what information is relevant. The platform administrator establishes where that data resides and how it can be preserved and collected. The authorization model determines which investigators may reach each content location or case. Confusing these decisions can create overcollection, missed evidence, or unauthorized access even when the search query itself is syntactically correct.
Define the custodians and repositories involved
A collection begins with people, accounts, and locations likely to hold relevant information. These can include Exchange mailboxes, OneDrive accounts, SharePoint sites, Teams-related material, and other supported locations depending on licensing and current product capabilities. An investigator should document each selected custodian or repository and the relationship to the matter. Search scope should not be expanded simply because the tenant contains many easily accessible locations.
Custodian identification requires care where individuals use shared mailboxes, multiple accounts, or organizational aliases. A departed employee’s mailbox may have a different lifecycle state from an active account, and a project site may contain material from many people. The collection plan should distinguish ownership, authorship, location, and permission boundaries; one is not an automatic substitute for the others.
Before executing searches, validate the inventory against current tenant configuration. A location that has been renamed, moved, or deleted can change what a query finds. Record the expected source count and note which sources cannot be searched under the existing permissions. Unavailable locations should be reported as a coverage limitation, not silently treated as empty.
Distinguish case permissions from search permissions
Case access governs which investigation teams can see and work within a particular matter. Search authorization determines which content locations they may query. Microsoft Purview compliance boundaries can combine role-group and search permissions filtering behavior to restrict both case access and the eligible data scope. An investigator who can see a case is not necessarily entitled to search every mailbox in the tenant.
In a multinational organization or group of subsidiaries, one investigation team may be authorized only for its legal entity’s content. A boundary can help enforce that restriction through supported attributes and filters. The implementation must consider where the data lives, which attributes are used to identify the entity, and which investigators have rights to manage those filters. A misapplied directory attribute can expose or hide material unexpectedly.
The information governance architecture becomes relevant when records, identities, and collaboration sites cross organizational boundaries. Security teams should verify the actual effective permissions in a controlled test. A written separation policy offers little reassurance if a user can still search another entity’s mailbox through a differently scoped role.
Understand how compliance boundaries work in practice
Microsoft documents compliance boundaries as logical restrictions on searchable content locations and access to eDiscovery cases. Search permissions filters are evaluated against supported attributes in Exchange, SharePoint, and OneDrive contexts, subject to product implementation details. They do not magically segregate all underlying cloud data into physical regions or replace contractual and jurisdictional obligations.
A boundary design should account for multigeo and organizational changes. If a user moves between legal entities, the attributes used by the filter may change while the historical data and holds remain. The investigation team needs to know whether a new boundary now excludes previously collected sources or permits newly relevant content. These transitions require a legal decision and a technical verification, not only a directory update.
Avoid relying on a single broad administrative role to service every matter. Excessive case and search privileges increase the impact of account compromise and accidental data exposure. Restrict the administration of compliance boundaries to accountable roles and record every material change, including its business reason and expected effect on active cases.
Separate collection completeness from query correctness
A search query can return no results because the terms are too narrow, the wrong repositories were selected, indexing is incomplete, or permissions prevented access. These outcomes have very different implications. Investigators should review the collection plan, data-source coverage, query criteria, and reported processing warnings before concluding that no relevant evidence exists.
Test representative known items where legally appropriate. If the team knows a project email exists but a query never finds it, investigate date filters, language, tokenization, attachments, and location scope. Search conditions that work for email may behave differently for documents or chat content. A sound protocol records the query version and why its terms were selected rather than overwriting the original search silently.
A query can also overcollect. Searching a common phrase across the whole company might pull unrelated personal or confidential material into the matter. Use proportional time, custodian, and content filters defined with counsel. The objective is defensible relevance and completeness within the approved scope, not the largest possible export.
Preserve content without confusing preservation with collection
Holds and retention controls address preservation; collection and export make material available for review. A preservation hold may cover content broader than what is eventually responsive to a legal request. Investigators should coordinate these operations but record their distinct purposes, start dates, and authorized custodians. Applying a hold does not prove that a search collected every relevant item.
Changing a hold can have consequences for content that would otherwise be deleted by normal retention processes. The legal team should understand what must remain preserved while the investigation is active. The platform administrator must verify that the hold has the intended scope and that any affected accounts or content locations are still supported under the current lifecycle state.
The technical process must also recognize that data can change while collection runs. Mailboxes receive new messages, collaboration files are edited, and some locations undergo migration. Record collection cutoffs, preservation assumptions, and whether subsequent incremental searches are necessary. A reproducible record describes what was collected when, not an impossible promise that all future activity was captured automatically.
Control review sets and exported evidence
Moving results into a review set or exporting them introduces another handling boundary. Investigators may need to tag, deduplicate, filter, and analyze items while maintaining chain-of-custody records. The export destination, encryption state, access permissions, and storage retention should follow the sensitivity of the collected material. A compliant query does not make an unsecured downloaded archive acceptable.
Review sets and exports have service limits, processing behavior, and potential unsupported-content caveats that must be considered for large matters. Monitor job status and error reports instead of equating a completed operation with full processing success. If an attachment could not be fully extracted, document the exception and determine whether another supported collection method is necessary.
Ensure that authorized reviewers can access only their assigned matters and that exports are distributed through an approved channel. Separate technical operators from substantive legal reviewers where appropriate. Permissions should be removed when the engagement ends, and copies left in temporary storage should be deleted according to the approved retention and evidence policy.
Validate boundary controls with negative tests
A positive test demonstrates that the authorized investigator can search an expected mailbox and work with the appropriate case. A negative test demonstrates that the same investigator cannot access an unauthorized case or content location. Both are necessary. Without the negative test, broad administrative privileges may quietly bypass the intended separation and render the boundary meaningless.
Test a representative user from each permitted investigation group and a denied account from outside the boundary. Check direct case navigation, location selection, searches, and permitted exports. Record the effective role-group membership, search filter, tested content location, and result. Repeat after changes to user attributes or case access policy.
An eDiscovery case can preserve material correctly and still breach a legal boundary if collection filters or reviewer permissions are overbroad; SC-401 analysis requires checking all three controls independently. Responsible administrators should be able to explain exactly how eDiscovery scope, location filtering, and case access differ, and verify their combined behavior. Certification terminology is less important than preserving sensitive evidence within a defensible permission model.
Document the collection protocol for independent review
For each matter, maintain an approval record, identified custodians, relevant source systems, preservation actions, search queries and their revisions, processing dates, review-set operations, export manifests, and unresolved limitations. This information allows a later reviewer to reconstruct how the collection was performed without relying on recollection. Record why a source was excluded and who authorized the decision.
Audit logs and job reports should be retained under the organization’s evidence policy. They may show who ran a search or export and when, but they should be correlated with case decisions and approval records. Technical activity alone does not demonstrate that collection was proportionate or legally authorized. Legal, privacy, and security teams need a shared interpretation of the boundaries.
A robust eDiscovery boundary is both permissive and restrictive in the right places: authorized investigators can retrieve what the matter requires, while other teams cannot access unrelated personal or organizational data. Achieving that balance depends on accurate repository inventories, tested permissions, careful search design, and a transparent evidence trail throughout preservation and review.