Exchange Online, Retention Policies. For Mailboxes.

%3CLINGO-SUB%20id%3D%22lingo-sub-214109%22%20slang%3D%22en-US%22%3EExchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214109%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Guys%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EQuick%20question%20here%2C%20i%20am%20trying%20to%20understand%20if%20you%20can%20create%20a%20new%20retention%20policy%20in%20exchange%20online%20and%20have%20it%20set%20as%20default%2C%20so%20that%20all%20new%20mailboxes%20will%20be%20assigned%20that%20newly%20created%20retention%20policy.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20documentation%20says%20no%3A%20(for%20both%20on%20prem%20and%20online).%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fsecurity-and-compliance%2Fmessaging-records-management%2Fdefault-retention-policy%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fsecurity-and-compliance%2Fmessaging-records-management%2Fdefault-retention-policy%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERight%20under%20%22%3CSTRONG%3Ewhat%20can%20you%20do%20with%3C%2FSTRONG%3E%22....%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECan%20you%20guys%20shed%20some%20light%20on%20this%20for%20me%3F%20I%20am%20sure%20that%20you%20can%20set%20a%20different%20retention%20policy%20to%20default%2C%20and%20have%20it%20be%20applied%20to%20all%20new%20mailboxes.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAm%20i%20just%20not%20understanding%20the%20documentation%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-214109%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EHybrid%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOn-Premises%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-214596%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214596%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20Vasil%2C%20you%20are%20always%20very%20helpful.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-214336%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214336%22%20slang%3D%22en-US%22%3E%3CP%3Eactually%20it%20looks%20like%20i%20may%20have%20found%20my%20answer.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fpractical365.com%2Fexchange-online%2Fcontrolling-exchange-online-mailbox-features-mailbox-plans%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fpractical365.com%2Fexchange-online%2Fcontrolling-exchange-online-mailbox-features-mailbox-plans%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethere%20is%20also%20a%20get%2Fset%20cas-mailboxplan%20as%20well.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-214334%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214334%22%20slang%3D%22en-US%22%3E%3CP%3EThanks.%20I%20was%20not%20familiar%20with%20that%20command.%20Is%20the%20Get%2FSet%20mailbox%20plan%20used%20by%20tenant%20admins%20frequently%3F%20I%20thought%20it%20was%20specific%20to%20hosting%20only%20solutions%20(not%20office%20365).%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20through%20the%20Set%20commands%20it%20looks%20like%20basically%20all%20of%20the%20options%20available%20to%20set-mailbox%20are%20also%20available%20to%20set-mailboxplan.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20would%20you%20modify%20a%20mailbox%20plan%20%3F%20vs.%20just%20modifying%20an%20existing%20mailbox%20with%20set-mailbox%3F%20Trying%20to%20understand%20when%20to%20use%20one%20command%20vs%20the%20other.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERobert%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-214199%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214199%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20correct%20way%20to%20change%20the%20default%20retention%20policy%20in%20ExO%20is%20via%20the%20mailbox%20plans.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGet-MailboxPlan%20%7C%20Set-MailboxPlan%20-RetentionPolicy%20%22New%20MRM%20policy%22%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20simple%20example%20will%20set%20it%20on%20all%20plans%2C%20but%20you%20can%20configure%20it%20on%20specific%20ones%20if%20needed.%20Remember%20that%20mailbox%20plans%20apply%20to%20newly%20created%20mailboxes%20only%2C%20so%20for%20any%20already%20existing%20ones%20you%20still%20have%20to%20apply%20the%20retention%20policy%20via%20the%20EAC%20or%20via%20Set-Mailbox.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-214114%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Online%2C%20Retention%20Policies.%20For%20Mailboxes.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-214114%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20working%20on%20exactly%20the%20same%20issue%20and%20in%20particular%20want%20to%20know%20(a)%20if%20a%20replacement%20RPT%20will%20replace%20the%20existing%20MRM%20policy%20automatically%2C%20and%20(b)%20how%20to%20apply%20an%20O365%20Classification%20Label%20Policy%20to%20all%20Exchange%20mailboxes%20and%20confirm%20it.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20is%20a%20summary%20I%20created%20of%20our%20current%20situation%20and%20what%20we%20in%20theory%20should%20be%20able%20to%20do.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EWhat%20is%20in%20place%20now%20in%20Exchange%20Online%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAll%20our%20(currently%20only%2047)%20EXO%20mailboxes%20have%20the%20Default%20MRM%20Policy%20applied.%20In%20mailboxes%2C%20you%20can%20see%20the%20default%20when%20you%20click%20on%20%E2%80%98mailbox%20features%E2%80%99.%26nbsp%3B%3C%2FP%3E%3CP%3E%3CBR%20%2F%3EThe%20default%20MRM%20Policy%20has%20two%20Default%20Policy%20Tags%20(DPT)%2C%20neither%20of%20which%20works%20now%20for%20the%20reasons%20stated%3A%3C%2FP%3E%3CUL%3E%3CLI%3E%E2%80%98Default%202%20years%20move%20to%20archive%E2%80%99%20after%202%20years.%20However%2C%20In-Place%20Archiving%20is%20not%20enabled%20on%20any%20mailbox%2C%20so%20this%20will%20not%20work.%26nbsp%3B%3CBR%20%2F%3E%E2%80%98Recoverable%20items%2014%20days%20move%20to%20archive%E2%80%99%2C%20but%20again%20without%20the%20archiving%20enabled%2C%20this%20will%20not%20work.%3C%2FLI%3E%3C%2FUL%3E%3CP%3ETherefore%2C%20the%20default%20MRM%20Policy%20currently%20will%20not%20do%20anything.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20rest%20of%20the%20tags%20in%20the%20Default%20MRM%20Policy%20are%20all%20personal%20tags%20so%20not%20relevant%20here%20except%20that%20a%20user%20could%20potentially%20apply%20a%20shorter%20retention%20period.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EFrom%20what%20I%20can%20see%2C%20you%20can%20only%20set%20one%20%3CEM%3Edefault%3C%2FEM%3E%20policy%20to%20be%20applied%20to%20new%20users%20via%20the%20default%20MRM%20policy.%20To%20do%20this%2C%20you%20create%20a%20new%20policy%20(that%20incorporates%20the%20policies%20in%20the%20default%20as%20well)%20and%20then%20replace%20the%20default%20MRM%20Policy%20with%20that%20new%20one%2C%26nbsp%3Bbut%20is%20this%20then%26nbsp%3Bapplied%20automatically%20to%20all%20mailboxes%20as%20it%20suggests%20it%20will%3F%3C%2FP%3E%3CP%3E%3CBR%20%2F%3E%3CSTRONG%3ECreating%20a%20new%20Retention%20policy%20using%20Exchange%20Retention%20Policies%20and%20RPTs%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20retention%20policy%20can%20be%20made%20up%20of%20multiple%20retention%20policy%20tags%20(RPT).%3C%2FP%3E%3CUL%3E%3CLI%3EA%20DPT%20to%20move%20items%20to%20the%20archive%20(if%2Fwhen%20enabled)%3C%2FLI%3E%3CLI%3EA%20DPT%20to%20delete%20items%3C%2FLI%3E%3CLI%3EOne%20or%20more%20RPTs%20for%20either%20the%20entire%20mailbox%20or%20for%20specific%20folders%20(multiple%20are%20possible)%20%E2%80%93%20see%20below.%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%3CSTRONG%3ECreating%20an%20RPT%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20you%20create%20a%20new%20RPT%20via%20%E2%80%98retention%20tags%E2%80%99%20you%20have%20three%20options%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CUL%3E%3CLI%3EThe%20first%20option%20(%E2%80%98applied%20automatically%20to%20entire%20mailbox%E2%80%99)%20allows%20us%20to%20create%20a%20single%20policy%20for%20the%20entire%20mailbox.%20This%20keeps%20everything%20for%20a%20period%20of%20time%20after%20the%20email%20date%20which%20may%20not%20suit%26nbsp%3Ball%20requirements%20%E2%80%93%20see%20below.%3C%2FLI%3E%3CLI%3EThe%20second%20option%20(%E2%80%98applied%20automatically%20to%20a%20default%20folder%E2%80%99)%20allows%20you%20to%20create%20multiple%20policies%20for%20different%20default%20folders%2C%20including%20the%20Deleted%20Items%20folder.%20This%20means%20that%20any%20emails%20in%20folders%20created%20by%20a%20user%20would%20not%20be%20covered%20by%20this%20policy.%20If%20the%20user%20doesn%E2%80%99t%20apply%20another%20policy%20to%20the%20folder%2C%20the%20items%20in%20these%20folders%20will%20(presumably)%20remain%20for%20the%20life%20of%20the%20mailbox.%3C%2FLI%3E%3CLI%3EThe%20third%20option%20(%E2%80%98applied%20by%20users%20to%20items%20and%20folders%20(personal)%E2%80%99)%20allows%20a%20retention%20policy%20to%20be%20applied%20by%20a%20user.%3C%2FLI%3E%3C%2FUL%3E%3CP%3EIf%20this%20model%20is%20correct%2C%20we%20should%20(a)%20enable%20archiving%20and%20(b)%20create%20and%20apply%20the%20new%20Retention%20Policy%20with%20the%20following%20tags%3A%3C%2FP%3E%3CUL%3E%3CLI%3EDefault%20(DPT)%2C%20to%20(a)%20move%20to%20archive%20after%202%20years%2C%20(b)%20allow%20delete%20(but%20goes%20to%20Recoverable%20items)%3C%2FLI%3E%3CLI%3EDefault%20folder%20tag%20(second%20option)%20to%20delete%20deleted%20items%20older%20than%205%20years%3C%2FLI%3E%3CLI%3EDefault%20folder%20tag%20(second%20option)%20to%20delete%20items%20from%20the%20primary%20and%20archive%20mailboxes%20after%207%20years%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThese%20tags%20will%20%E2%80%98miss%E2%80%99%20the%20personal%20folders%20but%20we%20think%20that%E2%80%99s%20OK%20as%20the%20emails%20will%20remain%20in%20there%20unless%20they%20are%20deleted%2C%20in%20which%20case%20they%20will%20be%20picked%20up%20by%20the%20second%20tag%20above.%20If%20they%20are%20not%20deleted%2C%20they%20will%20remain.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20we%20don't%20know%20-%20yet%20-%20is%20whether%20this%20replacement%20default%20retention%20policy%20will%20(a)%20automatically%20be%20applied%20and%20(b)%20ensure%20that%20the%20emails%20of%20users%20is%20not%20deleted%2030%20days%20after%20they%20leave.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Frequent Contributor

Hey Guys, 

 

Quick question here, i am trying to understand if you can create a new retention policy in exchange online and have it set as default, so that all new mailboxes will be assigned that newly created retention policy. 

 

This documentation says no: (for both on prem and online). https://docs.microsoft.com/en-us/exchange/security-and-compliance/messaging-records-management/defau...

 

Right under "what can you do with".... 

 

Can you guys shed some light on this for me? I am sure that you can set a different retention policy to default, and have it be applied to all new mailboxes. 

 

Am i just not understanding the documentation?

 

Thanks, 

 

Robert

5 Replies
Highlighted

We are working on exactly the same issue and in particular want to know (a) if a replacement RPT will replace the existing MRM policy automatically, and (b) how to apply an O365 Classification Label Policy to all Exchange mailboxes and confirm it.

 

Here is a summary I created of our current situation and what we in theory should be able to do.

 

What is in place now in Exchange Online

 

All our (currently only 47) EXO mailboxes have the Default MRM Policy applied. In mailboxes, you can see the default when you click on ‘mailbox features’. 


The default MRM Policy has two Default Policy Tags (DPT), neither of which works now for the reasons stated:

  • ‘Default 2 years move to archive’ after 2 years. However, In-Place Archiving is not enabled on any mailbox, so this will not work. 
    ‘Recoverable items 14 days move to archive’, but again without the archiving enabled, this will not work.

Therefore, the default MRM Policy currently will not do anything.

 

The rest of the tags in the Default MRM Policy are all personal tags so not relevant here except that a user could potentially apply a shorter retention period.

 

From what I can see, you can only set one default policy to be applied to new users via the default MRM policy. To do this, you create a new policy (that incorporates the policies in the default as well) and then replace the default MRM Policy with that new one, but is this then applied automatically to all mailboxes as it suggests it will?


Creating a new Retention policy using Exchange Retention Policies and RPTs

 

A retention policy can be made up of multiple retention policy tags (RPT).

  • A DPT to move items to the archive (if/when enabled)
  • A DPT to delete items
  • One or more RPTs for either the entire mailbox or for specific folders (multiple are possible) – see below.

Creating an RPT

 

When you create a new RPT via ‘retention tags’ you have three options:

 

  • The first option (‘applied automatically to entire mailbox’) allows us to create a single policy for the entire mailbox. This keeps everything for a period of time after the email date which may not suit all requirements – see below.
  • The second option (‘applied automatically to a default folder’) allows you to create multiple policies for different default folders, including the Deleted Items folder. This means that any emails in folders created by a user would not be covered by this policy. If the user doesn’t apply another policy to the folder, the items in these folders will (presumably) remain for the life of the mailbox.
  • The third option (‘applied by users to items and folders (personal)’) allows a retention policy to be applied by a user.

If this model is correct, we should (a) enable archiving and (b) create and apply the new Retention Policy with the following tags:

  • Default (DPT), to (a) move to archive after 2 years, (b) allow delete (but goes to Recoverable items)
  • Default folder tag (second option) to delete deleted items older than 5 years
  • Default folder tag (second option) to delete items from the primary and archive mailboxes after 7 years

These tags will ‘miss’ the personal folders but we think that’s OK as the emails will remain in there unless they are deleted, in which case they will be picked up by the second tag above. If they are not deleted, they will remain.

 

What we don't know - yet - is whether this replacement default retention policy will (a) automatically be applied and (b) ensure that the emails of users is not deleted 30 days after they leave.

 

Highlighted

The correct way to change the default retention policy in ExO is via the mailbox plans.

 

Get-MailboxPlan | Set-MailboxPlan -RetentionPolicy "New MRM policy"

 

This simple example will set it on all plans, but you can configure it on specific ones if needed. Remember that mailbox plans apply to newly created mailboxes only, so for any already existing ones you still have to apply the retention policy via the EAC or via Set-Mailbox.

Highlighted

Thanks. I was not familiar with that command. Is the Get/Set mailbox plan used by tenant admins frequently? I thought it was specific to hosting only solutions (not office 365). 

 

Looking through the Set commands it looks like basically all of the options available to set-mailbox are also available to set-mailboxplan. 

 

When would you modify a mailbox plan ? vs. just modifying an existing mailbox with set-mailbox? Trying to understand when to use one command vs the other. 

 

Thanks, 

 

Robert

 

 

Highlighted

actually it looks like i may have found my answer. https://practical365.com/exchange-online/controlling-exchange-online-mailbox-features-mailbox-plans/

 

there is also a get/set cas-mailboxplan as well. 

 

Robert 

Highlighted

Thanks Vasil, you are always very helpful.