Exchange Online Message Search and Purge
Search, validate and purge risky mail with approval evidence
Message purge should be treated as a controlled incident response procedure because it can permanently remove content from user mailboxes.
Executive Summary
This guide describes how to search and purge incorrectly sent or risky email messages from Exchange Online mailboxes using Microsoft Purview compliance search and PowerShell.
This procedure should be treated as a controlled incident response operation because it can permanently delete messages from user mailboxes.
Business Scenario
Organizations may need to remove messages when:
- A confidential email was sent to the wrong recipients
- A malicious message was delivered to multiple users
- A phishing campaign bypassed initial controls
- An internal mail was sent with incorrect attachment or content
- Legal or compliance team requests controlled removal
Important Warning
Message purge is a destructive operation.
Before execution:
- Obtain approval from authorized owner
- Confirm legal and compliance position
- Validate search query carefully
- Use a pilot search before purge
- Document all actions
Process Overview
Required Permissions
Administrators may require appropriate compliance and Exchange permissions.
Typical roles include:
- Compliance Administrator
- eDiscovery Manager
- Exchange Administrator
- Organization Management role where applicable
Step 1. Define Search Criteria
Search criteria may include:
| Criteria | Example |
|---|---|
| Subject | Specific mail subject |
| Sender | Sender email address |
| Date | Sent date |
| Recipient Scope | All mailboxes or selected mailboxes |
| Keywords | Unique message content |
Step 2. Create Compliance Search
Example structure:
New-ComplianceSearch `
-Name "Search-Message-Removal" `
-ExchangeLocation All `
-ContentMatchQuery 'subject:"<subject>" AND sender:"<sender>" AND sent:"<date>"'
Adjust the query to match the actual incident.
Step 3. Start Search
Start-ComplianceSearch -Identity "Search-Message-Removal"
Check status:
Get-ComplianceSearch -Identity "Search-Message-Removal"
Proceed only after the search status is completed and results are validated.
Step 4. Purge Message
Hard delete example:
New-ComplianceSearchAction `
-SearchName "Search-Message-Removal" `
-Purge `
-PurgeType HardDelete
Use HardDelete only when approved.
Validation
Validate that:
- Target message no longer exists in user mailbox
- Deleted Items does not contain the message
- Recoverable Items behavior is understood
- Search action completed successfully
- Incident record is updated
Operational Controls
| Control | Description |
|---|---|
| Approval | Legal, compliance or security approval required |
| Query Review | Peer review search query before purge |
| Pilot Search | Validate against small scope if possible |
| Audit Record | Maintain PowerShell command history and approval |
| Communication | Notify stakeholders only as required |
Risk and Mitigation
| Risk | Impact | Mitigation |
|---|---|---|
| Wrong query | Wrong messages deleted | Peer review and test search |
| No approval | Compliance issue | Require written approval |
| User impact | Business record removed | Validate legal retention requirements |
| Delayed action | Risk message remains accessible | Define incident SLA |
Recommended Deliverables
- Incident Request
- Search Query Evidence
- Approval Record
- Purge Execution Log
- Validation Result
- Final Incident Summary
References
- Microsoft Purview Compliance Search
- Exchange Online PowerShell
- New-ComplianceSearch
- New-ComplianceSearchAction
한국어 요약
Exchange Online message recall 또는 purge 작업은 잘못 발송된 메일, 보안 사고, 민감정보 노출 가능성이 있는 메시지를 신속하게 검색하고 조치하기 위한 운영 절차입니다.
실무에서는 검색 query, 승인 기록, 영향 범위, Purview retention, 감사 증적을 함께 관리해야 합니다. 잘못된 query로 메시지를 삭제하면 업무 기록 손상이나 compliance 이슈가 발생할 수 있으므로 peer review와 test search가 중요합니다.
검색 키워드
- Exchange Online message purge
- Microsoft Purview Compliance Search
- Exchange Online message recall
- New-ComplianceSearchAction
- email incident response
- Exchange Online 메일 삭제
- Purview 콘텐츠 검색
Contact / Asset Request
For message purge approval templates, compliance search evidence logs, incident response runbooks or validation checklists, use Contact and Asset Request.