Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
09Mitigate threats using Microsoft Purview4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows0/42 units complete
Learning path 09 · Mitigate threats using Microsoft Purview

4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows

0%

Study focus

Data risk response

Investigate DLP and insider-risk alerts, correlate evidence, remediate activity, and manage cases.

Evidence discovery

Search, validate, retain, and export evidence with Microsoft Purview Audit and eDiscovery.

4 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

04

Module 4

Search for content with Microsoft Purview eDiscovery

Focus: roles, cases, custodians and data sources, query design, search validation, and export.
0/8
01 / 08Introduction

Purview eDiscovery searches Microsoft 365 content for legal, regulatory, HR, and security investigations. Cases organize authorized users, searches, data sources, holds, review, and exports around a defined matter.

Official lessoneDiscovery search objectives
02 / 08Understand eDiscovery and content search capabilities

Search can locate Exchange mailboxes, SharePoint and OneDrive files, Teams-related content, and other supported Microsoft 365 data. eDiscovery adds case-based permissions, preservation, review, analytics, and export workflows depending on licensing.

Content search finds potentially relevant items; legal relevance and responsiveness remain human determinations.

Official lessonContent locations and case capabilities
03 / 08Prerequisites for using eDiscovery in Microsoft Purview

Assign appropriate eDiscovery role groups, confirm licensing, create the case, add only authorized members, and identify custodians, noncustodial sources, locations, date ranges, and preservation requirements.

Separate case administration, investigation, review, and export duties where required. Access to eDiscovery can expose highly sensitive organizational content.

Official lessonRoles, licensing, and case setup
04 / 08Create an eDiscovery search
  1. Create or open a case and add authorized members.
  2. Select custodians, mailboxes, sites, or other supported data sources.
  3. Define keywords, properties, conditions, and date ranges.
  4. Use Copilot-generated query assistance only as a draft.
  5. Name, save, and document the search purpose and version.

Use parentheses and Boolean logic carefully; a small syntax change can materially widen or narrow the result set.

Official lessonSources and query construction
05 / 08Conduct an eDiscovery search

Run the search, review status, and use statistics, keyword reports, location counts, and random samples to validate whether the query retrieves the intended population. Refine iteratively while retaining prior query versions and rationale.

Check false positives, missing synonyms, date and timezone assumptions, file types, participants, duplicate content, and location coverage before export.

Official lessonRun and validate searches
06 / 08Export eDiscovery search results

Configure export content and metadata, start the export, monitor progress, and download through the authorized workflow. Preserve the case, search version, export settings, item counts, errors, timestamps, and chain-of-custody information.

Exports contain sensitive evidence; restrict storage, transfer, review access, and retention according to case requirements.

Official lessonExport and evidence handling
07 / 08Module assessment

Review roles and licensing, case members, custodians and data sources, query syntax and Copilot assistance, statistics and sampling, iterative validation, export settings, and evidence protection.

Official assessmenteDiscovery search knowledge check
08 / 08Summary and resources

A defensible eDiscovery search is authorized, scoped, versioned, validated with statistics and samples, exported with metadata, and protected throughout its evidence lifecycle.

Official lessonSummary and resources
End of learning pathMitigate threats using Microsoft Purview