Skip to main content

Exchange Online Message Search and Purge

EXCHANGE ONLINE INCIDENT OPERATION

Search, validate and purge risky mail with approval evidence

Message purge should be treated as a controlled incident response procedure because it can permanently remove content from user mailboxes.

FindQuery
CheckResult
ApproveOwner
PurgeReport

Executive Summary​

This guide describes how to search and purge incorrectly sent or risky email messages from Exchange Online mailboxes using Microsoft Purview compliance search and PowerShell.

This procedure should be treated as a controlled incident response operation because it can permanently delete messages from user mailboxes.


Business Scenario​

Organizations may need to remove messages when:

  • A confidential email was sent to the wrong recipients
  • A malicious message was delivered to multiple users
  • A phishing campaign bypassed initial controls
  • An internal mail was sent with incorrect attachment or content
  • Legal or compliance team requests controlled removal

Important Warning​

Message purge is a destructive operation.

Before execution:

  • Obtain approval from authorized owner
  • Confirm legal and compliance position
  • Validate search query carefully
  • Use a pilot search before purge
  • Document all actions

Process Overview​

Message purge control flowValidate before destructive action
01Incident reportedConfirm business owner, risk type, sender, recipients and message identifiers.
02Compliance searchDefine query, create search and validate matched items before purge.
03Approval gateObtain authorized approval because purge can permanently remove mailbox content.
04Purge and reportExecute controlled purge and document result, scope, timestamp and evidence.

Required Permissions​

Administrators may require appropriate compliance and Exchange permissions.

Typical roles include:

  • Compliance Administrator
  • eDiscovery Manager
  • Exchange Administrator
  • Organization Management role where applicable

Step 1. Define Search Criteria​

Search criteria may include:

CriteriaExample
SubjectSpecific mail subject
SenderSender email address
DateSent date
Recipient ScopeAll mailboxes or selected mailboxes
KeywordsUnique message content

Example structure:

New-ComplianceSearch `
-Name "Search-Message-Removal" `
-ExchangeLocation All `
-ContentMatchQuery 'subject:"<subject>" AND sender:"<sender>" AND sent:"<date>"'

Adjust the query to match the actual incident.


Start-ComplianceSearch -Identity "Search-Message-Removal"

Check status:

Get-ComplianceSearch -Identity "Search-Message-Removal"

Proceed only after the search status is completed and results are validated.


Step 4. Purge Message​

Hard delete example:

New-ComplianceSearchAction `
-SearchName "Search-Message-Removal" `
-Purge `
-PurgeType HardDelete

Use HardDelete only when approved.


Validation​

Validate that:

  • Target message no longer exists in user mailbox
  • Deleted Items does not contain the message
  • Recoverable Items behavior is understood
  • Search action completed successfully
  • Incident record is updated

Operational Controls​

ControlDescription
ApprovalLegal, compliance or security approval required
Query ReviewPeer review search query before purge
Pilot SearchValidate against small scope if possible
Audit RecordMaintain PowerShell command history and approval
CommunicationNotify stakeholders only as required

Risk and Mitigation​

RiskImpactMitigation
Wrong queryWrong messages deletedPeer review and test search
No approvalCompliance issueRequire written approval
User impactBusiness record removedValidate legal retention requirements
Delayed actionRisk message remains accessibleDefine incident SLA

  • Incident Request
  • Search Query Evidence
  • Approval Record
  • Purge Execution Log
  • Validation Result
  • Final Incident Summary

References​

  • Microsoft Purview Compliance Search
  • Exchange Online PowerShell
  • New-ComplianceSearch
  • New-ComplianceSearchAction

한국어 요약​

Exchange Online message recall 또는 purge 작업은 잘못 발송된 메일, 보안 사고, 민감정보 노출 가능성이 있는 메시지를 신속하게 검색하고 조치하기 위한 운영 절차입니다.

실무에서는 검색 query, 승인 기록, 영향 범위, Purview retention, 감사 증적을 함께 관리해야 합니다. 잘못된 query로 메시지를 삭제하면 업무 기록 손상이나 compliance 이슈가 발생할 수 있으므로 peer review와 test search가 중요합니다.

검색 키워드​

  • Exchange Online message purge
  • Microsoft Purview Compliance Search
  • Exchange Online message recall
  • New-ComplianceSearchAction
  • email incident response
  • Exchange Online 메일 삭제
  • Purview 콘텐츠 검색

Contact / Asset Request​

For message purge approval templates, compliance search evidence logs, incident response runbooks or validation checklists, use Contact and Asset Request.