Feedback by UserVoice

Office 365 Security & Compliance

We have partnered with UserVoice, a third-party service and your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy. Please do not send any novel or patentable ideas, copyrighted materials, samples or demos for which you do not want to grant a license to Microsoft.

Welcome to the Security (Protection) & Compliance UserVoice forum. We’re happy you’re here! If you have suggestions or ideas on how to improve Security or Compliance related features in O365, we’d love to hear them!

How it works
◾Check out the ideas others have suggested and vote on your favorites
◾If you have a suggestion that’s not listed yet, submit your own — 25 words or less, please
◾Include one suggestion per post

Thanks for joining our community and helping improve these features in Office 365!

Need Tech Support? Please see the O365 Community for the product or feature you are having issues with, or open a support ticket through your Office 365 administrator portal.

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. OneDrive for Business unable to perform delete folder directly caused by Retention Policy

    Dear Microsoft,

    OneDrive for Business is one of the useful tools for cloud storage whereby end user should be able to folders (even got files inside) easily even being applied with retention policy.

    Retention policy is suppose used on backend which not suppose to affect on OneDrive for Business usage. We are have 500 users getting impact on this. (and i assume all users having this issue as Microsoft support tested having this issue - "behaviour")

    I was informed by Microsoft that this is by default preservation policy design behaviour, which I think this is not consider design behavior anymore…

    696 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  2. Compliance admins should be able to delete labels marked as record

    Under Classifications, a label created and marked as Record cannot be later changed or, more importantly, deleted by any administrator. As an admin can remove a document from bearing the status of record, they should therefore be able to delete a label with Record status. The combination of Record and Delete after 'x' years is very dangerous - not to mention a department may update their requirements in time.

    352 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  3. Preservation Lock enable and disable with special permission or at least with Microsoft Support.

    Preservation Lock can be set so easily that if you click on the policy on the right it will give you the option of on and Off resulting in a lock that even Support can not remove. Either provide a secure way of enabling disabling to the user or at least give it to Microsoft Support to do it on Client's behalf.

    312 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  4. Office 365 labels - allow deletion of documents with labels

    Please allow users to delete documents with Office 365 labels and keep such deleted documents in a secure location for the duration of the retention period as described on the following label tooltip in Office 365: ""We'll make sure the labeled content stays put where it currently lives. For example, email messages will stay in mailboxes and docs will stay in SharePoint or OneDrive libraries. If users modify or delete the content, we'll keep a copy of it in a secure location so you can get to it if you need to." At the moment SharePoint documents with labels can't…

    289 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  5. Allow dynamic retention policy based on group membership

    The below is too great a restriction and renders the retention policy useless.

    Groups selection confirmation

    The specified groups will be expanded so that an In-Place Hold can be put on the mailboxes in these groups. Only the mailboxes that are currently members of these groups will be placed on hold. Mailboxes added to or removed from these groups won't be added or removed from this hold. After setting the group for the location, the new member changes for this group will not auto apply to this location settings. Do you want to expand these groups?

    268 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  6. Retention Labels - Time Left - Report all files with label

    Hi,

    Would it be possible to have a report system or dahsboard, which would report on Time left of the retention period for all items or even just files that have a particualar label applied that the user has created.

    For example. A calculated column that shows the item, location, retention/deletion, time remaining before it happens, based on whether it was, either labeled, created, last modifed. (hope it makes sence)

    Currently you have to use the 'content search' area [search and investigation] and do the calculations there within excel on any given report.

    see the post here for some more…

    137 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  7. Retention Policy - Office 365 Groups - Separate Deletion settings for Exchange & SharePoint workload

    Retention Policies for Office 365 Groups currently treat all resources the same (i.e. Exchange and SharePoint). We need the ability to configure email items to delete after X years, but not delete documents stored on SharePoint.

    132 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  8. Allow duration of Retention label to be changed when the retention is based on when the label is applied

    When a retention label duration is based on the date the label is applied, the retention period may not be changed. It can be changed if the Created or last modified is chosen. This is impacting our ability to use the retention policies as they need to be active from the date of application with the capability to change duration in the future.

    103 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  9. Allow adding metadata fields to pending disposition reports

    Pending disposition and completed disposition reports are lacking metadata required to be captured by Government organisations for all disposed documents. Can we have the following metadata fields available in all disposition reports exported from Office 365:
    • Unique identifier (document ID number)
    • File name
    • Date created
    • Creator/Author
    • Date last modified
    • Last modified by
    • Date of disposal
    • Disposal label
    • Disposed by

    It would be even better if system admins could add/remove metadata fields from all disposition reports.

    Unfortunately, until these fields become available in Office 365 disposition reports, document disposal won’t meet the…

    85 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  10. Retention Compliance Rule - Exclude Item Classes

    Provide the capability to exclude item classes from a Retention Compliance Rule. This will allow for excluding Notes, Tasks, and Calendar items

    MS has published articles detailing how to do this for hold policies dating back to January of 2018, but the cmdlets still do not exist.

    https://support.office.com/en-us/article/overview-of-retention-policies-5e377752-700d-4870-9b6d-12bfc12d2423

    Set-RetentionComplianceRule [-ExcludedItemClasses <MultiValuedProperty>

    68 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  11. folder level default for compliance asset id

    A compliance asset id value can be applied to a folder and this should be 'inherited' as items are created or uploaded to the folder. However, there is no inheritance unlike the classification label. This means a user has to manually tag the asset id of any items they create or upload to the folder. They will not do it or make mistakes. Please can the compliance asset id inherit from the library or folder in the same way as the classification label.

    58 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  12. Record retention label - Disable "Record Status" toggling feature

    Based on Microsoft new feature release in Jan 2020, it allows user to toggle "Record status" to lock / unlock for a documents that are being applied with record retention labels. This feature is undesirable whereby it allows users with "members" rights to unlock and modify a record. We wish to have more control in terms of record handling and wish to disable this feature. Is there a way to hide this option from users and only allow site collection administrator to do so?

    52 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)

    The ability to mark a document as a record and restrict actions that can be performed on the record is an essential goal for any records management solution. However, collaboration might also be needed for people to create subsequent versions. This action creates a record in the Records folder in the Preservation Hold library, where it resides for the remainder of its retention period.

    While the document is unlocked, any user with standard edit permissions can edit the file. However, users can’t delete the file, because it’s still a record. When editing is complete, a user can then toggle the Record status from Unlocked to Locked, which prevents further edits while in this status.

    https://docs.microsoft.com/en-us/microsoft-365/compliance/record-versioning?view=o365-worldwide

    Alternatively, you can use the Regulatory Record Label which blocks versioning: https://docs.microsoft.com/en-us/microsoft-365/compliance/records-management?view=o365-worldwide#compare-restrictions-for-what-actions-are-allowed-or-blocked

  13. Alert Policy for changes to Retention Policy

    It would be great if we could set up an alert policy for when someone makes changes to a Retention Policy in Security and Compliance. We are moving away from Litigation Hold to Retention Policies and it would be very easy for someone to remove the policies by accident or intentionally.

    44 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  14. Retention label rules should also apply to Document Sets in SharePoint

    Currently it's possible to apply a retention label to a Document Set in SharePoint, which means that all documents in it are retained and disposed according to the rules set on the label. But the Document Set are not disposed of, only documents within it. As Document Sets usually have custom metadata (e.g. Personal Identifiable Information) which is subject to data retention regulations, it is necessary for Document Sets to be subject to the label rules as well.

    40 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  15. Retention Policy - SharePoint site exclusion - Site Admin permissions required

    When trying to exclude a SharePoint site from a retention policy in the new unified retention policy section, you have to be an admin of the SharePoint site. If you are not a site admin, when you try to FIND the site so it can be selected, it returns no site found. Support have verified this is not a bug and is the way this works at the moment, but for a company which is only giving access to sites to people who need it, this behaviour needs changing so that a O365 Global Admin/SharePoint Admin can lookup sites.

    39 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  16. Retention Label when defined as record don't allow change metadata

    When define a Retention Label as a record don't allow to change metadata (columns) in SharePoint. Now it only not permite change a file, but we can change metadata related to the file in document library.

    38 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  17. Automatically remove deleted auto-applied labels from documents

    Auto-applied retention label, and the policy, was deleted, but the label is not going away for the records that were auto-tagged by this policy.

    For example, we created a new label, assigned a policy that would auto-apply the label based on keywords in the documents of the library. Then we deleted the policy and the label, but the document's retention label didn't disappear. We have waited 7+ days just to be safe, but the label on the record is still there. Is this the intended design? (We opened a ticket with Microsoft and they've confirmed this is the case -…

    35 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  18. skype For Business Org-wide Retention Policy

    Add the ability to have an organization wide conversation retention policy for Skype For Business the current limit of 1000 users dosent help when you have 10k + users

    32 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  19. Make the disposition date available as column in SharePoint libraries

    Based on the Retention Label, the retention period and date a Retention period starts, the disposition date can be calculated. For end users it is an advantage if they can see, filter or sort on the disposition date in a SharePoint library. A nice to have is also the action that follows de disposition date, like Delete, Trigger disposition review or retention period ends.

    29 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
  20. Allow SharePoint Subsites be be Excluded from Retention Policy

    Enable the Ability to Exclude Subsites from Retention Policies to allow for easier deletion and management of sites

    28 votes
    Vote
    Sign in
    (thinking…)
    Sign in with: Facebook Google
    Signed in as (Sign out)
    You have left! (?) (thinking…)
← Previous 1 3 4 5
  • Don't see your idea?

Feedback and Knowledge Base