Skip to content

Control 4.3: Site and Document Retention Management - Portal Walkthrough

This playbook provides portal configuration guidance for Control 4.3.


Prerequisites

Before starting, ensure you have:

  • SharePoint Admin role assigned
  • Microsoft 365 E5 or E5 Compliance license
  • SharePoint Advanced Management enabled for tenant
  • Retention requirements documented by regulation and content type

Step 1: Document Retention Requirements

Identify retention requirements for your organization:

  • Regulatory requirements (FINRA, SEC, SOX, GLBA)
  • Business requirements
  • Legal hold requirements
  • Agent knowledge source retention needs

Retention Periods by Regulation:

Regulation Retention Period Content Type
FINRA 4511 6 years Books and records
SEC 17a-3/4 3–6 years Communications (3y), financial records (6y)
SOX 404 7 years Financial records
GLBA 5-7 years Customer information

Step 2: Configure Inactive Site Policies

Create policy to manage inactive sites:

  1. Navigate to Microsoft Purview
  2. Go to Data lifecycle management > Microsoft 365
  3. Click Open under "Inactive site policies"
  4. Click Create policy
  5. Configure:
  6. Scope: All sites or specific site templates
  7. Inactivity period: 90 days (adjust per requirements)
  8. Notification: Email to site owners and admins
  9. Action: Notify > Mark read-only > Archive
  10. Enable the policy

Step 3: Configure Site Ownership Policies

Ensure sites have active owners:

  1. Navigate to Policies > Site lifecycle management
  2. Click Open under "Site ownership policies"
  3. Create policy to identify orphaned sites
  4. Configure notification to SharePoint admins
  5. Set action for unresolved ownership issues:
  6. Notify admins to assign new owners
  7. Mark read-only after 30 days if no owner assigned

Step 4: Set Organization Retention Defaults

Configure organization-wide settings:

  1. Navigate to Settings in SharePoint Admin Center
  2. Review "OneDrive Retention" setting
  3. Set to 365 days minimum for regulated organizations
  4. Review "Version history limits" settings

Step 5: Integrate with Microsoft Purview

For comprehensive document-level retention:

  1. Navigate to Microsoft Purview Compliance Portal
  2. Go to Data lifecycle management > Microsoft 365
  3. Create retention labels for document-level retention
  4. Apply retention labels to sensitivity-labeled content
  5. Configure retention policies for regulated content types
  6. Coordinate with eDiscovery for legal holds

Governance Level Configurations

Baseline (Level 1)

Setting Value
Inactive site policy Identify sites inactive for 90+ days
Policy action Notify only
Version history Enabled for document recovery
Setting Value
Site ownership policy Identify and remediate orphaned sites
Inactive site action Archive after 180 days
OneDrive retention 365 days minimum
Retention by content type Apply labels to regulated content

Regulated (Level 4)

Setting Value
Policy-driven retention All Zone 3 sites have documented retention
Manual deletion Disabled for regulated content
Deletion logs Immutable and non-editable
Legal hold integration Coordinated with eDiscovery

Validation

After completing the configuration, verify:

  1. Inactive site policy enabled with 90+ day threshold in SharePoint Admin Center
  2. Site ownership policy configured to identify and remediate orphaned sites
  3. OneDrive retention set to 365 days minimum in SharePoint Admin Center settings
  4. Retention labels created for FINRA (6-year), SEC (6-year), and SOX (7-year) content in Microsoft Purview

Expected Result: Inactive sites are identified and managed, orphaned sites have remediation workflow, and retention policies apply to regulated content.


Back to Control 4.3 | PowerShell Setup | Verification Testing | Troubleshooting


Updated: January 2026 | Version: v1.2