SOLVED

Trying to recover lost emails for one user.

%3CLINGO-SUB%20id%3D%22lingo-sub-645349%22%20slang%3D%22en-US%22%3ETrying%20to%20recover%20lost%20emails%20for%20one%20user.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-645349%22%20slang%3D%22en-US%22%3E%3CP%3EEssentials.%26nbsp%3B%20I%20have%20a%20user%20that%20somehow%20has%20lost%20exactly%2C%20to%20the%20day%2C%201%20year%20of%20emails%20from%20his%20inbox%2C%20just%20his%20inbox.%26nbsp%3B%20I%20have%20looked%20at%20the%20deepcache%20settings%20and%20OWA.%26nbsp%3B%20Same%20thing.%26nbsp%3B%20I%20looked%20through%20other%20folders%2C%20they%20are%20not%20to%20be%20found.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%2C%20via%20the%20Security%20and%20Compliance%20center%20I%20have%20done%20a%20recover%20of%20that%20year.%20It%20seemed%20to%20work%20well%20and%20in%20fact%20generated%20a%205Gb%20.pst%20file.%26nbsp%3B%20I%20have%20tried%20both%20opening%20that%20.pst%20file%20in%20Outlook%20and%20doing%20an%20import%20into%20a%20folder%20in%20his%20mailbox.%26nbsp%3B%20The%20recover%20will%20run%20for%20over%20an%20hour%2C%20with%20it%20going%20through%20folder%20after%20folder%20and%20then%20finish.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20go%20into%20the%20folder%20that%20I%20imported%20them%2C%20or%20go%20into%20the%20mailbox%20itself%20that%20I%20opened%20and%20all%20I%20have%20is%20a%20huge%20amount%20of%20nested%20folders%20and%20very%20few%20messages.%26nbsp%3B%20I%20cannot%20figure%20out%20what%20is%20taking%20up%205Gb%20and%20what%20takes%20so%20long%20to%20do%20the%20import.%26nbsp%3B%20The%20import%20is%20the%20same%20as%20the%20folder%20structure%20in%20the%20open%20mailbox.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20anybody%20done%20a%20recovery%20like%20this%20with%20success%3F%20Or%2C%20has%20anybody%20seen%20email%20just%20disappear%20this%20way%3F%26nbsp%3B%20Yes%2C%20as%20soon%20as%20I%20saw%20it%20missing%20I%20went%20to%20the%20OWA%20interface%20and%20it%20was%20missing%20there%20as%20well.%26nbsp%3B%20So%20deleting%20the%20.OST%20file%20and%20letting%20it%20rebuild%20just%20ended%20up%20with%20it%20being%20the%20same.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20advice%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-645349%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-645981%22%20slang%3D%22en-US%22%3ERe%3A%20Trying%20to%20recover%20lost%20emails%20for%20one%20user.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-645981%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F86729%22%20target%3D%22_blank%22%3E%40Jim%20Ryan%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20the%20list%20of%20folders%20I%20end%20up%20with%20after%20the%20import.%26nbsp%3B%20I%20can%20locate%20a%20couple%20of%20inbox%20folders%20within%20them%2C%20but%20there%20might%20be%202-3%20messages%20in%20each.%26nbsp%3B%20Keep%20in%20mind%20this%20is%20a%20years%20worth%20of%20recovery%20and%20a%205Gb%20file.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20220px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F116024iBFD8683BA89F5D38%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22List%20of%20folders.jpg%22%20title%3D%22List%20of%20folders.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-646110%22%20slang%3D%22en-US%22%3ERe%3A%20Trying%20to%20recover%20lost%20emails%20for%20one%20user.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-646110%22%20slang%3D%22en-US%22%3E%3CP%3EHow%20exactly%20did%20he%20%22lose%22%20the%20items%3F%20If%20it's%20exactly%201year%2C%20perhaps%20he%20applied%20a%20retention%20tag%20to%20the%20Inbox%20folder%3F%20If%20so%2C%20check%20what%20the%20retention%20action%20was%2C%20as%20items%20might%20either%20be%20deleted%20or%20moved%20to%20the%20archive%20mailbox.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20recovery%20steps%20will%20depend%20on%20the%20action%20above%20-%20if%20the%20messages%20were%20deleted%2C%20you%20should%20be%20able%20to%20simply%20go%20to%20the%20dumpster%20and%20mass%20recover%20them%2C%20or%20use%20PowerShell%3A%26nbsp%3B%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Frecoverableitemscmdlet%2F2018%2F01%2F08%2F45%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Frecoverableitemscmdlet%2F2018%2F01%2F08%2F45%2F%3C%2FA%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20they%20were%20archived%2C%20moving%20them%20back%20is%20a%20bit%20more%20complicated%20as%20we%20dont%20have%20built-in%20tools.%20In%20general%20an%20EWS-based%20script%20could%20do%20it%2C%20or%20you%20can%20just%20use%20the%20eDiscovery%20process.%20I%20strongly%20advise%20you%20limit%20the%20search%20to%20just%20the%20Inbox%20folder%2C%20but%20if%20that's%20not%20possible%20you%20can%20just%20ignore%20the%20ApplicationDataRoot%2C%20CalendarSharingCacheCollection%20and%20SubstrateFiles%20containers%20-%20those%20do%20not%20contain%20any%20user-accessible%20items%20(although%20they%20are%20the%20ones%20contributing%20most%20to%20the%20size%20of%20the%20PST).%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-648643%22%20slang%3D%22en-US%22%3ERe%3A%20Trying%20to%20recover%20lost%20emails%20for%20one%20user.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-648643%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThank%20you.%26nbsp%3B%20Well%2C%20I%20think%20I%20was%20looking%20at%20this%20the%20wrong%20way%20and%20trying%20to%20recover%20things%20to%20the%20Inbox.%26nbsp%3B%20When%20I%20went%20to%20the%20Recover%20Deleted%20Items%20(Dumpster%20in%20your%20words%2C%20they%20should%20have%20named%20it%20that)%26nbsp%3B%20I%20found%20what%20I%20think%20the%20user%20wants%20but%20can't%20confirm%20until%20he%20is%20back%20after%20the%20weekend.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20other%20words%20I%20think%2C%20and%20hope%2C%20the%20email%20was%20deleted%20by%20him%2C%20and%20then%20the%20deleted%20folder%20emptied.%26nbsp%3B%20However%20I%20don't%20know%20why%20it%20was%20emptied%2C%20this%20user%20would%20not%20even%20be%20aware%20you%20can%20do%20that.%26nbsp%3B%20Anyway%2C%20I%20am%20currently%20recovering%20everything%20in%20the%20dumpster%20to%20the%20deleted%20folder%20and%20will%20then%20just%20move%20the%20lot%20into%20the%20Inbox%20and%20have%20him%20sort%20out%20what%20he%20needs%2Fwants.%26nbsp%3B%20I%20suspect%20he%20is%20somebody%20using%20the%20Deleted%20folder%20as%20a%20place%20to%20store%20stuff%20against%20everything%20I%20advise%20them%20to%20do.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThere%20seems%20to%20be%20no%20retention%20policies%20set%20on%20his%20folders.%26nbsp%3B%20I%20have%20not%20set%20up%20any%20global%20ones%20and%20don't%20know%20what%20the%20default%2C%20if%20any%2C%20is%20in%20365.%26nbsp%3B%20Interestingly%20the%20only%20option%20regarding%20this%20on%20all%20the%20top%20level%20folders%20(inbox%2C%20sent%2C%20deleted%2C%20etc.)%20are%20all%20%22from%20parent%20file%22%20.%26nbsp%3B%20Any%20folders%20below%20those%20have%20the%20usual%20options.%26nbsp%3B%20I%20assume%20the%20parent%20of%20those%20would%20be%20the%20mailbox%2C%20but%20I%20see%20nothing%20there.%26nbsp%3B%20He%20does%20not%20have%20the%20%22empty%20deleted%20folder%20upon%20exit%22%20checked%20off.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBottom%20line%20I'm%20sure%20this%20is%20some%20kind%20of%20user%20error%20that%20caused%20it%20but%20I'm%20not%20sure%20what%20he%20did.%26nbsp%3B%20I%20would%20like%20to%20point%20is%20out%20so%20it%20doesn't%20happen%20again.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-797477%22%20slang%3D%22en-US%22%3ERe%3A%20Trying%20to%20recover%20lost%20emails%20for%20one%20user.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-797477%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F86729%22%20target%3D%22_blank%22%3E%40Jim%20Ryan%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMay%20be%20possible%20that%20issue%20can%20be%20fixed%20with%20an%20utility%20a%20third%20party%20program%20that%20can%20recover%20.ost%20files%20even%20deleted%20emails%20too%2C%20you%20can%20give%20it%20a%20try%20by%20installing%20this%20program%20on%20your%20machine%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fgallery.technet.microsoft.com%2FOST-Recovery-Software-to-ba51ac50%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgallery.technet.microsoft.com%2FOST-Recovery-Software-to-ba51ac50%3C%2FA%3E%3C%2FP%3E%3CP%3Eor%20systools%20is%20of%20the%20name%20i%20searched%20and%20gone%20through%20they%20provide%20forensic%20digital%20solutions%20and%20a%20leading%20company.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Essentials.  I have a user that somehow has lost exactly, to the day, 1 year of emails from his inbox, just his inbox.  I have looked at the deepcache settings and OWA.  Same thing.  I looked through other folders, they are not to be found.

 

So, via the Security and Compliance center I have done a recover of that year. It seemed to work well and in fact generated a 5Gb .pst file.  I have tried both opening that .pst file in Outlook and doing an import into a folder in his mailbox.  The recover will run for over an hour, with it going through folder after folder and then finish.

 

I go into the folder that I imported them, or go into the mailbox itself that I opened and all I have is a huge amount of nested folders and very few messages.  I cannot figure out what is taking up 5Gb and what takes so long to do the import.  The import is the same as the folder structure in the open mailbox.

 

Has anybody done a recovery like this with success? Or, has anybody seen email just disappear this way?  Yes, as soon as I saw it missing I went to the OWA interface and it was missing there as well.  So deleting the .OST file and letting it rebuild just ended up with it being the same.

 

Any advice appreciated

4 Replies
Highlighted

@Jim Ryan 

 

This is the list of folders I end up with after the import.  I can locate a couple of inbox folders within them, but there might be 2-3 messages in each.  Keep in mind this is a years worth of recovery and a 5Gb file.

 

List of folders.jpg

Highlighted
Solution

How exactly did he "lose" the items? If it's exactly 1year, perhaps he applied a retention tag to the Inbox folder? If so, check what the retention action was, as items might either be deleted or moved to the archive mailbox.

 

The recovery steps will depend on the action above - if the messages were deleted, you should be able to simply go to the dumpster and mass recover them, or use PowerShell: https://blogs.technet.microsoft.com/recoverableitemscmdlet/2018/01/08/45/

 

If they were archived, moving them back is a bit more complicated as we dont have built-in tools. In general an EWS-based script could do it, or you can just use the eDiscovery process. I strongly advise you limit the search to just the Inbox folder, but if that's not possible you can just ignore the ApplicationDataRoot, CalendarSharingCacheCollection and SubstrateFiles containers - those do not contain any user-accessible items (although they are the ones contributing most to the size of the PST).

 

 

Highlighted

@Vasil Michev Thank you.  Well, I think I was looking at this the wrong way and trying to recover things to the Inbox.  When I went to the Recover Deleted Items (Dumpster in your words, they should have named it that)  I found what I think the user wants but can't confirm until he is back after the weekend.  

 

In other words I think, and hope, the email was deleted by him, and then the deleted folder emptied.  However I don't know why it was emptied, this user would not even be aware you can do that.  Anyway, I am currently recovering everything in the dumpster to the deleted folder and will then just move the lot into the Inbox and have him sort out what he needs/wants.  I suspect he is somebody using the Deleted folder as a place to store stuff against everything I advise them to do.

 

There seems to be no retention policies set on his folders.  I have not set up any global ones and don't know what the default, if any, is in 365.  Interestingly the only option regarding this on all the top level folders (inbox, sent, deleted, etc.) are all "from parent file" .  Any folders below those have the usual options.  I assume the parent of those would be the mailbox, but I see nothing there.  He does not have the "empty deleted folder upon exit" checked off.

 

Bottom line I'm sure this is some kind of user error that caused it but I'm not sure what he did.  I would like to point is out so it doesn't happen again.

 

 

 

 

Highlighted

@Jim Ryan 

May be possible that issue can be fixed with an utility a third party program that can recover .ost files even deleted emails too, you can give it a try by installing this program on your machine

https://gallery.technet.microsoft.com/OST-Recovery-Software-to-ba51ac50

or systools is of the name i searched and gone through they provide forensic digital solutions and a leading company.