exchange online
3 TopicsRetention Compliance Policy exemption group honoring
Hello, My company is starting down a path to enact a Data Lifecycle Management policy, starting with our EOL email. The desired state outcome is a policy that deletes all email older than 7 years, applied to all mailboxes, with certain exemptions to named users/individuals (execs, etc.). I created a mail-enabled security group for the named exempt individuals, sync'ed into EntraID. I was able to use powershell to create a retention compliance policy (in a disabled state for now) + corresponding retention compliance rule that is targeted to EOL, but I can't see to get the configuration to honor the exemption group I've specified. I'm typically PIM'ed up to Compliance Administrator to do these manipulations, though I've also tried with Global Admin to no avail. Whether via the powershell based attempts or via the Purview GUI, the exempt group listing just doesn't seem to take/appear after I've submitted the change to enact on it. Is there anything special needed to get the Purview system to honor a group specified for named users/mailboxes for exemption? I understand that it can take up to 7 days for a change to take hold, but I was under the impression that changes that are submitted should at least be visible via the admin interface of choice (powershell, Purview web GUI) once submitted. Thanks114Views0likes3CommentsInbound Sensitive Information
Hello All, We currently have some DLP policies to restrict Financial Data, HIPPA, and PII data from leaving our org. However, is there a way to restrict this type of sensitive data from being sent into the org? For example, an external address sends some sensitive data to a specific mailbox. Can a DLP policy be created to block that data from reaching a specific mailbox and reply back the email was blocked due to the content? Thanks for any info!Solved561Views0likes5CommentsAny advice on a self service way of having managers access mailbox from terminated employees?
Greetings, I'm looking for some advice on a challenge we are facing with accessing mailboxes from terminated users. Currently, we have some managers who need access to terminated employees' emails for valid business reasons, and our current process involves exporting PSTs from eDiscovery, which can be time-consuming and cumbersome. Moreover, once we pass the PST to the requestor, we lose control of it, which is not ideal because it's not subject to retention policies. We've considered creating a shared mailbox, importing the PST there, and giving access to the requestor, but that takes too long and involves too many parties in the process (exporting the PST, legal team, creating the shared folder, X team, giving access to said shared mailbox, eventually removing it, Y team, etc.). I would like to know if there is a self-service way for approved employees to access mailboxes from terminated users (users that no longer exist in Active Directory and are only available in eDiscovery). Any insights or advice you can provide would be greatly appreciated. Thank you in advance for your help.1.3KViews1like2Comments