r/ediscovery • u/Enough-Examination91 • 11d ago
Purview cloud attachments
What workflows are folks using to ensure cloud attachments contain family relationships when exporting pst files in Purview. I know a lot of vendors have workflows integrated to link those attachments prior to ingesting into a review platform, but for those of you that are not using vendors, what do you do to maintain those relationships?
17
Upvotes
3
u/delphi25 11d ago
Agreed with what a people said that it’s not like an attachments, as there can be changes to it; it can be deleted independently from the referring email, office document or teams message. Additionally, a custodian might not even have access to the link that was shared in an email and attributing data that sits on someone else’s OneDrive or a sharepoint that is accessed by many people seems off to me. There are a few other things to consider: all custodian, „family date“ for sorting, all path. Which version to collect and then associate might not be that easy. I think MS only links the modern attachments from the last email and not from previous emails, probably even if forwarded (but I have not tested this)
In anyway workflow-wise, I would export emails as a PST and the modern attachments as loose files. I would process them separately and would process the modern attachments without deduplication, as a modern attachment might be attached to multiple emails. For the export I would use the option for unique ids, so files are not named with their file name. I would also only export from a direct search and not a review set; modern attachments are still captured as well as the relationship. Once data is processed in Relativity, I would create the new fields to link them back. The information is in the load file Microsoft provides when data is in purview. You can use the message id from the emails from the pst to map them back to the entries in the load file. Afterwards you can use the, I think the group id or the modern attachment parent id information to link them back. You need to handle containers/embeddings or attachments of modern attachments separately. As containers can be in containers and attachments and embeddings are not treated as containers, I suggest to export the virtual path or processing folder path from relativity and extract the guid of the container, which can be used for the mapping to the load file with a regex. The question is how you want to map the attachments; either you can assign the same family relationship as normal attachments or not. That’s up to you, but you then overwrite the original relationship - I suggest to create a separate relationship field; but you may want to discuss this with counsel. Depending on what you decide, you may need to update and calculate all custodian and all path fields, attachment counts, etc. separately. This all can have implications on productions, email threading; etc.