How to Search and Recover Older Emails in Exchange Online
Question details
A Microsoft 365 administrator needs to search a user's email history to locate and recover email messages that are older than 12 months.

- Product
- Exchange Online
- Device & OS
- not provided
- Scenario
- An administrator is attempting to retrieve older historical emails for a user, typically for compliance, legal hold, or historical reference purposes.
- Observed behavior
- The standard mailbox view does not display emails older than 12 months, requiring the use of specialized administrative tools and retention policies to locate and recover the messages.
Ensure you have global administrator rights in Microsoft 365 and verify that your organization's retention policies are configured to keep emails longer than 12 months.
Use Microsoft Purview eDiscovery or Content Search
Assign the necessary administrative permissions and utilize Microsoft Purview to search and restore older emails.
To recover emails older than 12 months, regular mailbox search is usually insufficient. Administrators must use Content Search or eDiscovery, provided the organization's retention policies have prevented the permanent deletion of these older emails.
Log in to the Microsoft Purview compliance portal and assign yourself the eDiscovery Manager or Compliance Management role under the Permissions tab.
Navigate to 'Content search' in the Purview portal, click 'New search', and specify the target user's Exchange mailbox as the location.
Configure the search conditions by setting a date range for emails older than 12 months and specify any relevant keywords or sender information.
Run the search. Once completed, review the generated report and choose 'Export results' to download the recovered emails as a PST file.

Boost Your Productivity with WPS Office
While Microsoft 365 handles your Exchange Online email server, WPS Office serves as a highly compatible, free, and lightweight alternative to Microsoft Office desktop apps. It is perfect for seamlessly viewing and managing exported CSV logs and documents related to your eDiscovery searches.
- 1. Download the Installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install WPS Office: Run the downloaded installer and follow the on-screen prompts to complete the setup.
- 3. Open Exported Files: Launch WPS Spreadsheets to easily open, filter, and analyze your CSV search reports generated from Microsoft Purview.

Frequently Asked Questions
Why are emails older than 12 months missing from the user's Exchange mailbox?
By default, users might have an archive policy that moves emails older than 12 months to an In-Place Archive, or a retention policy might be permanently deleting them. Always check the user's Archive mailbox first before initiating a Content Search.
Can a regular user perform an eDiscovery search to recover their own older emails?
No. eDiscovery and Content Search require specialized administrative roles, such as eDiscovery Manager or Compliance Administrator, which must be assigned by a Microsoft 365 global administrator.
What formats can I export the recovered Exchange emails into?
When exporting search results from Microsoft Purview, the recovered emails are typically exported into a PST (Personal Storage Table) file. This PST file can then be imported back into Microsoft Outlook or other compatible email clients.




