Study guide
Technical reference and lesson notes
Purpose of This Lesson
Microsoft Purview Content Search helps investigators locate relevant content across Microsoft 365 locations. It is useful when a security, insider-risk, compliance, or legal investigation requires searching documents and other stored content for keywords, people, dates, participants, authors, or senders.
The key operational concern is balancing search scope and completeness. A broad search can take a long time in a large tenant, while a sample search returns faster but does not represent the complete result set.
Key Concepts
Content Search in Microsoft Purview
Content Search is accessed through the Microsoft Purview portal, from the eDiscovery solution. An investigator creates a search, defines the data sources and conditions, runs the query, and reviews the resulting statistics or sample data.
Typical search criteria can include:
- Specific people or groups
- All people and groups in the selected scope
- Keywords such as a sensitive project name or business term
- Date and time ranges
- Participants
- Sender
- Author
A search can be scoped to a specific individual rather than the entire organization. Narrowing the source population is often useful for an initial investigation because it reduces noise and search time.
eDiscovery and investigation cases
Content Search is part of the broader Microsoft Purview eDiscovery capability. eDiscovery supports forensic and investigative workflows where evidence may need to be collected, reviewed, and preserved.
An investigation can be organized as a case when the work needs continuing analysis, evidence handling, or collaboration. The exact investigation workflow depends on the organization’s Purview configuration and licensing, but the central principle is to preserve relevant information and document how it was searched and handled.
Holds and deleted content
A hold can preserve relevant data so that deletion does not remove the evidence needed for an investigation. This is important when users may delete documents or messages after an investigation begins.
A hold is not the same as a search. The search locates potentially relevant content; the hold preserves content according to the applicable investigation or compliance process.
Search result modes
When running a search, Content Search provides different ways to inspect results:
- Statistics: A summary of collected data and estimates, including indicators such as categories and query keywords.
- Sample: A subset of items generated per location so an investigator can inspect representative results more quickly.
A sample is useful for early triage, but it should not be treated as proof that all matching content has been identified.
Partial indexing
Some items may not be fully indexed. Partially indexed items may be unsearchable or only partially searchable, which creates a risk of incomplete findings.
Content Search provides options to:
- Include partially indexed items in the search results
- Exclude partially indexed items
- Exclude partially indexed items from locations with no search hits
- Attempt advanced indexing on a sample of partially indexed items
After the search runs, the statistics page should be reviewed for information about partially indexed content. A search with no matches is not necessarily conclusive if relevant locations contain items that were not fully indexed.
Microsoft Security Operations Context
Content Search is not a replacement for Microsoft Sentinel or Microsoft Defender XDR alert investigation. It serves a different purpose:
- Defender XDR: Investigates security alerts, incidents, entities, and attack activity across Microsoft security products.
- Microsoft Sentinel: Correlates security data, runs analytics rules, supports hunting, and orchestrates SOC workflows.
- Purview Content Search: Locates Microsoft 365 content for investigative, compliance, forensic, or evidence-preservation purposes.
A SOC analyst may begin with a Defender or Sentinel alert and then use Purview Content Search to answer questions such as:
- Did a user create or access documents containing a sensitive term?
- Which documents or messages reference a suspected activity?
- Did a particular person or group participate in the relevant communications?
- Is there content that should be preserved before further investigation?
The results should be correlated with the original alert, user and device context, access records, and organizational procedures. Content Search can identify relevant content, but it does not by itself establish malicious intent.
Exam-Relevant Takeaways
- Content Search is accessed in Microsoft Purview > Solutions > eDiscovery > Content Search.
- A search consists of a data-source scope and conditions that define what to find.
- Search scope can include all sources, all people and groups, or specifically selected people and groups.
- Conditions can include keywords, dates, participants, senders, and authors.
- Statistics provide a summary or estimate of collected data; Sample returns a subset for faster inspection.
- Large searches may take a significant amount of time, especially in large environments.
- Partially indexed items can cause incomplete results and must be considered when interpreting findings.
- Advanced indexing can be used to attempt re-indexing a sample of partially indexed items.
- A hold is used to preserve relevant data, including data that a user might otherwise delete; it is not simply another search filter.
- eDiscovery Premium features may provide more efficient search and investigation capabilities where available.
Tool / Feature Decision Guide
| Investigation need | Appropriate capability | Why |
|---|---|---|
| Find documents or communications containing a term | Purview Content Search | Searches Microsoft 365 content using keywords and other conditions |
| Limit the search to one suspected user | Content Search with a specific person as the source | Reduces scope, noise, and processing time |
| Quickly inspect representative matches | Sample results | Provides a subset without waiting for a complete review |
| Review estimates, categories, keywords, or indexing concerns | Statistics results | Gives a summary of collected data and partially indexed items |
| Preserve relevant information against deletion | Hold within the applicable eDiscovery/compliance workflow | Protects evidence needed for the investigation |
| Investigate an endpoint alert or active attack behavior | Defender XDR or Defender for Endpoint | Provides security alerts, incidents, entities, and device investigation data |
| Correlate telemetry and automate SOC response | Microsoft Sentinel | Uses connected data, analytics, hunting, and automation workflows |
Common Exam Traps
- Confusing Content Search with KQL hunting: Content Search uses Purview search conditions; it is not a Sentinel or Defender hunting query.
- Treating a sample as a complete investigation: A sample is intended for faster, representative review and does not replace a full search when completeness matters.
- Ignoring partially indexed items: A search can miss relevant content if items were not fully indexed. Always check the indexing information in the statistics results.
- Assuming a no-hit result proves absence: A no-match result may be affected by scope, search conditions, or incomplete indexing.
- Confusing a hold with a search: A search finds content. A hold preserves content.
- Selecting an unnecessarily broad scope: Searching all locations may increase processing time and produce excessive noise. Start with a justified scope, then expand when needed.
- Assuming the search is immediate: Large-tenant searches can take a long time. Progress information and status should be monitored.
Real-World SOC Analyst Notes
- Define the investigation question before selecting keywords. Generic terms can create a large, noisy result set.
- Record the search name, scope, conditions, start time, result mode, and any indexing limitations. This supports repeatability and evidence handling.
- Preserve relevant data according to the organization’s legal, compliance, and incident-response procedures before users or administrators can alter it.
- Treat search results as evidence that requires validation. Confirm dates, authors, participants, and surrounding context rather than interpreting a keyword match in isolation.
- Use a narrow initial scope when justified, but expand the search if the initial findings indicate additional users, groups, or locations are involved.
- Plan for tenant-wide impact. Broad searches can consume time and operational resources, so coordinate large investigations with the appropriate Purview, legal, compliance, and security teams.
- Review partially indexed items and document the limitation. If the investigation requires high confidence, determine whether advanced indexing or another approved collection method is appropriate.
- Avoid changing or deleting investigation data during review. Maintain evidence-handling and change-control procedures.
Quick Reference Summary
- Open Microsoft Purview and navigate to Solutions > eDiscovery > Content Search.
- Create and name the search.
- Add the relevant data sources, such as specific people or groups.
- Add conditions such as keywords, dates, participants, sender, or author.
- Run the query and choose between statistics and sample results.
- Review progress, results, and partially indexed item information.
- Preserve relevant content using the applicable hold and eDiscovery process.
- Correlate the findings with Defender, Sentinel, identity, and other investigation evidence.
Flashcards
Q: Which Microsoft capability should you use to locate Microsoft 365 documents or communications containing a sensitive keyword?
A: Use Microsoft Purview Content Search through eDiscovery. It is designed to search stored Microsoft 365 content using keywords and additional conditions.
Q: Where in the Microsoft Purview portal is Content Search located?
A: Navigate to Solutions, open eDiscovery, and select Content Search.
Q: When would you scope a Content Search to specific people rather than all people and groups?
A: Use a specific-person scope when the investigation already identifies a likely user or group. This reduces noise and can make the search faster while keeping the scope justified.
Q: What is the difference between Content Search statistics and sample results?
A: Statistics provide summaries and estimates about collected data, while sample results provide a subset of items for quicker inspection. A sample is not a complete result set.
Q: An investigator wants a fast initial view of matches across many locations. Which result mode is most appropriate?
A: Use sample results for initial triage. If the investigation requires complete findings, follow up with a full search and review its statistics and limitations.
Q: Why must partially indexed items be considered when interpreting Content Search results?
A: They may be unsearchable or only partially searchable, so relevant content can be missed. Review the statistics page and consider advanced indexing when appropriate.
Q: What does the advanced indexing option attempt to do?
A: It attempts to re-index a sample of partially indexed items to determine whether they match the query.
Q: What is the decisive difference between a search and a hold?
A: A search locates potentially relevant content; a hold preserves relevant data so it is not lost through deletion during an investigation.
Q: Why might a broad Content Search be operationally problematic in a large tenant?
A: It can take a long time and produce substantial noise. A justified, narrower scope is often better for initial triage.
Q: What is an exam trap involving a Content Search with no matches?
A: No matches do not always prove that the content is absent. Scope, conditions, and partially indexed items can affect the result.
Q: Which tool is the better starting point for investigating an endpoint alert rather than searching documents for a term?
A: Use Microsoft Defender XDR or Defender for Endpoint for endpoint alerts, devices, entities, and attack activity. Use Content Search when the question concerns stored Microsoft 365 content.
Q: Why should an analyst document the search scope and conditions?
A: Documentation makes the investigation repeatable, supports evidence handling, and explains how the results were obtained and interpreted.
Practice Questions
Question 1
A security team suspects that a user discussed a sensitive payroll matter in Microsoft 365 content. The analyst needs to search that user’s content for the term payroll. Which approach is most appropriate?
A. Create a Sentinel analytics rule using the keyword payroll
B. Use Purview Content Search, select the user as a data source, and add payroll as a condition
C. Create a Defender for Endpoint custom detection for the user’s device
D. Use a Microsoft Defender XDR incident to automatically search all documents
Correct answer: B
Purview Content Search is the capability for searching Microsoft 365 content. The analyst can narrow the source to the specific user and use the keyword as a condition.
Question 2
An investigator wants to inspect representative matches quickly before deciding whether a full review is necessary. Which result option should be selected?
A. Statistics
B. Sample
C. Hold
D. Advanced indexing only
Correct answer: B
Sample results provide a subset of items for quicker inspection. Statistics are better for reviewing summaries, estimates, categories, keywords, and indexing information.
Question 3
A Content Search returns no matching items, but the statistics page shows many partially indexed items in relevant locations. What is the best conclusion?
A. The investigation proves that no matching content exists
B. The search should be replaced with a Defender for Endpoint investigation
C. The result may be incomplete, and the analyst should evaluate indexing options and limitations
D. The search automatically placed all content on hold
Correct answer: C
Partially indexed items may be unsearchable or only partially searchable. The analyst should review the indexing details and consider advanced indexing or another approved investigative step.
Question 4
A user may delete documents after learning about an investigation. What capability addresses the evidence-preservation requirement?
A. A Content Search sample
B. A hold in the applicable eDiscovery or compliance workflow
C. A Sentinel workbook
D. A Defender XDR alert suppression rule
Correct answer: B
A hold preserves relevant information against deletion. It is separate from the search used to locate the content.
Question 5
An analyst must search an entire large tenant and wants the fastest possible response. Which statement is most accurate?
A. A tenant-wide search is always immediate if keywords are used
B. Statistics always return every matching item faster than a sample
C. A sample can provide faster representative results, but a broad full search may take considerable time
D. Partially indexed items are automatically irrelevant
Correct answer: C
Large searches can take a long time. Sample results can accelerate initial inspection, but they should not be treated as complete evidence, and partially indexed items can affect completeness.