SOLVED

Records retention on Skype for Business conversations

%3CLINGO-SUB%20id%3D%22lingo-sub-10104%22%20slang%3D%22en-US%22%3ERecords%20retention%20on%20Skype%20for%20Business%20conversations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-10104%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20been%20tasked%20with%20discovering%20more%20information%20on%20retention%20policies%20for%20IMs%20sent%20through%20Skype%20for%20Business.%26nbsp%3B%20We%20are%20thinking%20about%20adding%20it%20as%20an%20alternative%20to%20texting%20for%20information%20that%20is%20subject%20to%20public%20records%20requests.%26nbsp%3B%3C%2FP%3E%3CP%3EBased%20on%20what%20I%20think%20I%20found%20-%20the%20conversations%20for%20desktop%20clients%20are%20stored%20in%20Exchange%20-%20so%20we%20can%20set%20retention%20and%20archiving%20policies%20on%20those.%3C%2FP%3E%3CP%3EHowever%20the%20big%20argument%20is%20personal%20phone%20vs.%20work%20issued%20cell%20phone.%26nbsp%3B%20It%20appears%20that%20conversations%20are%20stored%20on%20the%20personal%20device%20-%20so%20we%20would%20have%20to%20use%20MDM%20to%20have%20access%20to%20the%20data%20to%20archive%20it%3F%3C%2FP%3E%3CP%3EI%20also%20am%20looking%20at%20the%20eDiscovery%20center%20and%20see%20I%20can%20do%20eDiscovery%20on%20Skype%20for%20Business%2C%20but%20is%20that%20just%20on%20the%20client%20installs%20where%20the%20conversations%20are%20stored%20in%20Outlook%2C%20or%20does%20it%20cover%20mobile%20devices%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20someone%20verify%20if%20I'm%20on%20the%20right%20track%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-13024%22%20slang%3D%22en-US%22%3ERe%3A%20Records%20retention%20on%20Skype%20for%20Business%20conversations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-13024%22%20slang%3D%22en-US%22%3E%3CP%3EThis%20is%20an%20area%20that%20is%20still%20weak%20with%20SfB.%20We%20need%20proper%20audit%20capability%20for%20it%2C%20we%20also%20need%20enforced%20conversation%20save.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnother%20weak%20area%20is%20that%20of%20DLP.%20We%20should%20be%20able%20to%20monitor%20conversations%20for%20inapppropriate%20information%20being%20shared%20and%20for%20inappropriate%20conversations.%20Bullying%20is%20a%20particular%20problem%20over%20IM.%20Sexual%20harrassment%20can%20also%20be%20an%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20file%20sharing%20enabled%2C%20SfB%20is%20also%20another%20path%20for%20data%20exfiltration%2C%20another%20reason%20for%20DLP%20to%20cover%20it.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-13022%22%20slang%3D%22en-US%22%3ERe%3A%20Records%20retention%20on%20Skype%20for%20Business%20conversations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-13022%22%20slang%3D%22en-US%22%3E%3CP%3ESaving%20of%20conversations%20in%20Outlook%20is%20optional%2C%20users%20can%20turn%20it%20off%20and%20I'm%20not%20sure%20whether%20you%20can%20enforce%20it%20on.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-11100%22%20slang%3D%22en-US%22%3ERe%3A%20Records%20retention%20on%20Skype%20for%20Business%20conversations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-11100%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20were%20thinking%20of%20steering%20people%20away%20from%20SMS%2Ftexting%20for%20that%20very%20reason%20and%20trying%20to%20get%20them%20to%20use%20the%20IM%20feature%20in%20Skype%20for%20Business%2C%20but%20if%20those%20aren't%20archived%20anywhere%20but%20their%20personal%20phone%2C%20we%20aren't%20gaining%20anything.%26nbsp%3B%20I%20took%20a%20look%20at%20the%20privacy%20agreement%20here%26nbsp%3B%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-US%2Farticle%2FPrivacy-supplement-for-Microsoft-Skype-for-Business-f2100fe5-20f2-4f87-a986-2a823b013b41%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-US%2Farticle%2FPrivacy-supplement-for-Microsoft-Skype-for-Business-f2100fe5-20f2-4f87-a986-2a823b013b41%3C%2FA%3E%20There%20are%20documents%20specifically%20for%20phones%20and%20it%20seems%20like%20the%20conversations%20are%20stored%20on%20the%20phone%20and%20not%20in%20Outlook%20archives.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-11081%22%20slang%3D%22en-US%22%3ERe%3A%20Records%20retention%20on%20Skype%20for%20Business%20conversations%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-11081%22%20slang%3D%22en-US%22%3E%3CP%3EI%20too%20am%20interested.%20We%20don't%20have%20any%20%22work%22%20phones%2C%20they%20are%20all%20personal%20phones%20used%20for%20work%20purposes.%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20under%20the%20impression%20that%20all%20conversations%20conducted%20within%20Skype%20were%20stored%20in%20Outlook's%20Conversation%20History.%3C%2FP%3E%3CP%3EI%20do%20know%20that%20if%20you%20are%20refering%20to%20normal%20SMS%2Ftexting%20then%20no%2C%20MDM%20doesn't%20get%20them.%20For%20us%20we'd%20have%20to%20take%20someone's%20phone%20and%20send%20it%20to%20a%20phone%20%22forensics%22%20company%20that%20would%20then%20retrieve%20all%20the%20messages%20for%20us%20(that%20would%20include%20non-work%20messages).%20Not%20a%20cheap%20proposition.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

I have been tasked with discovering more information on retention policies for IMs sent through Skype for Business.  We are thinking about adding it as an alternative to texting for information that is subject to public records requests. 

Based on what I think I found - the conversations for desktop clients are stored in Exchange - so we can set retention and archiving policies on those.

However the big argument is personal phone vs. work issued cell phone.  It appears that conversations are stored on the personal device - so we would have to use MDM to have access to the data to archive it?

I also am looking at the eDiscovery center and see I can do eDiscovery on Skype for Business, but is that just on the client installs where the conversations are stored in Outlook, or does it cover mobile devices?

 

Can someone verify if I'm on the right track?

4 Replies
Best Response confirmed by Deleted
Solution

I too am interested. We don't have any "work" phones, they are all personal phones used for work purposes. 

I was under the impression that all conversations conducted within Skype were stored in Outlook's Conversation History.

I do know that if you are refering to normal SMS/texting then no, MDM doesn't get them. For us we'd have to take someone's phone and send it to a phone "forensics" company that would then retrieve all the messages for us (that would include non-work messages). Not a cheap proposition.

 

We were thinking of steering people away from SMS/texting for that very reason and trying to get them to use the IM feature in Skype for Business, but if those aren't archived anywhere but their personal phone, we aren't gaining anything.  I took a look at the privacy agreement here  https://support.office.com/en-US/article/Privacy-supplement-for-Microsoft-Skype-for-Business-f2100fe... There are documents specifically for phones and it seems like the conversations are stored on the phone and not in Outlook archives.

Saving of conversations in Outlook is optional, users can turn it off and I'm not sure whether you can enforce it on.

This is an area that is still weak with SfB. We need proper audit capability for it, we also need enforced conversation save.

 

Another weak area is that of DLP. We should be able to monitor conversations for inapppropriate information being shared and for inappropriate conversations. Bullying is a particular problem over IM. Sexual harrassment can also be an issue.

 

With file sharing enabled, SfB is also another path for data exfiltration, another reason for DLP to cover it.