Yes, with real limits. Microsoft Purview includes a redaction capability, but it lives in one specific place: review sets in eDiscovery (Premium). Understanding exactly what that tool does, and what it was built for, is the difference between a defensible disclosure and a workflow that runs out of road halfway through a DSAR.
What Purview's Redaction Tool Actually Does
In an eDiscovery (Premium) case, documents added to a review set can be opened in an annotation view. The tool offers area redactions (draw a box over content to hide it), text selection for deletion, and freehand pencil markup. Annotations save with the document, but by Microsoft's own documentation they do not change how the document appears in the review set, in search results, or in exports until you commit them. Committing generates a PDF version of the annotated document, which Microsoft describes as reducing the risk of exporting the unredacted native version.
Three properties follow from that design. The redaction is manual: a reviewer draws each redaction on each document. It is per-document: there is no operation that applies a redaction decision across an export. And the committed output is a PDF, regardless of the source format: a redacted DOCX or XLSX leaves the review set as a PDF work product.
Content Search and eDiscovery (Standard) Have No Redaction Step
The annotation tool is a review-set feature, and review sets are an eDiscovery (Premium) capability. Content Search and eDiscovery (Standard) cover search, hold, and export; what they produce is the unredacted export itself: PSTs for mailboxes, native files for documents. If your licensing or workflow puts you on either of those paths, redaction happens entirely after export, in whatever tool you bring. Microsoft's newer unified eDiscovery experience in the Purview portal consolidates these routes, but the shape of the workflow is unchanged: search, export, then redact the export.
Why the Annotate Tool Is the Wrong Shape for a DSAR
The review-set tool was built for litigation work product: a lawyer marks privileged or irrelevant passages on the specific documents that matter to a case. A data subject access request inverts every one of those assumptions. The volume is the whole export, not a shortlist. The task is finding personal information you do not already know is there, and the annotation tool redacts only what a person marks; it does not detect anything for you. And the goal is asymmetric: preserve the data subject's information while redacting other people's, a distinction the tool has no concept of.
On a mailbox-sized request under a 30-day clock, manually drawing redactions one document at a time is not a plan. That is not a criticism of Purview; it is a scoping fact. Purview's job in a DSAR is collection and export, and it does that well.
Redacting a Purview Export at DSAR Scale
The workflow that fits is: export from Purview, then run detection and review on the export. SafeRedact processes Purview exports directly, supporting 11 file types (PST, PDF, DOCX, XLSX, EML, MSG, HTML, TXT, CSV, JSON, ZIP), with attachments and forwarded messages included in detection. DSAR mode preserves the named data subject while other individuals' personal information is flagged across every file, a human reviews each detection before export, and the output ships with a processing summary and audit trail. Files never leave your browser: documents are processed client-side and only extracted text is sent for AI detection.
The Purview export guide documents the exact export settings, including exporting mailboxes as PSTs, and the Purview eDiscovery redaction guide covers the full workflow from export to disclosure pack.
Redaction Is Not Deletion
One adjacent confusion worth settling: redacting an export does not remove anything from your tenant, and deleting from your tenant does not produce a disclosure. Deletion and erasure obligations, under GDPR, UK GDPR, or Quebec's Law 25, are fulfilled in the source systems, and inside Microsoft 365 that is Purview's records-management side: retention policies, retention labels, and deletion workflows. Redaction produces the copies you disclose; retention and deletion govern what stays in the tenant. A complete subject-request program runs both.
Redact Purview Exports Without the Manual Grind
AI-powered detection, human review, and DSAR mode for Microsoft 365 exports. Files never leave your browser.
Start Your EvaluationRelated Guides
Microsoft, Microsoft 365, Microsoft Purview, Content Search, SharePoint, Exchange Online, OneDrive, and Teams are trademarks of Microsoft Corporation. SafeRedact is not affiliated with or endorsed by Microsoft. Purview capabilities described here reflect Microsoft's public documentation; consult Microsoft Learn for current behavior.