15.2 Recover Retained Content in Microsoft 365
Key Takeaways
- SharePoint and OneDrive store retained copies in the Preservation Hold library; Exchange uses Recoverable Items; Teams, Viva Engage, Copilot, and AI apps use the SubstrateHolds subfolder of Recoverable Items.
- End users restore SharePoint/OneDrive files from the first-stage Recycle Bin (93 days spanning both Recycle Bin stages) and Exchange items from Recover Deleted Items (14 days default, maximum 30).
- The Preservation Hold library is a hidden compliance store; Microsoft does not support interactively editing, deleting, or moving automatically retained files there. Use eDiscovery to access that content.
- Exchange administrators restore with Exchange admin center Recover deleted items or Restore-RecoverableItems, which requires the Mailbox Import Export role.
- eDiscovery searches and exports retained content for an investigation; it does not put a file back in the library, a message back in the Inbox, or a chat back in the Teams thread.
15.2 Recover Retained Content in Microsoft 365
Retention in Microsoft 365 is in place. People keep using the live document or message. When they edit or delete content that a retain action still covers, the service stores a copy in a hidden location so the item remains available for compliance—and, for some workloads, for operational restore. The exam bullet is recover retained content, which means you must know where the copy lives, who can put it back into the user's view, and when eDiscovery is the wrong tool.
Do not mix up three names that look similar:
- Preservation Hold library — SharePoint and OneDrive (and Microsoft 365 group sites) hidden library.
- Recoverable Items — Exchange mailbox dumpster (non-IPM subtree).
- Preservation Lock — irreversible PowerShell lock on a policy, not a store of files.
Where the copy is stored
| Workload | Hidden store | Who typically restores to the app | Who can still read it without restoring |
|---|---|---|---|
| SharePoint and OneDrive | Preservation Hold library on the site | User: first-stage Recycle Bin. Site collection admin: second-stage Recycle Bin | eDiscovery (supported way to access PHL content) |
| Exchange mailboxes and public folders | Recoverable Items folder | User: Recover Deleted Items (Deletions). Admin: EAC or Restore-RecoverableItems | eDiscovery; only eDiscovery-permissioned admins can view another user's Recoverable Items |
| Teams, Viva Engage, Copilot, and AI apps | SubstrateHolds (subfolder of Recoverable Items) | No user restore into the Teams or Viva Engage thread | eDiscovery, until the copy is permanently deleted from SubstrateHolds |
The Preservation Hold library counts against the site storage quota. You may need to increase SharePoint, OneDrive, or group site storage when retention is on. Recoverable Items has its own quota, separate from the mailbox quota: Exchange Online defaults to a 20 GB warning and 30 GB limit, automatically raised to 90 GB and 100 GB when Litigation Hold, In-Place Hold, or a Microsoft 365 retention policy applies (and slightly higher if archiving is also enabled). If Recoverable Items is full, users cannot delete items and copy-on-write cannot keep versions.
SharePoint and OneDrive: Recycle Bin versus Preservation Hold library
When a user changes an item that a retention policy covers (or a label that marks a record), or deletes any item subject to retention, SharePoint copies the original into the Preservation Hold library if one does not already exist. Microsoft is explicit: this library is a hidden system location not designed to be used interactively. It is not supported to edit, delete, or move those automatically retained files, or to change their retention or sensitivity labels. The supported way to access the files is a compliance tool such as eDiscovery.
That is not the same as saying users have no restore path. The live file still follows the ordinary Recycle Bin path:
- User deletes the file → first-stage Recycle Bin (visible to users).
- User empties that Recycle Bin or deletes the item there → second-stage Recycle Bin (site collection Recycle Bin). End users cannot see it; site collection administrators can view and restore from it.
- In SharePoint in Microsoft 365, items are retained 93 days from deletion from the original location. That 93-day period spans both stages; it is not 93 plus 93. Microsoft does not publish a tenant-configurable Recycle Bin duration for SharePoint Online.
The Recycle Bin is not indexed. eDiscovery cannot find content that exists only in the Recycle Bin and cannot place a hold on it. If you need a deleted file to remain searchable, it must still be in the library, in the Preservation Hold library, or under another hold that keeps it out of the Recycle Bin-only state.
A timer job periodically evaluates the Preservation Hold library. For content that has been there more than 30 days, the job compares it to the retention queries. Content older than its retention period and not awaiting disposition review is moved to the second-stage Recycle Bin. Microsoft no longer permanently deletes from the Preservation Hold library; permanent deletion happens from the Recycle Bin. The timer job runs every seven days, so after the 30-day minimum it can take up to 37 days for eligible content to leave the library. Permanent deletion is always suspended if another policy, a label, or an eDiscovery hold still requires the item to be retained.
Versioning matters. For a retention policy, the first edit of new content is not copied into the Preservation Hold library unless versioning is turned on; later versions are retained. Users are blocked from deleting versions while a retention policy (or eDiscovery hold) applies, and library version limits are ignored until the retention period ends.
Thirty-day grace period when you release a SharePoint or OneDrive policy
When you release (delete or turn off) a retention policy for SharePoint sites or OneDrive accounts, content that was subject to that policy continues to be retained for 30 days so an accidental removal does not destroy copies. During the grace period, deleted files still copy into the Preservation Hold library, but the cleanup timer job is suspended for those files so you can restore if necessary. If you exclude one or more sites or OneDrive accounts from a policy that you keep, that 30-day delay does not apply—the timer job can clean those locations without waiting. If you turn the policy back on within 30 days, it resumes without permanent loss during the window.
When a user leaves, SharePoint content they created is unaffected: a site is collaborative. OneDrive files that are in a retention policy or have a retention label remain subject to those settings for the configured period, sharing continues to work, and the content remains discoverable. After a delete action at the end of retention, content moves into the site collection Recycle Bin and is accessible only to an admin.
Exchange: Recoverable Items, users, and admins
Exchange uses a different vocabulary:
- Delete — item goes to Deleted Items.
- Soft delete — emptying Deleted Items, or Shift+Delete, places the item in Recoverable Items\Deletions.
- Hard delete — the item is marked to be purged from the store (for example, the user purges it from Recover Deleted Items).
Users recover from Deletions with Recover Deleted Items in Outlook or Outlook on the web, until the deleted item retention period expires. The Exchange Online default is 14 days. Administrators can raise it to a maximum of 30 days. Microsoft does not publish a higher user-recoverable value than that 30-day cap.
If the user purges an item, or an automated process hard-deletes it, the item moves to Purges when single item recovery or Litigation Hold is enabled. Single item recovery is enabled by default on new Exchange Online mailboxes. Users cannot recover from Purges. Administrators can, if the deleted item retention period has not expired:
- Exchange admin center: Recipients > Mailboxes > select the mailbox > Recover deleted items.
- Exchange Online PowerShell:
Get-RecoverableItemsto find the item, thenRestore-RecoverableItemsto put it back. Both cmdlets require the Mailbox Import Export role, which is not assigned to any role group by default—you must add the role (for example, to Organization Management) before the restore works.
A Microsoft 365 retention policy also uses Recoverable Items for copy-on-write. If the user changes subject, body, attachments, senders, recipients, or sent/received dates, Exchange stores a copy of the original before the change is committed. Drafts are exempt from that copy-on-write list. At the end of the retention period, copies are permanently deleted, typically within 14 days after expiry (configurable up to 30). The evaluation timer job can take up to seven days, and the mailbox must have at least 10 MB. Exchange shows users the policy name and expiry date on messages when the policy will delete items; retain-only policies do not show that banner. A retention label on the message replaces the policy name and date in that banner.
When a user leaves and the Microsoft 365 account is deleted, a mailbox that is in a retention policy becomes an inactive mailbox. Its contents remain subject to the policy and remain available to eDiscovery. An inactive mailbox is not automatically deleted when retention ends; an Exchange admin deletes it after the retain action no longer applies.
Teams, Viva Engage, and Copilot: SubstrateHolds is not a user restore folder
Deleted or edited Teams chats, channel messages, Viva Engage messages, and Copilot or AI-app interactions are stored in SubstrateHolds. They disappear from the client. There is no Outlook-style Recover Deleted Items experience that republishes a Teams chat into the conversation. Until the service permanently deletes the copy from SubstrateHolds, eDiscovery can still find it. Permanent deletion from SubstrateHolds is suspended if another Teams retention policy for the same location, Litigation Hold, a delay hold, or an eDiscovery hold still applies. Viva Engage retention policies do not inform users when messages are deleted because of the policy.
If a SharePoint or OneDrive policy deletes a file that is still referenced in a Teams or Viva Engage message, the message can show a File not found error. That is ordinary file deletion, not a Teams retention bug.
eDiscovery is investigation, not restore
eDiscovery (the SC-401 wording as of July 28, 2026 is to perform searches by using eDiscovery) can return items from Recoverable Items, the Preservation Hold library, and SubstrateHolds, and you can export them for a case. That is how legal and security investigators read retained content that users can no longer see. Exporting a PST or a ZIP does not:
- restore the document to the SharePoint library or OneDrive folder,
- re-deliver the message to the user's Inbox or recover it into Deleted Items as a user-facing restore would, or
- republish the chat into the Teams thread.
An eDiscovery hold also prevents permanent deletion under the first principle of retention, but Microsoft tells you not to use holds as a long-term data lifecycle tool. Use retention policies and labels for lifecycle; use eDiscovery to investigate and export. If the operational goal is "put this email back in Malik's mailbox," the documented admin path is Recover deleted items / Restore-RecoverableItems, not an eDiscovery case. If the goal is "can counsel read the deleted Teams message," the documented path is eDiscovery search, not the Preservation Hold library UI.
Exam traps for recovery
- 14 days is the Exchange Online user deleted-item window (max 30). 93 days is the SharePoint Recycle Bin window across both stages. Do not swap them.
- Site collection admins restore from the second-stage Recycle Bin. They do not get a Microsoft-supported interactive file manager for automatically retained Preservation Hold library items; eDiscovery is how you access those files.
- Releasing a SharePoint/OneDrive policy gives a 30-day cleanup pause. Excluding a site from a still-active policy does not.
- Preservation Lock does not create a restore button. It only stops anyone—including a global admin—from turning the policy off or making it less restrictive.
A user deletes a Word file from a SharePoint library that a retain-and-delete retention policy covers, and another user Shift+Deletes an email from a mailbox covered by an Exchange retention policy. Where does Microsoft 365 store the compliance copies?
Legal counsel needs to read a Teams chat that a user deleted yesterday. A Teams retention policy is still retaining the mailbox. Which statement matches Microsoft's documented model?
An administrator deletes a retention policy that applied to SharePoint sites. Which statement describes the 30-day grace period Microsoft documents?