Home > Glossary > Microsoft 365 Administrator > Retention Policies

📖 What is Retention Policies?

Retention policies are settings in Microsoft Purview that determine how long data is kept and when it is permanently deleted. They help organizations meet legal requirements and business needs by automating the preservation or disposal of content across Exchange, SharePoint, and OneDrive.

🥋 Sensei Says:

"Student, a retention policy is a 'blanket' setting for an entire location, whereas a retention label is applied to a specific item or folder."

📚 Certification: Microsoft 365 Administrator (MS-102)

🔑 What are the Key Concepts of Retention Policies?

  • Scope of Application: Policies apply to entire locations like all Exchange mailboxes or specific SharePoint sites, ensuring consistent data governance across a broad user base.
  • Retention Actions: You can configure policies to retain content for a specific duration, retain it indefinitely, or trigger automatic deletion after a set period.
  • Preservation Hold Library: For SharePoint and OneDrive, policies move deleted items to a hidden Preservation Hold library to prevent permanent data loss during retention.
  • Conflict Resolution Logic: When multiple policies apply, Microsoft 365 follows a hierarchy: retention wins over deletion, and the longest retention period always takes precedence.
  • Policy Deployment: Policies are managed via the Microsoft Purview compliance portal and can be targeted to specific users, groups, or all organization-wide locations.

🎯 How does Retention Policies appear on the MS-102 Exam?

You may be asked to determine the outcome when a user deletes an email that is subject to both a 3-year retention policy and a 5-year retention label.

A scenario might describe a legal requirement to keep all company emails for seven years regardless of user action; you must identify the correct Purview tool to implement this.

Expect questions where you must choose between a retention policy and a retention label based on whether the requirement applies to an entire site or specific files.

❓ Frequently Asked Questions

What happens if a retention policy and a deletion policy overlap on the same document?

In the Microsoft 365 retention hierarchy, retention always wins over deletion. If one policy says 'keep for 5 years' and another says 'delete after 3,' the document is kept for 5.


Can a user bypass a retention policy by emptying their Deleted Items folder?

No. For Exchange, items are moved to the Recoverable Items folder. For SharePoint and OneDrive, items are moved to the Preservation Hold library, keeping them invisible to users but accessible to admins.


How long does it take for a new retention policy to be applied to all users?

While configuration is immediate, it can take up to 24 hours for the policy to be fully propagated across all targeted mailboxes and sites in a large tenant.

Related Terms from Microsoft 365 Administrator

📝 Related Study Guides

Comparison 8 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

Choose CISSP if you want broad technical security expertise across eight domains, including cryptography, network security, and software development. Choose CISM if you're focused on information security management, governance, and risk management from a leadership perspective. CISSP is ideal for hands-on security architects, while CISM is designed for security managers and directors.

Career Guide 9 min read

The IT Certification Roadmap: Where to Start in 2026

Start your IT certification journey in 2026 with CompTIA A+ for general IT foundations, then branch into networking (Network+), cybersecurity (Security+), or cloud computing (AWS Cloud Practitioner or Azure Fundamentals) based on your career goals. Each path leads to advanced certifications like CISSP, AWS Solutions Architect, or CISM within 2-3 years of focused progression.

Comparison 10 min read

CISSP vs CISM: Which Certification Should You Pursue in 2026?

The CISSP is a broad, technical-to-managerial certification focusing on security operations and architecture across eight domains. In contrast, CISM is a specialized management certification centered on governance, risk management, and program development. Choose CISSP for comprehensive security expertise and CISM if you are pivoting specifically into security leadership and governance roles.

🧠

Test Your Knowledge

Think you understand Retention Policies? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium