13.1 Plan Information Retention and Disposition with Retention Labels
Key Takeaways
- Retention settings support three outcomes: retain-only, delete-only, and retain-then-delete; retained copies stay in workload-specific hidden locations while people keep working in place
- Retention policies apply the same settings at a container (site or mailbox); retention labels apply settings at the item and travel with content inside the Microsoft 365 tenant
- This chapter creates labels and adaptive scopes; publishing, auto-apply, precedence (including Policy lookup), retention policies, and recovery are later chapters
- Use Data Lifecycle Management labels for ordinary item exceptions; use Records Management when you need records, regulatory records, event-based retention, or disposition review
- Teams, Viva Engage, Skype for Business, and Exchange public folders do not support retention labels; plan retention policies for those locations
When you plan information retention and disposition for SC-401, start from the business rule, not from a portal wizard. Microsoft Purview Data Lifecycle Management exists to retain the content the organization must keep and to permanently delete content that no longer has business value. Deleting stale data is not only a storage exercise; Microsoft documents it as a way to reduce risk and shrink the attack surface after a breach. Retention is a long-term compliance control. It is not an eDiscovery hold, it is not a sensitivity label, and it is not Exchange messaging records management (MRM) from the classic Exchange admin center.
The three retention outcomes
Every retention policy and every retention label is built from two actions: retain (prevent permanent deletion and keep the item available for eDiscovery) and delete (permanently delete the item from the organization). Combining those actions produces three published outcomes:
| Outcome | Portal intent | Typical planning use |
|---|---|---|
| Retain-only | Keep content for a period, or forever, without forcing deletion | Minimum keep for regulation or investigation readiness |
| Delete-only | Permanently delete content after a specified age | Hygiene when you are not required to keep the item |
| Retain and then delete | Keep for the period, then permanently delete | The most common regulated pattern (keep, then dispose) |
Retain does not mean users are blocked from clicking Delete in the app. Content remains in its original location. If someone edits or deletes an item that still has a retain action, Microsoft 365 keeps a copy in a hidden location most people never see:
- SharePoint and OneDrive: Preservation Hold library (this library counts against the site storage quota)
- Exchange mailboxes: Recoverable Items folder
- Teams, Viva Engage, Copilot, and AI apps: a hidden SubstrateHolds folder under Recoverable Items
Plan storage as part of retention. A seven-year retain-then-delete policy on busy SharePoint sites can grow Preservation Hold until the site hits quota. For Exchange, Teams, and Viva Engage, retained copies live in mailboxes; Microsoft points admins at Exchange Online limits and auto-expanding archive when volume is high.
The retention period is not counted from the moment you save the policy. You choose when the clock starts (covered below). Months in the portal assume 30 days; years assume 365 days. Those are Microsoft's published conversions—do not invent a 365.25-day year on the exam.
Retention policies versus retention labels
To assign retention settings you use retention policies and retention labels with label policies. You can use one method or both.
A retention policy applies the same retain/delete settings at a container: Exchange mailbox, SharePoint site, OneDrive account, Microsoft 365 group, Skype for Business, Exchange public folders, Teams locations, Copilot and AI app locations, or Viva Engage. Items inherit settings from that container. If an item is moved out of the container while a retain action is in effect, a copy can remain in the workload's secure location, but the policy settings do not travel with the item to the new place.
A retention label applies retain/delete settings at an item: one document, one email, or (when used as a default) items that inherit from a library, folder, or Outlook folder. Label settings travel with the content as long as it stays inside your Microsoft 365 tenant. Retention labels, unlike sensitivity labels, do not persist if the file leaves Microsoft 365.
Use a policy when every document in a site should be treated the same (for example, retain all site files for five years). Use a label when items in the same container need different periods (five years for ordinary files, ten years for a subset). Microsoft's Data Lifecycle Management guidance treats policies as the default for a workload and labels as exceptions to that default.
Labels also unlock capabilities policies do not support: starting the period when the item was labeled or when an event occurs; trainable classifiers as a way to find content to label; a default label on a SharePoint library or Outlook folder; disposition review; automatically applying another label at the end of the period; marking content as a record; and proof of disposition when you use disposition review or when the item is marked as a record. End users can apply labels; they cannot apply retention policies.
This chapter's boundary
This chapter is about planning those settings, creating the labels, and creating adaptive scopes. Publishing labels so they appear in apps, auto-apply policies, precedence (including Policy lookup), creating retention policies, and recovering retained content are later chapters. After you finish the create-label wizard, choose Just save the label for now. Do not treat the publish or auto-apply pages as part of this skill.
Data Lifecycle Management versus Records Management
Create labels from Solutions > Data Lifecycle Management > Retention labels when you are supplementing policies for ordinary lifecycle exceptions (a longer keep for contracts, a shorter delete for a project code name, a classify-only label with no retain or delete action).
Create labels from Records Management (file plan) when the item is a high-value business, legal, or regulatory record and you need event-based retention, disposition review, or the options to mark items as records or regulatory records. Both solutions use the same retention engine. The portal path you choose is a design decision about how strict the item will be, not a second product. Labels created in Data Lifecycle Management appear in the file plan; labels created in the file plan that do not mark content as a record are also available from Data Lifecycle Management.
When the retention period starts
Plan the clock, not only the number of years:
- When created — default. For Exchange, age is based on the date received (incoming) or sent (outgoing).
- When last modified — files in SharePoint, OneDrive, and Microsoft 365 Groups only. Each edit resets the start, which can make a "shorter" period outlast a "longer" created-date period.
- When labeled — retention labels only; documents in SharePoint and OneDrive, and email items.
- When an event occurs — retention labels configured for event-based retention (employee departure, contract expiration). This is a records-management planning choice, not a Data Lifecycle Management default.
Retention policies support created and (for those file locations) last modified. They do not support labeled or event-based starts. If the business rule is "keep the visa file for seven years after the employee leaves," you are planning a label, not a policy.
Combining policies and labels (planning patterns)
You do not have to choose only policies or only labels. Microsoft documents complementary patterns you should recognize:
- Override automatic deletion: a OneDrive delete-only policy after five years from last modified, plus a published keep-forever label users apply to the few files that must survive.
- Keep a subset longer: a SharePoint retain-then-delete policy of five years, plus a ten-year label applied as a library default for contracts.
- Delete a subset sooner: an Exchange delete-only policy of ten years, plus a one-year delete label targeted at a project code name (auto-apply and Outlook rules are how you apply it—later chapters).
The principles of retention (retention wins over deletion, longest retain wins, a label's delete is explicit compared with a policy, then shortest delete among remaining policy deletes) decide the combined outcome. You will apply those rules in the precedence chapter. For planning, remember the outcome is not "which object wins" but how long the item is retained and when it is permanently deleted, calculated independently.
Do not use eDiscovery holds as a substitute retention program. Holds are short-term, user-scoped, and have no automatic deletion when released. If content is on an eDiscovery hold, that preserve action takes precedence over permanent deletion until an admin releases the hold—then ordinary retention rules resume.
Workload and operational traps
Retention labels can be published or auto-applied to Exchange (except public folders), SharePoint, OneDrive, and Microsoft 365 Groups. Exchange public folders, Skype for Business, Teams, and Viva Engage messages do not support retention labels. Those locations need retention policies. An item can have only one retention label at a time; unlike sensitivity labels, you do not configure a priority list of retention labels.
Allow up to seven days for retention policies to take effect and for published labels to appear in apps. Often it is faster; Microsoft still tells you to plan for seven days. Adaptive scopes (next section) currently do not support Preservation Lock. If a regulator requires a lock that nobody can turn off or make less restrictive, that is a static-scope policy design, not an adaptive-scope design.
Permissions: Microsoft recommends adding compliance staff to Compliance Administrator, or a custom role group with Retention Management (View-Only Retention Management for read-only). Priority Cleanup Admin is a separate role and is not in Compliance Administrator by default. The person who creates labels does not need permission to open the files.
Mailbox locations require at least 10 MB of data before retention settings apply to that mailbox. Static All mailboxes includes inactive mailboxes; specific static includes cannot pick an already-inactive mailbox at assignment time. If you must target only inactive mailboxes, that is an adaptive User scope with IsInactiveMailbox, not a static include list.
Exam trap: A classify-only retention label (no retain or delete action) is still a retention label. You can use it as a text tag to find content later, and you can use a retention label as a condition in a DLP policy for SharePoint documents. Do not assume every label must delete or keep.
Which Microsoft 365 retention outcome keeps content for a specified period and then permanently deletes it?
All documents in a SharePoint site must be retained for five years, but a small set of contract files in that same site must be retained for seven years. What should you plan?
A user deletes a SharePoint document that is still subject to a retain action. Where does Microsoft 365 keep the retained copy?