Understand data protection and governance tasks for Microsoft 365 and Copilot
Retention and Data Lifecycle Management
Treat retention as its own competency: choose policies or labels, reason about retain/delete outcomes, and distinguish lifecycle from sensitivity and DLP.
What you need to know
- Retention exists to meet legal, regulatory, records, and business lifecycle requirements while reducing obsolete data. The core outcomes are retain-only, delete-only, and retain then delete after a defined period.
- A retention policy efficiently assigns the same settings to supported locations such as mailboxes, SharePoint sites, OneDrive accounts, Microsoft 365 groups, Teams messages, and Copilot experiences. Items inherit the container/location settings.
- A retention label assigns lifecycle settings to an individual email, document, or supported item. Labels can use different event/start conditions, be applied manually or automatically, mark items as records, and offer supported end-of-period actions such as disposition review.
- Retention duration includes both length and when the clock starts, such as creation, modification for supported locations, labeling, or a defined event. The correct choice depends on the requirement, not merely the number of years.
- When retention requires preserving content, Microsoft 365 keeps a compliance copy in a protected workload location if a user edits or deletes it. Users can often continue normal work while the retained copy remains discoverable for compliance.
- Disposition review is a human review at the end of a supported retention-label period before final deletion. It is useful for selected records that require a decision; it is not required for every retention policy.
- Records Management builds on retention labels when content needs record restrictions, file plans, proof of disposition, and stricter governance. AB-900 requires recognizing this relationship, not designing an expert records program.
How it works
- The administrator defines scope, retention action, duration, and start condition. A policy applies to locations; a label applies lifecycle behavior to selected items and can travel within Microsoft 365 as documented.
- If retained content is edited or deleted, a protected copy remains in a workload preservation location. When the retention period ends, the configured action can leave, delete, relabel, or send supported labeled content for disposition review.
- Multiple retention settings can overlap. Preservation generally wins over deletion during the required period, and the longest retention period can control when settings conflict; administrators should use Microsoft’s retention principles rather than assuming the newest policy overrides all others.
Compare and distinguish
- Retention policy vs retention label: broad location/container coverage vs item-specific lifecycle and richer end-of-period/record options.
- Retain vs delete vs retain then delete: preserve indefinitely/for a period vs remove when eligible vs preserve first and remove afterward.
- Sensitivity vs retention: classification/protection and access controls vs lifecycle keep/delete behavior.
- DLP vs retention: control risky use or movement vs preserve/delete content according to schedule.
- Retention vs eDiscovery hold: ongoing information-governance policy vs case/investigation preservation need.
Objects and administrative surfaces
- Retention policies, retention labels, label policies, events, disposition, and Data Lifecycle Management settings — Microsoft Purview portal.
- Records Management — Microsoft Purview for record declaration, disposition, file plans, and advanced record controls.
- Users may apply published labels in supported Exchange, SharePoint, OneDrive, and Microsoft 365 experiences.
Scenario examples
- Scenario: All mailboxes and SharePoint sites must keep ordinary business content for seven years — reasoning: begin with a broad retention policy.
- Scenario: Final audit reports need ten years and human disposition review, while other finance content needs seven — reasoning: combine broad policy coverage with a retention label for the special records.
- Scenario: A confidential file must be encrypted and deleted after five years — reasoning: sensitivity handles encryption; retention handles the five-year lifecycle.
- Scenario: A user deletes a retained email before its period ends — reasoning: the user-facing item may disappear, but a protected compliance copy remains according to the retention configuration.
When to use it
- Use a retention policy when a broad population or location needs one common rule.
- Use a retention label when item types need different schedules, event-based starts, record declaration, or disposition review.
- Use sensitivity and DLP alongside retention when the requirement also includes protection or control of risky movement; one control does not replace the others.
Security and governance implications
- Map retention settings to approved schedules and legal requirements, identify policy owners, and test before broad deployment.
- Restrict disposition and records roles because reviewers can make consequential deletion decisions and view sensitive metadata/content.
- Do not retain everything forever by default; unnecessary retention increases storage, privacy, and discovery risk.
Troubleshooting signals
- Confirm whether the item is governed by a policy, label, record setting, eDiscovery hold, or another overlapping retention rule.
- Check scope/location, publication/application, start date, duration, preservation location, and processing/propagation before expecting final deletion.
- If deletion is blocked, identify the controlling retention or hold before attempting removal; if content disappeared too early, verify that the intended policy actually applied.
Exam traps
- A retention policy and a retention label are not interchangeable merely because both contain a duration.
- Retention does not encrypt content, remove oversharing, or block risky sharing unless another control performs that job.
- Disposition review is an end-of-period decision for supported labels, not a universal step for every retained item.
- A user deleting a retained item does not necessarily delete the protected compliance copy.
Key takeaways
- Broad location rule → policy; item-specific schedule/record/disposition → label.
- Define action, duration, start, scope, and end-of-period outcome.
- Sensitivity protects; classification detects; DLP controls risky use; retention keeps/deletes.
Related objectives
- D2.1.a
- D2.1.d