16.2 Retention Labels & Policies

Key Takeaways

  • Retention policies apply at the container/location level (all Exchange mailboxes, all SharePoint sites, all OneDrive, all Teams chats) while retention labels apply per-item
  • Retention settings are retain-then-delete, delete-only, and retain-only; the retention period and end-of-retention action (delete, disposition review, or move to archive) are configured per policy or label
  • Auto-apply retention label policies use conditions including sensitive info types, trainable classifiers, keywords/KQL queries, and cloud attachments
  • Disposition reviews let a reviewer decide whether to permanently delete, extend, or relabel items at the end of the retention period
  • Retention governs how long content is kept and deleted; sensitivity labels govern protection and classification — the two are separate Purview features that can apply to the same item
Last updated: August 2026

Quick Answer: Retention in Microsoft Purview is delivered through two objects: retention policies that apply at the location level (all Exchange mailboxes, all SharePoint sites, all OneDrive accounts, all Teams chats) and retention labels that apply per-item, either manually or automatically. Retention settings determine whether content is retained then deleted, deleted only, or retained only, and what happens at the end of the retention period.

Data Lifecycle Management in Purview

Data lifecycle management is the Purview discipline that governs how long content is kept and when it is deleted. Most organizations face two opposing pressures: legal and regulatory requirements to keep content for a minimum period, and risk-reduction goals to delete content when it is no longer needed. Retention policies and retention labels operationalize both goals.

Retention Policy vs Retention Label vs Label Policy

These three objects are easy to confuse on the MS-102 exam. The table below distinguishes them.

ObjectScopeHow appliedTypical use
Retention policyContainer/locationAutomatically to an entire location (all Exchange mailboxes, all SharePoint sites, all OneDrive, Teams chats/channel messages)Broad baseline retention, e.g., keep all Teams chats for 3 years then delete
Retention labelPer-itemManual by users in Outlook/Word/SharePoint, or automatic via an auto-apply policySpecific retention for a class of content, e.g., keep employee contracts 7 years
Retention label policyUsers/groups or locationsPublishes labels so users see them, or auto-applies labels based on conditionsThe delivery mechanism for retention labels; a label has no effect until published through a policy

A retention label by itself is just a definition. The label must be published through a retention label policy for users to apply it manually, or through an auto-apply retention label policy for Purview to apply it automatically based on conditions.

Retention Settings

Retention policies and retention labels both offer the same retention settings:

  • Retain-then-delete — keep the content for a specified period, then delete it. The most common setting for compliance-driven content.
  • Delete-only — delete the content after a specified age; no retention guarantee. Useful for routine content that should age out.
  • Retain-only — keep the content indefinitely or for a specified period without deleting it; the user cannot delete it during the retention period.

When you configure retain-then-delete, you also choose what happens at the end of the retention period:

  • Delete automatically — Purview deletes the item.
  • Disposition review — a designated reviewer inspects the item and chooses to permanently delete, extend the retention, or relabel it.
  • Move to archive — for Exchange mailboxes, the item is moved to the archive mailbox at the end of the period.

Adaptive vs Org-Wide Scope

Retention policies can be org-wide (apply to all instances of a location, such as all Exchange mailboxes) or scoped to specific recipients. Adaptive policy scopes use attributes and properties to define the scope dynamically, so that new mailboxes, sites, or users that match the attributes are added automatically without you editing the policy. For example, an adaptive scope can target all users whose department attribute equals "Engineering". Adaptive scopes require Azure AD (Entra ID) attributes or SharePoint site properties to filter on.

Auto-Apply Retention Label Conditions

An auto-apply retention label policy applies a retention label to content that matches conditions you define. The supported conditions are:

  • Sensitive info types — apply the label when content contains a SIT match (e.g., a credit card SIT triggers a 7-year retention label)
  • Trainable classifiers — apply the label when content matches a trainable classifier such as Source Code, HR documents, or Legal documents
  • Keywords or KQL queries — apply the label based on a keyword query or Keyword Query Language expression
  • Cloud attachments — apply the label when files are shared as cloud attachments in Exchange or Teams (a relatively recent addition that addresses shared-file lifecycle)

Auto-apply policies run in the background; labeling is not instantaneous. Content is typically labeled within a day of matching the conditions, though large tenants may take longer.

Disposition Reviews

When a retention label or policy is configured with a disposition review at end of retention, Purview surfaces the items in the Disposition page of the Purview compliance portal. A reviewer can:

  • Permanently delete the item
  • Extend the retention period
  • Relabel the item with a different retention label
  • Export the list of items for offline review

Disposition reviews provide a human check before destructive deletion, which is important for legal-hold scenarios and for content where the retention period may need extension.

Retention vs Sensitivity Labels

Retention labels and sensitivity labels are often confused because both are labels and both live in Purview. They serve different purposes:

Retention labelSensitivity label
PurposeHow long to keep content and when to delete itHow to protect and classify content (encryption, watermarks)
Typical valuesRetain 7 years then deleteConfidential, Highly Confidential
EffectControls lifecycle (keep/delete)Controls access (encryption) and marking (watermark/header/footer)

A single item can carry both a retention label and a sensitivity label at the same time; the two are independent.


Exam Tip

For the MS-102 exam, remember the three-object distinction (policy, label, label policy), the four auto-apply conditions (SITs, trainable classifiers, keywords/KQL, cloud attachments), and the three end-of-retention actions (delete, disposition review, archive). A common scenario question asks which object to use when legal needs content kept for 7 years — the answer is a retention label published via a label policy, not a sensitivity label.

Test Your Knowledge

Your legal team requires that all employee contracts be retained for 7 years and then reviewed before deletion. Which Purview object should you create?

A
B
C
D
Test Your Knowledge

Which condition is supported for auto-applying a retention label policy?

A
B
C
D
Test Your Knowledge

What is the difference between an adaptive policy scope and an org-wide retention policy scope?

A
B
C
D