15.1 Create and Configure Retention Policies

Key Takeaways

  • A retention policy applies the same retain, delete, or retain-then-delete settings at container level (mailbox, site, team); a retention label applies settings at item level and can travel with the content inside the tenant.
  • You cannot put every Microsoft 365 location in one policy. A static policy that includes Teams or Viva Engage automatically excludes Exchange, SharePoint, OneDrive, and the other non-conversation locations; an adaptive policy can include both Teams and Viva Engage.
  • After you save a policy you cannot change its name, its adaptive-versus-static type, or the retain/delete configuration except the duration. Allow up to seven days for distribution.
  • Preservation Lock is applied after the policy exists, only in Security & Compliance PowerShell (RestrictiveRetention $true), and is not supported on adaptive scopes. A locked policy can be extended, not reduced or turned off.
  • If a static location uses includes and you remove the last include, that location reverts to All—dangerous on a delete-only policy.
Last updated: August 2026

15.1 Create and Configure Retention Policies

A retention policy is the location-wide tool in Microsoft Purview Data Lifecycle Management. You pick a container—an Exchange mailbox, a SharePoint site, a OneDrive account, a Microsoft 365 group, a Teams chat location, a Viva Engage network, or an AI-app location—and every item in that container inherits the same retain, delete, or retain-then-delete settings. Users keep working in the original app. The policy does not move copies into a separate archive you manage by hand. If someone edits or deletes an item that must still be kept, Microsoft 365 stores a hidden copy in a workload-specific hold location (covered in the next section).

That container model is why the exam treats policies and labels as different skills. The previous chapters built labels, publishing, auto-apply, and precedence. This section is the broad brush: one policy, many items, no user click required.

Retention policies versus retention labels

Use a policy when the rule is the same for everything in the location ("all Exchange mailboxes, retain seven years then delete"). Use a label when the rule is about the item ("this contract is a record for ten years," "start the clock when the employee leaves," "review before delete"). You can—and usually should—run both. A typical design is an org-wide policy for the baseline, plus published or auto-applied labels for longer or shorter exceptions. Precedence when they overlap is the subject of the previous chapter; the short operational reminder is that retention wins over deletion and the longest retain period wins, while a label's delete action beats any policy delete action.

CapabilityRetention policyRetention label
ScopeContainer (site, mailbox, team, and similar locations)Item (document, email, list item)
Travels if the item is moved inside the tenantNo—the copy left behind can still be retained, but the settings do not follow the moved itemYes, inside Microsoft 365
Start of retentionWhen created; for SharePoint, OneDrive, and Microsoft 365 group files, also when last modifiedAlso when labeled or when an event occurs
User applies it manuallyNoYes
Conditions (SITs, keywords, trainable classifiers, cloud attachments)NoYes (auto-apply)
Declare a record, disposition review, proof of dispositionNoYes
Teams, Copilot, Viva Engage, Skype for BusinessYesNo for those conversation/AI locations (and no Skype)

Retention labels, unlike sensitivity labels, do not persist if the file leaves Microsoft 365. Do not promise that a policy or a label will follow a download to a USB drive.

Where you create the policy

Sign in to the Microsoft Purview portal > Solutions > Data Lifecycle Management > Policies > Retention policies > New retention policy. Members of Compliance Administrator can do this work. If you want a narrower assignment, create a role group and add Retention Management; View-Only Retention Management is the read-only counterpart. The person who configures the policy does not need permission to open the mailboxes or sites. Microsoft recommends against using Global Administrator for day-to-day retention work.

On Assign admin units, keep Full directory. Microsoft currently documents that admin units are not supported for this policy. Restricted administrators who are assigned one or more administrative units cannot configure SharePoint sites or Exchange public folders; those locations require an unrestricted administrator.

Decide Adaptive or Static before you start the wizard. Adaptive scopes are created in the previous chapter; if none exist, you can select Adaptive but you cannot finish. Adaptive membership is a query against Microsoft Entra attributes or site/group properties and refreshes daily. Static membership is All for the location, or explicit includes and excludes. Skype for Business and Exchange public folders support static scopes only. Adaptive scopes currently do not support Preservation Lock.

Locations you can select—and the ones you cannot mix

A retention policy can target many services, but you cannot create a single policy that includes every supported location.

Microsoft lists these locations: Exchange mailboxes; SharePoint classic and communication sites; OneDrive accounts; Microsoft 365 Group mailboxes & sites; Skype for Business; Exchange public folders; Teams channel messages (standard channels, shared channels, and private channels after the 2025 private-channel migration); Teams chats; Teams private channel messages (pre-migration only, and you cannot combine that option with the other Teams locations in the same policy); Teams call logs; Microsoft Copilot experiences; Enterprise AI apps; Other AI apps; Viva Engage community messages; Viva Engage user messages.

If you still have an older Teams chats and Copilot interactions policy, it keeps working but becomes uneditable once the tenant has the split locations. New policies must use the separate Teams chats and Microsoft Copilot experiences locations.

Static policies: if you include any Teams or Viva Engage location, the wizard automatically excludes Exchange, SharePoint, OneDrive, Groups, Skype, and public folders. You need a dedicated static policy for Teams and another for Viva Engage if you use both.

Adaptive policies: you can include both Teams and Viva Engage in one policy. The locations you can toggle still depend on the scope type. A User scope can select Exchange mailboxes and Teams chats, not SharePoint sites or Teams channel messages. A Site scope can select SharePoint, not mailboxes.

Location familyTypical contentExtra policy you still need
Teams channel / chat messagesChat and channel text (and, after migration, private-channel messages in the channel location)Files uploaded to a channel sit in the team SharePoint site; files shared in chat sit in the sharer's OneDrive
Microsoft 365 Group mailboxes & sitesGroup mailbox plus the connected SharePoint site, including channel meeting recordings and transcripts for group-connected teamsChat meeting recordings live in the organizer's OneDrive
Viva Engage community / user messagesCommunity and private messagesFiles and Viva Engage-related email need the Microsoft 365 Group mailboxes & sites location
Other AI appsPrompts and responses for supported non-Copilot appsA collection policy that captures that AI content must exist first

From late April 2026, new Teams call logs (call data records and related metadata) are retained only by a PowerShell-created Teams call log policy (New-AppRetentionCompliancePolicy with application User:MicrosoftTeamsCallLog). The policy then appears in the portal as visible but read-only. Call records that were already covered by older Teams chat policies stay with those policies. Do not invent a portal toggle that Microsoft has not published for this location.

Location-specific traps that show up on the exam

  • Exchange mailboxes and Microsoft 365 group mailboxes must contain at least 10 MB before retention settings apply (the same 10 MB floor applies when you publish labels to those mailboxes).
  • SharePoint sites must be indexed for policy settings to apply. Files configured not to appear in search are still in scope.
  • Retention policies retain and delete files in document libraries (including automatically created libraries such as Site Assets). They do not apply to SharePoint list items; labels do, except items in hidden system lists. Policies also do not apply to libraries, lists, folders, or Loop workspaces as objects. Users see an error if they try to delete a library, list, or site that is subject to retention.
  • For static includes and excludes, Microsoft's documented warning is explicit: if you configure includes and then remove the last include, the location reverts to All. A delete-only policy that accidentally becomes All SharePoint sites will target every site.
  • When you select Edit on Teams chats or Viva Engage user messages, you may see guests and non-mailbox users. Retention policies are not designed for those accounts; do not select them.
  • For Teams and Viva Engage, the wizard may offer when items were last modified, but Microsoft documents that When items were created is always used. Edited messages keep a copy of the original with the original timestamp.

Retain, delete, or both

On Decide if you want to retain content, delete it, or both, choose one of three outcomes:

  1. Retain-only — keep content forever or for a period; do not delete when the period ends.
  2. Delete-only — permanently delete after a period (the item can disappear from the user's view when the period elapses).
  3. Retain and then delete — the common compliance pattern: keep for n years, then delete.

For files in SharePoint, OneDrive, and Microsoft 365 Groups you may start the period when created or when last modified. Exchange age is based on date received (incoming) or date sent (outgoing), not last modified. After you save the policy you cannot change its name, its adaptive-versus-static type, or the retain/delete configuration except the duration.

Allow up to seven days for the policy to distribute and apply. Often it is faster; plan for seven. Open the policy flyout on the Retention policies page to check status. If you see (Error) and a message that deployment is taking longer than expected, connect to Security & Compliance PowerShell and retry distribution: Set-RetentionCompliancePolicy -Identity <name> -RetryDistribution for Exchange, SharePoint, and Teams channel messages; Set-AppRetentionCompliancePolicy -Identity <name> -RetryDistribution for Teams private channel messages and Viva Engage.

Preservation Lock after the policy is published

Some regulators (Microsoft cites SEC Rule 17a-4 as the example) require that once a retention policy is on, it cannot be turned off or made less restrictive. Preservation Lock is that control. You apply it after the retention policy exists, not in the create wizard, and not in the portal UI—the UI omits the control so nobody enables it by accident.

Connect to Security & Compliance PowerShell, list names with Get-RetentionCompliancePolicy, then run:

Set-RetentionCompliancePolicy -Identity "<Name of Policy>" -RestrictiveRetention $true

Confirm with Y. Recheck with Get-RetentionCompliancePolicy -Identity "<Name>" | Fl and verify RestrictiveRetention is True.

When a retention policy is locked: nobody can disable or delete it; locations can be added but not removed; you can extend the period but not decrease it. When a retention label policy is locked (only if it contains labels that mark items as regulatory records): the same disable/delete and location rules, and labels can be added but not removed. In one sentence: a locked policy can be increased or extended; it cannot be reduced or turned off. All retention policies with any configuration support Preservation Lock, but adaptive scopes currently do not. Do not confuse Preservation Lock with the Preservation Hold library. The lock freezes the policy. The library stores SharePoint and OneDrive copies of edited or deleted files.

If you no longer need an unlocked policy, you can delete it, turn the location off, or remove includes. SharePoint and OneDrive get a 30-day grace period when you release the policy (next section). Excluding a specific site from a policy that you keep does not get that delay.

Loading diagram...
Creating a Microsoft 365 retention policy: scope, locations, and Preservation Lock
Test Your Knowledge

A compliance admin must retain both Teams channel messages and Viva Engage community messages with one retention policy. Which statement is correct?

A
B
C
D
Test Your Knowledge

After a static org-wide Exchange retention policy is created, the organization must meet a regulator's rule that the policy cannot be turned off or made less restrictive. What does Microsoft document as the way to apply Preservation Lock?

A
B
C
D
Test Your Knowledge

A static retention policy is configured to delete content and currently includes a single SharePoint site. An admin removes that last include and saves. What happens?

A
B
C
D