How to Search Microsoft 365 eDiscovery for Specific File Attachments
Question details
The user is unable to successfully create an eDiscovery query to identify email messages containing specific file attachments, such as RTF files.

- Product
- Microsoft 365 eDiscovery
- Device & OS
- not provided
- Scenario
- Attempting to search across all Exchange mailboxes for messages that contain specific types of file attachments.
- Observed behavior
- The created query fails to identify or return the messages that contain the specified file attachments.
Ensure you have the appropriate administrator or eDiscovery Manager permissions assigned in the Microsoft 365 compliance center before attempting to manage queries or contact support.
Open a Microsoft 365 Support Service Request
When standard queries fail to identify specific attachments across Exchange mailboxes, Microsoft support intervention is required to investigate potential indexing or query issues.
Advanced eDiscovery searches rely on mailbox indexing. If queries for specific file types (like RTF) are not yielding results, there may be a backend indexing issue or an undocumented limitation requiring direct investigation by the Microsoft 365 support team.
Sign in to the Microsoft 365 admin center using an account with administrator privileges.
Locate and click on the 'Support' menu on the left-hand navigation pane, then select 'Help & support' or 'New service request'.
Describe the specific issue, mentioning that your eDiscovery case for all Exchange mailboxes is failing to identify specific file attachments (e.g., RTF files), and submit the request.
If you are an end user or eDiscovery manager without global admin rights, contact your organization's IT administrator to open the service request on your behalf.

Verify KQL Attachment Syntax
Ensure that the query syntax used to search for attachments conforms to the standard Keyword Query Language (KQL) requirements.
Open and Edit Exported eDiscovery Documents with WPS Office
While Microsoft 365 handles complex administrative eDiscovery searches, WPS Office is the perfect free, lightweight alternative for viewing and managing the actual documents you export from those searches. Open exported RTF, Word, and Excel files instantly without requiring a heavy subscription.
- 1. Download the Software: Download and install WPS Office from the official website.
- 2. Locate Exported Files: Find the RTF or Office attachments you exported from your eDiscovery search.
- 3. Open and Review: Right-click the exported file and select 'Open with WPS Office' to view and edit its contents seamlessly.

Frequently Asked Questions
What query syntax should I use to find specific file types in Microsoft 365 eDiscovery?
You can use Keyword Query Language (KQL) properties such as 'filetype:ext' (e.g., filetype:rtf) or 'attachmentnames:*.ext' (e.g., attachmentnames:*.rtf) to search for specific file types in Exchange mailboxes.
Why might my eDiscovery query fail to return messages with known attachments?
This can happen if the attachments are encrypted, password-protected, in an unsupported format, or if the mailbox indexing is corrupted. Unindexed items often require support intervention to resolve.
Can an eDiscovery manager open a service request in Microsoft 365?
Typically, only users assigned the administrator role in Microsoft 365 can open support tickets via the admin center. eDiscovery managers will need to work with their global administrators to submit a service request.




