How to "bypass" an Exchange Retention Policy Preservation Lock

Iron Contributor

I have a scenario with a complete Exchange Retention policy with a preservation lock.

As you already know, once a preservation lock is in place, nobody can turn off the policy, delete the policy, or make it less restrictive, ( neither the Global Admin ).

Now we need to modify it for a couple of mailboxes, but as those mailboxes, ( like all the mailboxes ), are included in the locked retention policy, there's "no way" to do it.

 

Well, I figured out one chance... ;) 

 

Here starts to play the principles of retention.

 

As the mentioned retention policy is applied to the whole Exchange environment, and as per the principles of retention explicit wins over implicit for deletions, we can create a new policy that applies to the required specific mailboxes in order to delete the content sooner.

 

"  If a retention policy for a location uses an adaptive scope or a static scope that includes specific instances (such as specific users for Exchange email) that retention policy takes precedence over a static scope that is configured for all instances for the same location ".

 

Learn about retention policies & labels to retain or delete - Microsoft Purview (compliance) | Micro...

 

That should solve the issue "bypassing" the locked policy. But note that this principle only takes advatage in the case of deletions. For only retention, that wins always over deletions. Maybe not the best solution, but people should be aware about such kind of things before locking a retention policy. 

 

Feel free to let me know your thoughts.

 

 

0 Replies