Onboarding · export step

Purview export settings
for your SafeRedact case

The Microsoft Purview export settings that produce a package SafeRedact processes completely. Format and package size decide whether the export is usable at all; the completeness settings decide what is inside it.

The export settings

This page covers one step: producing a Microsoft Purview export that SafeRedact can process completely. It is written to be forwarded to whoever operates Purview, who is often not the person running the case. The rest of the case is covered in the full guide.

Two settings decide whether the export is usable: format and package size. Choose Create PSTs for messages, and set the maximum PST package size to 1 GB or 2 GB rather than the 5 GB default. PST is the only mailbox format with complete attachment coverage, because each message is expanded locally and every attachment is read out and scanned as a document in its own right. Individual .msg files are processed and their bodies, headers and recipients are detected, but content inside a .msg attachment is not read.
SettingChooseWhy
Export formatPSTs for messagesThe only mailbox format where attachment content is read out and scanned in its own right
Maximum PST package size1 or 2 GBDefault is 5 GB; processing runs in the browser, which cannot open a file above 2 GB
Maximum .zip package size2 GBMust equal or exceed the PST size; smaller packages also download more reliably
Select items to includeIndexed and partially indexedPartially indexed is where scanned and image-only documents sit; the default leaves them out
Access links (cloud attachments)On, latest versionOff, files shared as links never reach the disclosure. All versions multiplies volume
Separate folders or PSTs per locationOnKeeps custodians separable in review
Include folder and path of sourceOnMailbox structure survives into review and makes navigation far easier
Give each item a friendly nameOnKeeps SharePoint and OneDrive files under their real names rather than a GUID
Condense paths to 259 charactersOnDeep SharePoint paths otherwise break extraction on Windows
Export typeItems with items reportReport-only truncates every string field at 255 characters
Organize conversation into HTML transcriptOn, for TeamsChats arrive as threaded transcripts, which are read natively with participants and timestamps

Review-set exports offer the same settings where they appear. Skip the separate text-file layer; text is extracted from the native files.

Settings that decide completeness

  • Partially indexed items are excluded by default. That set holds scanned documents, image-only PDFs, encrypted files, unsupported types and anything that hit an indexing error. On a subject access request those are exactly the documents you cannot afford to have quietly missing. They arrive without a text layer and OCR runs on them locally in the browser. Note that the setting on the original search governs statistics and preview only; the decision that counts is made at export.
  • Cloud attachments depend on the collection, not just the export. If the original search was not scoped to include them, enabling the export option may not retrieve them and the collection itself may need re-running. Check before exporting rather than after.
  • Including Teams conversations widens the date range. Include Teams and Viva Engage conversations collects a twelve-hour window either side of each responsive message, which increases volume noticeably. That is usually the right call for context, but make it a decision rather than a surprise.

Timing and download

  • Mailbox content exports at roughly 2 GB per hour, per mailbox. One large mailbox is usually the long pole; adding custodians parallelises better than adding years.
  • Any export process cancels automatically after seven days. Split by date range or custodian if a collection is anywhere near that.
  • A single export is capped at 500,000 items, and individual files larger than 5 GB are not exported at all.
  • Download promptly. Search exports expire 14 days after creation and are then permanently deleted. Exports taken from a review set allow 30 days.
  • Extract with 7-Zip rather than the built-in Windows extractor, which resets timestamps and fails on long paths. The zips can then be loaded whole; nested archives are expanded automatically.
  • If a ZIP package itself exceeds 2 GB, extract it first and add the extracted files directly; a single archive over 2 GB cannot be opened in the browser. Alternatively re-export with the package size set to 1 or 2 GB.
  • If the download stalls, suspect the network before the export. Allow pop-ups from Purview, allow the site to download multiple files automatically, save to a local drive rather than a network share, and test on another connection.

What will not be processed

Worth knowing before the export, not at reconciliation. SafeRedact processes PDF, Word, Excel, CSV, JSON, text, HTML, email (PST, MSG, EML) and the contents of zip archives including nested ones.

  • File types outside that list are not picked up. Standalone image files are the common case in a SharePoint or OneDrive collection: a photograph or a screenshot exported as .jpg or .png is not currently examined, and it is not listed as a failure either. Scanned pages inside a PDF are a different matter and are OCR'd normally.
  • Handwriting is never machine-readable. Handwritten annotations and signatures are not detected. If a custodian's material is substantially handwritten, plan for a manual pass on those documents.
  • Reconcile against the item report. The export's item report gives an independent count of what Purview produced, including items it could not retrieve at all. Compare it against the processed count and the failure manifest at the end of the case. The two failure layers are separate and a complete reconciliation uses both. The report is itself a spreadsheet containing names and subject lines, so decide deliberately whether it belongs in the case or stays alongside it as a control document.

Handing it over

Once the packages are downloaded, they go to whoever is running the case. Nothing needs converting or unpacking first: the zips are loaded whole, PSTs are expanded in the browser, and the folder paths from the export are preserved as document names.

The full onboarding guide covers what happens next: setting up the case and the subject details, processing, review, and producing the disclosure.

Questions on any of the above: support@saferedact.app, answered within 24 hours, Monday to Friday. Support is US-based and not staffed at weekends, so from UK or European hours a morning message usually gets a reply the same day.