Traditional email attachments are relatively straightforward: a file is embedded in the message and the collected item contains the attachment that was sent. Microsoft 365 introduced a different model through cloud, or “modern,” attachments. Instead of attaching a static copy, a user can share a link to a file stored in OneDrive or SharePoint. That distinction matters in litigation and investigations because the linked file can continue to change after the message or Teams conversation is sent.
The collection problem
If an eDiscovery team collects only the email or Teams message containing the link, the communication may be preserved while the substance of the shared document is not. A defensible workflow should therefore consider both the communication and the linked cloud object. Microsoft Purview eDiscovery provides options designed to address this relationship, including collection of the live file, the version shared at the time of the communication, or additional versions depending on the workflow and licensing.
The correct choice is matter-specific. A fraud investigation may need the version that existed when the representation was made. A contract dispute may require the version shared with the recipient plus later revisions. An internal investigation may need the current version and revision history to understand how a document evolved.
Key concerns before collection
- Preservation timing: determine whether a hold should be applied before searching or exporting so relevant cloud content is not lost through normal retention or user activity.
- Version scope: decide whether the matter requires the shared version, the current version, multiple versions, or revision metadata.
- Custodian versus location: the sender of a link may not own the linked file. OneDrive, SharePoint sites, Teams-connected sites and shared libraries may all be relevant.
- Access relationships: document who had access and whether permissions changed when that information is relevant to the investigation.
- Downstream processing: confirm that the review platform can preserve or reconstruct the relationship between the communication and the linked document.
Why this is a defensibility issue
A collection can be technically successful and still be incomplete from an evidentiary perspective. Export counts alone do not answer whether the collected material accurately represents what users communicated and shared. The collection plan should identify modern attachments as a distinct data type and document how linked content and versions were handled.
Digital Shield approaches Microsoft 365 collections by defining custodians, date ranges, data locations, preservation requirements and modern-attachment handling before export. The goal is not simply to obtain data; it is to preserve the communication context needed for review, analysis and production.
Practical takeaway
When Microsoft 365 is in scope, treat OneDrive and SharePoint links as potential evidence objects—not merely text inside an email or Teams message. Validate the collection settings, review the export structure, and document how linked-file versions were selected. That additional planning can prevent a significant evidence gap later in the matter.
Technical references
Platform capabilities and interfaces change. These official resources provide current technical context for the topics discussed above.
Microsoft Purview: Cloud attachments in eDiscoveryMicrosoft Purview: Finding Teams content in eDiscovery