Compliance Manager & eDiscovery
Compliance Manager tells you how well you're meeting regulations. eDiscovery helps you find content during investigations. Together, they answer: 'Are we compliant?' and 'Where's the evidence?'
Two compliance tools, two purposes
Compliance Manager is your health checkup. eDiscovery is your search warrant.
Compliance Manager says: βHereβs your compliance score. Youβre doing well on data protection, but you need to improve your retention policies. Here are the steps to fix it.β Itβs a dashboard with a to-do list.
eDiscovery says: βWe need to find every email and document related to this legal case.β It searches across Exchange, SharePoint, OneDrive, and Teams to find specific content for investigations or legal holds.
Compliance Manager
The compliance score
- Score from 0 to a maximum based on your assessments
- Higher = more compliant (not perfectly secure β itβs about configuration alignment)
- Based on improvement actions youβve completed
- Found in Microsoft Purview β Compliance Manager
How it works
- Assessments β choose regulatory frameworks (GDPR, ISO 27001, etc.)
- Improvement actions β Compliance Manager generates a prioritised list of recommendations
- Each action shows: what to do, which service to configure, impact on score, current status
- Two types of actions:
- Microsoft-managed β actions Microsoft handles for you (infrastructure security)
- Customer-managed β actions YOU need to take (enable MFA, configure DLP, etc.)
Scenario: Clearfield Council's compliance assessment
Officer Patel adds a GDPR assessment to Compliance Manager:
Score: 62% (needs improvement)
Top 5 recommended actions:
- β Enable MFA for all users (+8 points) β already done
- β¬ Configure DLP policies for personal data (+12 points) β not started
- β¬ Enable sensitivity labels (+10 points) β in progress
- β¬ Set up retention policies for email (+6 points) β not started
- β¬ Enable audit logging (+4 points) β already enabled but not verified
Officer Patel works through the list over 3 months β score rises to 84%.
Exam tip: Compliance Manager RECOMMENDS and SCORES β it doesnβt ENFORCE. You must take the actions yourself. Compare with Identity Secure Score (Module 10) which does the same for security.
eDiscovery
Content search β the basic tool
Content search lets you search for specific content across M365:
- Where it searches: Exchange mailboxes, SharePoint sites, OneDrive accounts, Teams messages
- What you can search by: Keywords, date ranges, senders/recipients, file types, labels
- What you can do with results: Preview, export, or add to an eDiscovery case
eDiscovery cases β for investigations
When you need more than a one-off search:
| Feature | What It Does |
|---|---|
| Case creation | Organise searches and holds around a specific investigation |
| Legal holds | Prevent data from being deleted or modified during an investigation |
| Search | Run multiple searches within the case |
| Export | Export search results for external review (legal team, auditors) |
| Close | Close the case and release holds when investigation is complete |
Scenario: Clearfield Council receives a legal request
Clearfield Council receives a freedom-of-information request: βProvide all emails and documents related to the North Bridge construction project from 2025-2026.β
Officer Patelβs process:
- Create eDiscovery case β βNorth Bridge FOI Request 2026β
- Place legal hold β on all relevant usersβ mailboxes and the North Bridge SharePoint site (prevents deletion)
- Run content search β keywords: βNorth Bridgeβ, date range: 2025-01-01 to 2026-12-31, locations: email + SharePoint
- Preview results β 847 items found, review for relevance and redact sensitive content
- Export β deliver to legal team for the FOI response
- Close case β release holds after investigation is complete
π¬ Video walkthrough
π¬ Video coming soon
Compliance Manager & eDiscovery β AB-900 Module 18
Compliance Manager & eDiscovery β AB-900 Module 18
~10 minFlashcards
Knowledge Check
Clearfield Council needs to prevent deletion of all emails related to an active investigation while they review the content. Which tool should Officer Patel use?
Next up: Activity Explorer & Data Monitoring β the tools that show you whatβs happening to your data in real time.