Compliance
Microsoft 365 email archiving requirements: what you actually need
"Email archiving requirements" means two things at once, and mixing them up is where most buying decisions go wrong. There are the requirements on you — laws and regulations that say certain business records must be kept, unchanged, for years. And there are the requirements on the archive — what a solution must actually do so those obligations are met. This article walks through both for a small or mid-size company running on Microsoft 365, and ends with a checklist you can hold against any solution, including the built-in tools.
Why email is in scope at all
Most retention rules don't mention email — they mention records: contracts, invoices, order confirmations, payroll correspondence, complaints. But in a typical small business, a large share of exactly those records exists only as email. Regulators and courts treat a business email the way they'd treat a business letter: if the paper version had to be kept, the email version does too. That single fact generates all five requirements below.
Requirement 1: Complete capture
An archive is only useful if the message you need is guaranteed to be in it. That means every mailbox and every message — not "the mail users remembered to drag into a folder" and not "the mailboxes an admin remembered to add." In practice, completeness has three failure points worth checking explicitly:
- Shared mailboxes. info@, sales@, and support@ hold the correspondence with the most legal weight and usually have the weakest retention — they're a classic blind spot.
- New hires. If adding a mailbox to the archive is a manual step, it will eventually be skipped. New mailboxes should be picked up automatically.
- Departed employees. When a license is removed, Microsoft 365 deletes the mailbox after a grace period. The archive must keep that mail — retention obligations don't end at offboarding.
Requirement 2: Immutability
The evidentiary value of an archive comes from one property: once a message is stored, nobody can alter or selectively delete it — not the user, and not an admin. A copy that an administrator could quietly edit proves nothing; you'd be asking an auditor or a court to trust your IT department instead of your records.
This isn't a nice-to-have; it's written into the rules. The SEC's record-keeping rule for broker-dealers requires storage that prevents alteration or supports a complete audit trail. Germany's GoBD principles require stored records to be unveränderbar — unchangeable. Even where the rule doesn't spell it out, an archive whose contents can be edited after the fact fails at the moment it's needed most: when someone disputes what was sent.
Requirement 3: Retention periods that fit your obligations
How long you must keep email depends on what the email documents, your industry, and your country. The table shows the ranges most small and mid-size businesses run into:
| Rule | Who it applies to | Typical period |
|---|---|---|
| IRS record-keeping (US) | Any business, for tax-relevant records | Commonly 3–7 years |
| FLSA (US) | Employers, for payroll records | At least 3 years |
| SEC Rule 17a-4 (US) | Broker-dealers, for business communications | 3–6 years, early years readily accessible |
| HIPAA (US) | Healthcare, for required documentation | 6 years |
| GoBD / HGB / AO (Germany) | Any business, for commercial and tax records | 6–10 years depending on document type |
Two practical consequences. First, because email doesn't arrive labeled "tax-relevant" or "payroll", most companies don't sort — they archive everything for the longest period that applies to them, which typically lands somewhere between six and ten years. Second, the archive's retention must be a property of the system, not of a policy an admin can shorten later. For a deeper look at picking a number, see how long should a business keep email?
Requirement 4: Searchability
Retention rules rarely stop at "keep it" — they expect you to produce records on request, within a reasonable time. An auditor asking for "all correspondence with this supplier between 2023 and 2026" is a five-minute task with full-text search across sender, recipient, subject, and body — and a multi-day ordeal if the answer involves restoring backups or opening PST files one by one. If finding a specific email from four years ago takes longer than an afternoon, the archive fails this requirement regardless of how complete it is.
Requirement 5: Access control and an audit trail
An email archive concentrates years of everyone's correspondence in one place — which makes it a privacy risk if access isn't governed. The baseline that satisfies both auditors and data-protection expectations: each user can search their own mail, additional access is granted explicitly per mailbox, and every cross-mailbox access is logged. "All admins can read everything, and nobody would know" is the pattern to avoid — it turns your compliance tool into a liability. How a provider handles storage, encryption, and access is worth reading before you commit; ours is documented on the security page.
Why native Microsoft 365 retention alone falls short
Microsoft 365 does ship preservation tooling — Purview retention policies can keep mail beyond user deletion, and configured carefully they cover the core "keep it" requirement. Held against the full list above, though, three gaps remain for a typical small business:
- Licensing and upkeep. Meaningful retention setups need E3-class licensing on every covered mailbox, plus someone who designs the policies and keeps them correct as people join and leave.
- Retrieval is admin-only. Preserved mail is retrieved through eDiscovery — every "find that email from 2023" becomes an IT task rather than a self-service search.
- The custody problem. The preserved copy lives inside the same tenant, under the same admins, whose actions it's supposed to make provable. A policy quietly shortened is mail quietly aging out.
None of this makes retention policies useless — for some organizations they're a legitimate answer, and the full side-by-side is here: Microsoft 365 retention policies vs. a dedicated email archive. The point is narrower: measured against completeness, immutability, self-service search, and independent custody together, the native tools alone usually leave requirements open.
The requirements checklist
Hold this against whatever you're evaluating — a product, or your current setup:
- Every mailbox is captured automatically — including shared mailboxes and new hires, with no manual step that can be forgotten.
- Mail of departed employees stays archived and searchable after the account and license are gone.
- Archived messages cannot be altered or selectively deleted by anyone, including admins.
- Retention covers your longest obligation — for most businesses, six to ten years.
- Full-text search across sender, recipient, subject, and body — self-service, not an IT ticket.
- Access is per mailbox, extra access is granted explicitly, and cross-mailbox access is logged.
- The archive is an independent copy outside your tenant, exportable in a standard format like
.eml.
mailvault365 was built to check exactly this list for Microsoft 365: connect your tenant once, and every mailbox — shared ones and departed employees' included — is archived automatically to tamper-proof storage, with full-text search for every user and per-mailbox access control with a full access log. Pricing is per mailbox, and the 14-day trial needs no credit card — long enough to run the checklist against your own tenant instead of a brochure.