Jump to content

Recommended Posts

Posted

I'm currently looking at setting up email retention policies in Office 365, as per recommendations from our last data protection audit. We have an agreed retention period of up to 3 years on email, although in practical terms we've never put any measures in place to enforce it. This is because some emails will contain financial, personnel or SEND data which might need to be kept longer.

 

My plan is to enforce deletion after 3 years as the default policy on email, but I was wondering how others have dealt with the exceptions for emails with longer retention periods.

 

From what I can see, my options are:

  1. Creating labels and educating staff that they need to use these on emails/folders that need to be retained beyond 3 years
  2. Different policies for different mailboxes dependent on job role, eg, Finance Team 7 years, SEND 31 years, etc.

 

Option 1 strikes me as the most accurate, but also the most time consuming, and most likely to fail as users inevitably don't use the labels correctly. Option 2 would be far easier, but, a pretty broad stroke.

 

Anyone care to share how they've done theirs?

Posted
Hmmm, looks like I'm going to be limited to Option 1, regardless. You need O365 E5/A5 before you can target your retention policies by mailbox or group. E3/A3 and below, looks like you can only have one retention policy for email across the board.
Posted (edited)

I could be wrong (someone correct me), but some of that stuff you only need 1 A5 licence for. The person setting the policies, not everyone.

 

We have a few A5 licences, and I am looking at setting up polices by group. I haven't seen anything that would stop me doing this yet.

 

Edit

 

I'm looking at using ExtendedAttributes to pull users into groups eg;

 

EmailRetention-Staff, or EmailRetention-SLT etc as I hit a wall with dynamic groups which would have been useful... Thanks MS

Edited by smithson83
Posted
I could be wrong (someone correct me), but some of that stuff you only need 1 A5 licence for. The person setting the policies, not everyone.

 

We have a few A5 licences, and I am looking at setting up polices by group. I haven't seen anything that would stop me doing this yet.

 

I had this conversation with a licensing reseller recently about Azure AD P1. Yes, if you buy one license, it opens up the options for the whole tenant. But, my understanding is that every user who uses the functionality should be licensed, so in this case, everyone covered by the retention policy should have an A5 licence.

 

O365 A5 could behave differently to AAD P1 of course.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...