logo
search
Compliance Problems

How to Exclude Specific File Names in Microsoft Purview eDiscovery Search

Kushani NimanthikaKushani Nimanthika Sep 28, 2026 870 views

Question details

The user needs to configure an eDiscovery search in Microsoft Purview that includes specific keywords while excluding messages containing certain file names or attachments.

How to Exclude Specific File Names in Microsoft Purview eDiscovery Search
Product
Microsoft Purview
Device & OS
not provided
Scenario
Creating complex search queries in Microsoft Purview eDiscovery to filter out specific file attachments and reduce false positive compliance results.
Observed behavior
The user wants to refine eDiscovery searches to include required keywords but omit specific document names, but they are unsure of the correct syntax or workload support.
Before you start

Ensure you have the appropriate eDiscovery permissions (such as eDiscovery Manager) in the Microsoft Purview compliance portal before attempting to create or modify search queries.

Solution 1Recommended

Use Keyword Query Language (KQL) to Exclude File Names

Utilize standard KQL operators in your eDiscovery search query to explicitly exclude specific file names or attachment types from your search results.

Microsoft Purview eDiscovery relies on Keyword Query Language (KQL) for building complex queries. By combining standard inclusion keywords with exclusion operators, you can accurately filter out unwanted attachments.

1
Access the eDiscovery case

Log in to the Microsoft Purview compliance portal and navigate to eDiscovery (Standard or Premium) from the left pane, then select your specific case.

2
Open the query builder

Navigate to the 'Searches' tab within your case and click 'New search' or select an existing search to edit your query.

3
Input the inclusion keyword

In the search query box, type the primary keywords or phrases that the messages must contain to be flagged in your search.

4
Add the exclusion operator

Add a space after your keywords and type the minus sign followed by the attachment property, like this: -attachment:"filename.docx" (replace "filename.docx" with the exact file name you want to exclude).

5
Run and verify the search

Click 'Save & run' to execute the search, then review the search statistics and sample results to ensure the specified files have been successfully excluded.

Use Keyword Query Language (KQL) to Exclude File Names
Supported Properties: Not all workloads support every KQL property equally. If excluding by specific file name fails, try excluding by file extension using the -filetype: operator.
Free Microsoft Office alternative

Switch to WPS Office for Efficient Document Management

While Microsoft Purview handles complex enterprise compliance tasks, everyday document creation doesn't need to be complicated. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for writing, editing, and managing your everyday work files.

  1. 1. Download the installer: Visit the official WPS Office website and click the 'Download' button to get the free installer for your operating system.
  2. 2. Install the software: Run the downloaded installer file and follow the on-screen prompts to set up WPS Office on your device.
  3. 3. Open your documents: Launch WPS Office and seamlessly open your existing Microsoft Word, Excel, or PowerPoint files without losing any formatting.
Fully compatible with Microsoft Office formats (Word, Excel, PowerPoint) and eDiscovery exports.Lightweight software that loads instantly and consumes minimal system resources.Familiar, tabbed user interface for easy navigation and document switching.Built-in PDF toolkit to view, edit, and secure confidential documents offline.
QA img-9

Frequently Asked Questions

Can I exclude all files of a specific format in eDiscovery instead of a specific name?

Yes, you can use the file type exclusion operator in your KQL query. For example, typing -filetype:pdf will exclude all messages and documents that have a PDF attachment, regardless of the file's name.

Why are excluded file names still appearing in my Purview eDiscovery search results?

This typically happens if the excluded file is embedded within another document (like a ZIP file or an attached email) that doesn't match the exclusion criteria, or if the specific search property is not fully supported by the workload (e.g., searching Teams chats versus Exchange mailboxes).

Is it possible to include a keyword but exclude documents where the keyword is only in the attachment name?

Yes, you can refine your search by including the keyword as your main search term and adding an exclusion operator such as -attachment:"*keyword*" to omit results where that specific term appears in the attachment's file name.