Estimate search results - This option returns an estimate of the total size and number of items that will be returned by the search based on the criteria you specified. Preview search results - This option provides a preview of the results.
Messages returned from each mailbox searched are displayed. Copy search results - This option lets you copy messages to a discovery mailbox. Export search results - After search results are copied to a discovery mailbox, you can export them to a PST file. Users familiar with KQL can construct powerful search queries to search content indexes. For authorized users to perform In-Place eDiscovery searches, you need to add them to the Discovery Management role group.
By default, permissions to perform In-Place eDiscovery-related tasks aren't assigned to any user or Exchange administrators. Exchange administrators who are members of the Organization Management role group can add users to the Discovery Management role group and create custom role groups to narrow the scope of a discovery manager to a subset of users.
To learn more about adding users to the Discovery Management role group, see Assign eDiscovery permissions in Exchange Server. Auditing of RBAC role changes, which is enabled by default, makes sure that adequate records are kept to track assignment of the Discovery Management role group.
You can use the administrator role group report to search for changes made to administrator role groups. For more information, see Search the role group changes or administrator audit logs.
Users who have been added to the Discovery Management role group can perform In-Place eDiscovery searches. You can perform a search using the web-based interface in the EAC. This makes it easier for non-technical users such as records managers, compliance officers, or legal and HR professionals to use In-Place eDiscovery. You can also use the Exchange Management Shell to perform a search. This object can be manipulated to start, stop, modify, and remove the search.
After you create the search, you can choose to get an estimate of search results, which includes keyword statistics that help you determine query effectiveness. You can also do a live preview of items returned in the search, allowing you to view message content, the number of messages returned from each source mailbox and the total number of messages.
You can use this information to further fine-tune your query if required. When satisfied with the search results, you can copy them to a discovery mailbox. Name - The search name is used to identify the search. When you copy search results to a discovery mailbox, a folder is created in the discovery mailbox using the search name and the timestamp to uniquely identify search results in a discovery mailbox.
Sources - You can choose to search all mailboxes in your Exchange Server organization or specify the mailboxes to search. You can also choose to search all public folders. If you also want to use the same search to place items on hold, you must specify the mailboxes. You can also place all public folders on In-Place Hold.
You can specify a distribution group to include mailbox users who are members of that group. Membership of the group is calculated once when creating the search and subsequent changes to group membership aren't automatically reflected in the search.
A user's primary and archive mailboxes are included in the search. Search query - You can either include all mailbox content from the specified mailboxes or use a search query to return items that are more relevant to the case or investigation. You can specify the following parameters in a search query:. Keywords - You can specify keywords and phrases to search message content. Additionally, Exchange Server also supports the NEAR operator, allowing you to search for a word or phrase that's in proximity to another word or phrase.
To search for an exact match of a multiple word phrase, you must enclose the phrase in quotation marks. For example, searching for the phrase "plan and competition" returns messages that contain an exact match of the phrase, whereas specifying plan AND competition returns messages that contain the words plan and competition anywhere in the message. You must capitalize logical operators such as AND and OR for them to be treated as operators instead of keywords.
We recommend that you use explicit parenthesis for any query that mixes multiple logical operators to avoid mistakes or misinterpretations. To search messages sent during a specific date range, you can narrow the search by specifying the start and end dates. If you don't specify an end date, the search will return the latest results every time you restart it. Senders and recipients - To narrow down the search, you can specify the senders or recipients of messages.
You can use email addresses, display names, or the name of a domain to search for items sent to or from everyone in the domain. For example, to find email sent by or sent to anyone at Contoso, Ltd, specify contoso. You can also specify contoso. Message types - By default, all message types are searched. You can restrict the search by selecting specific message types such as email, contacts, documents, journal, meetings, notes and Lync content.
For details, see Default Filters for Exchange Search. In on-premises deployments, you can add support for additional file types by installing search filters also known as an iFilter for the file type on Mailbox servers. Unsearchable items - Unsearchable items are mailbox items that can't be indexed by Exchange Search. Reasons they can't be indexed include the lack of an installed search filter for an attached file, a filter error, and encrypted messages. For a successful eDiscovery search, your organization may be required to include such items for review.
When copying search results to a discovery mailbox or exporting them to a PST file, you can include unsearchable items. For more information, see Unsearchable Items in Exchange eDiscovery.
De-duplication - When copying search results to a discovery mailbox or exporting search results to a PST file, you can enable de-duplication of search results to copy only one instance of a unique message to the discovery mailbox. De-duplication has the following benefits:. Lower storage requirement and smaller discovery mailbox size due to reduced number of messages copied.
Reduced workload for discovery managers, legal counsel, or others involved in reviewing search results. This includes searching permanently deleted items and original versions of modified items in the Recoverable Items folder for users placed on Litigation Hold or In-Place Hold. You need to be assigned permissions before you can perform this procedure or procedures. To see what permissions you need, see the "In-Place eDiscovery" entry in the Messaging policy and compliance permissions in Exchange Server topic.
To create eDiscovery searches, you have to have an SMTP address in the organization that you're creating the searches in. In an Exchange hybrid organization, your on-premises Exchange mailbox must have a corresponding mail user account in your Microsoft or Office organization, such as the tenant administrator account, that account must be assigned an Exchange Online license.
For more information about the Microsoft or Office licensing requirements for in-place eDiscovery searches, see Exchange Online Service Description. You can create additional Discovery mailboxes. For details, see Create a discovery mailbox. When you create a search, messages returned in search results aren't copied automatically to a discovery mailbox. After you create the search, you can use the Exchange admin center EAC to estimate and preview search results or copy them to a discovery mailbox.
You can also export the search results to a. For details, see:. Use the EAC to estimate or preview search results later in this topic. Copy eDiscovery search results to a discovery mailbox. Export eDiscovery search results to a PST file.
As previously explained, to create eDiscovery searches, you have to sign in to a user account that has an SMTP address in your organization. To include all mailboxes in the search, click Search all mailboxes. If you select this option, you won't be able to enable an In-Place Hold for the search. To exclude mailboxes from the search and search only public folders , click Don't search any mailboxes.
To include specific mailboxes in the search, click Specify mailboxes to search , and then add that mailboxes that you want to search. To include public folders in the search or to place public folders on hold , click Search all public folders.
For more information about searching public folders, see Search and place a hold on public folders using In-Place eDiscovery. Include all content : Select this option to include all content in the search results. Syed Muhammad Faisal. For more details about hybrid deployments " Thanks. This thread is locked. You can follow the question or vote as helpful, but you cannot reply to this thread. I have the same question 0. Report abuse. In Exchange , we have to use the Export-Mailbox cmdlet or 3rd party tools to search and export content from multiple mailboxes.
It scans mailboxes using the MAPI library, something that takes an extensive amount of time. This is even less effective when we working against thousands of mailboxes. Exchange provides a simpler, user friendly web-based interface to perform Multi-Mailbox search. You may now delegate the Multi-Mailbox search task to end-users without providing them with elevated rights. This gives you peace of mind that users won't be able to make any configuration changes on the Exchange Server.
Multi-Mailbox Search uses the same index catalog created by the Exchange Search engine. Thus it is faster and at the same time less demanding on resources. All you have to do is to assign the RBAC permission to the user who needs to carry out the Multi-Mailbox search operation.
The Discovery Management role group has no members by default on installing Exchange , not even Exchange Administrators. So initially no one has permission to use this functionality. It requires giving permission explicitly to the authorized person by adding the user id to this group using the cmdlet: Add-RoleGroupMember -Identity "Discovery Management" -Member User.
The Discovery Mailbox is a special type of mailbox in Exchange The results of a multi-mailbox search may contain sensitive information, thus we need to store it at a safe and secure location. The discovery mailbox is the repository for search results and the related content. By default, the Exchange server installation creates a discovery mailbox with display name "Discovery Search Mailbox".
Members of the Discovery Management group have full mailbox access to this. Nobody has mailbox access permission on a newly created Discovery Mailbox. The Administrator has to give Full Mailbox permission explicitly to authorized users.
To store large amounts of search results, 50GB of mailbox storage quota is assigned to Discovery Mailboxes on creation.
0コメント