Handle an access request

Find data with Microsoft 365

Search your organisation's Microsoft 365 data from a case to find the information in scope of the request.

What this task achieves

Discovery searches the Microsoft 365 services your organisation has connected — Exchange mailboxes, OneDrive files, and SharePoint documents — for material relating to the person who made the request. Everything a run finds is listed on the case, where you can inspect it, exclude items that are out of scope, and carry the rest forward. Discovered files are also added to the case's documents automatically, so when discovery finishes the case holds a body of material ready for review and redaction.

Before you begin

Before you begin

  • Your organisation needs a connected Microsoft 365 connector in Integrations. See Connect Microsoft 365. Data connectors are available on the Growth and Pro plans.
  • The case must have reached identity verification. The Discovery tab is shown while the case is at the identity-verification, data-discovery, or review stage.
  • You need write access to cases. Admins and Members can run discovery; Viewers can see results but cannot start, cancel, or re-run a search.

If any of these are missing, the Start Discovery button is disabled and a note underneath it explains which requirement to resolve first.

  1. Open the case and select the Discovery tab.
  2. Select Start Discovery. A dialog asks you to confirm the search parameters for this run.
  3. In Data Source, choose your organisation's Microsoft 365 connector.
  4. Check Subject Name and Subject Email. They are filled in from the case and cannot be edited here — if they are wrong, correct the case's subject details before searching.
  5. Under Data Sources, choose which services to search: Exchange Emails, OneDrive Files, and SharePoint Documents. All three are selected by default, and at least one must stay selected.
  6. To narrow the search, expand Advanced options:
    • Additional Search Terms takes a comma-separated list, for example invoice, payroll, contract.
    • Date Range (optional) limits the search to a period. Select both a start and an end date — with only one set, the run searches all time.
  7. Select Start Discovery. The case status moves to discovering data.

While a run is active the tab shows Discovery in progress... with a progress card for each selected source, moving through Queued, Searching..., and Complete, along with a count of items found so far. The page refreshes itself every 5 seconds — you do not need to reload.

To stop a run early, select Cancel Discovery and confirm. Cancelling keeps any items already found and shows them as partial results; you can start a new run later. A run can also stop early on its own when it reaches a service limit, such as a maximum number of items or a time limit — the result is reported the same way, as partial results.

Inspect and exclude results

When a run completes, the tab shows the total number of items found and a count for each of Exchange, OneDrive, and SharePoint, with the discovered items listed below grouped by source.

  • Use the preview and download buttons on an item to check its contents. Files are malware-scanned first; if you see File is still being scanned. Please try again shortly., wait a moment and try again.
  • To leave an item out of the response, turn on Exclude from response and record an Exclusion reason. The reason is optional in the product, but recording one supports the case's audit record and your ability to justify the scope of the search.
  • When you are satisfied with the results, select Continue to Review to move the case to the review stage.

Handle empty, partial, or failed runs

No results. If the run completes without finding anything, the tab reports that no data was found and suggests checking the search parameters. You can Re-run Discovery with broader terms or a wider date range, use Manual Upload to switch to the Documents & Review tab and add files yourself, or Continue Anyway to move the case to review without discovered data.

Partial results. If a run fails or is cancelled after finding some items, the tab shows Partial results with a notice that discovery completed with partial results. Review the recovered items, then either Retry Discovery to attempt a full run or Use partial results to continue with what was found.

Failed with nothing recovered. The tab shows Discovery failed with the error and, where available, an error code. Temporary problems — such as Microsoft 365 rate limits or service errors — are retried automatically a few times before a run is marked failed, so a failure usually means the problem persisted. Select Retry Discovery to try again; if failures continue, see Troubleshoot the core workflow.

Select Re-run Discovery on a completed run to search again — for example after refining the search terms. The dialog summarises the previous run's connector, subject, sources, and terms, and asks you to confirm that you understand the previous results will be replaced. After confirming, the start dialog opens pre-filled with the previous parameters so you can adjust them. The Discovery tab always shows the most recent run.

UK GDPR context

When responding to a subject access request you must make a reasonable and proportionate search for the requested information. The sources you select, the search terms you add, and the date range you set are how you scope a discovery run to what is reasonable and proportionate for the request. You are not required to run searches that would be unreasonable or disproportionate, but you must be able to show why — so record your reasoning, including the reason for excluding any discovered item. See the ICO guidance on finding and retrieving information linked below.

This is operational guidance for UK organisations, not legal advice.

Official sources

What happens next

What happens next

Discovered files appear on the case automatically. Continue to Add and organise documents to add anything discovery could not reach and prepare the collection for review.

Last reviewed . UK regulatory context.

Previous
Verify identity or representative authority