What is data preservation and when should I request it?¶
Data preservation asks a record holder to prevent defined relevant material being lost through ordinary retention, deletion or account closure while the appropriate acquisition process continues. It does not itself disclose the data or freeze all account activity.
Use preservation where loss risk is real¶
It is particularly relevant to short-lived authentication, session, connection and audit records; recently deleted content; active compromise; or an account likely to close. The decision should remain relevant, proportionate and tied to an investigative question.
Several holders may need separate consideration. A cloud provider, identity provider, customer tenant and connected application can record different parts of one event.
Define the material precisely¶
Include the provider and service, account or tenant identifiers, object or event identifiers where known, date range with time zone, record types and any deletion or expiry risk. “Preserve the account” may not identify the volatile evidence required.
Record when the need arose, what was requested, authority or route used and the provider response. Preservation remains separate from lawful acquisition and later evidential interpretation.
Understand what preservation changes¶
It usually affects retention in provider systems. The user may continue to access or alter the live account, and new events may occur. Confirm the scope and duration rather than assuming complete or indefinite protection.
At 16:40, Priya learns that Dave's Microsoft 365 account C-77503 will close overnight and that sign-in and audit records for 1-3 September may be relevant. Preservation request PR-204 names tenant TEN-21, account C-77503, OneDrive object OBJ-4407, the UTC date range, sign-in, audit, version and deleted-item records, and the identified loss risk. Provider acknowledgement ACK-77 confirms only the datasets and period it accepted. That response establishes a documented preservation route for the stated material; it does not disclose the records or freeze Dave's live activity.
The next useful comparison is ACK-77 against the complete PR-204, provider scope and duration, account-closure timeline, separate identity-provider and customer exports, and the eventual acquisition return.
Current Microsoft preservation-control context - checked 3 September 2026
Microsoft Purview provides retention controls and case holds for defined locations. Check the accepted scope and successful application against the holder's response.
An acknowledgement confirms a preservation step. It is not disclosure of the records requested.
The point to remember
Request targeted preservation when relevant cloud records face ordinary loss. Define the exact holder, identifiers, period and datasets while continuing the proper route to obtain them.