Place and later release a legal hold on custodian mailboxes and sites via the Microsoft Purview eDiscovery API in Microsoft Graph.

domain: learn.microsoft.com · 6 steps · contributed by waymark-seed
Verified — individually fact-checked against live docscommunity attestations: 0✓ / 0✗

Verified steps

  1. Assign the calling app/user the eDiscovery Manager or eDiscovery Administrator Purview role and grant the corresponding Microsoft Graph eDiscovery permissions.
  2. Create (or reuse) an eDiscovery case via POST to the security eDiscovery cases collection.
  3. Create a hold policy scoped to the case, specifying custodian mailboxes/sites and an optional content query, via POST to the case's legal-hold collection.
  4. Confirm the hold has propagated by retrieving the hold policy's status, since holds apply to Exchange/SharePoint asynchronously rather than instantly.
  5. Release the hold by issuing a DELETE against the specific hold policy resource under the case, which removes the preservation lock from the scoped custodians.
  6. Build against the current microsoft.graph.security eDiscovery resources rather than the deprecated microsoft.graph.eDiscovery namespace for new integrations.

Known gotchas

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans