Question
How do I configure eDiscovery to collect from SharePoint 365?
Prerequisites
- Internet access from the Collections Work Manager machine
Answer
Follow the steps below.
1) Create a SharePoint Service Account
- Sign in to the O365 Admin console at https://admin.microsoft.com as an administrator
- Under User Management click "Add user"
- Specify a name and credentials for the new user.
- Expand Roles and select "Customized administrator", then check "SharePoint administrator"
- Click "Add" to create the new user
2) Grant Permissions Using either the Modern or Classic SharePoint Admin Center
Modern SharePoint Admin Center:
- Login to your SharePoint Admin page (https://-admin.sharepoint.com) as an Administrator
- Under Sites on the left, click "Active sites"
- Do the following for every site you wish to be able to collect from:
- Highlight the desired site
- Click "Owners" at the top and select "Change admins"
- Add your newly created service account user and click "Save"
Note: Sites may be listed in eDiscovery even if the specified account is not an admin of that site. However, collections against these sites will fail until you add the account as an admin.
Classic SharePoint Admin Center:
- Login to your SharePoint Admin page (https://-admin.sharepoint.com) as an Administrator
- In the menu on the left, click "Classic SharePoint admin center"
- On the left, click "site collections"
- Do the following for every site you wish to be able to collect from:
- Highlight the desired site
- Click "Owners" at the top and select "Manage Administrators"
- Add your newly created service account user under "Site Collection Administrators" and click "OK"
Note: Sites may be listed in eDiscovery even if the specified account is not a Site Collection Administrator of that site. However, collections against these sites will fail until you add the account as a Site Collection Administrator.
3) Add a SharePoint Connector in eDiscovery
- Login to eDiscovery as an Administrator
- Click "Data Sources" at the top
- Click the SharePoint tab
- Click the plus sign
to create a new connector
- Specify the Web Application URL and the Username and Password of the previously created service account user, then click "OK"
Note: The Web Application URL should be a root site in the form https://domain.sharepoint.com
Perform Collections
- In the Jobs tab, click on the
to create a new collection
- In the pull down box, select Collection
- Select SharePoint in the selection box below
- In the SharePoint tab, select the SharePoint site that you need to collect from
- Complete the collection as you would any other collection
Notes
- AD eDiscovery does not support collecting from sites based off the Modern "Team site" template.
- Sites based on the Modern "Team site" template will not be listed in the Classic SharePoint Admin Center.
- "Admin" in the Modern SharePoint Admin Center is the equivalent of "Site Collection Administrator" in the Classic SharePoint Admin Center.