What a Teams retention policy is
A Teams retention policy is a Microsoft Purview setting that keeps Teams chats or channel messages for a period, deletes them after a period, or both. It applies to whole locations and chosen users or teams, counts from the date each message was created, and works behind the Teams app rather than in it.
It governs what happens inside your Microsoft 365 tenant. People without an account in it, guests, and conversations held in other apps are outside it.
Retention in Microsoft 365 is managed through Microsoft Purview data lifecycle management. Microsoft's own summary, on its page for administrators on managing retention policies for Microsoft Teams, is that retention settings can "keep data needed to comply with your organization's internal policies, industry regulations, or legal requirements" and "delete data that's considered a liability, that you're no longer required to keep, or that has no legal or business value." Teams supports retention policies for chat and channel messages "so that as an admin, you can decide proactively whether to retain this data, delete it, or retain it for a specific period of time and then delete it."
When you create a retention policy for Teams, a few rules shape everything else:
- Two locations. When you configure a retention policy for Teams, Teams chats (one-to-one, group and meeting chats) and Teams channel messages are separate locations, and each can have its own settings. Teams chats and channel messages are not covered by a policy set for Exchange mailboxes, even though that is where the retained copies are stored.
- Policies, not labels. Microsoft states that "Retention labels aren't supported for Teams", so everything is done by policy at the level of the location, the user or the team, not message by message.
- The clock starts at creation. "The start of the retention period for these actions is always based on when a message is created."
- Scope. A policy can apply to the whole organisation or to specific users (for chats) and specific teams (for channel messages).
- Licensing. Users who are subject to a Teams retention policy "must have an appropriate license, such as Office 365 E3 or Office 365 A3". Check Microsoft 365 licensing guidance for your own plan before relying on it, including education and charity plans.
What a Teams retention policy includes, and what needs its own policy
Microsoft's page Learn about retention for Teams is precise about what is in scope, and it is worth reading before anyone promises that "everything in Teams is kept".
- Included: the text of chat messages, channel messages and private channel messages, and with them video clips, embedded images, tables, hypertext links, links to other Teams messages and files, and card content. Chat messages include the names of everyone in the conversation; channel messages include the team name and the message title.
- Not retained: "Code snippets, recorded voice memos from the Teams mobile client, thumbnails, announcement images, and reactions from others in the form of emoticons aren't retained when you use retention policies for Teams messages." A voice memo from a phone is the item most likely to matter in a school or care setting.
- Files and emails are separate. "Emails and files that you use with Teams aren't included in retention policies for Teams." A file shared in a channel lives in SharePoint and needs a policy for Microsoft 365 group or SharePoint sites; a file shared in a chat, and a meeting recording or transcript from a chat, lives in the organiser's OneDrive and needs a policy for OneDrive accounts.
- Shared and private channels. Shared channels inherit the parent team's retention settings. Microsoft began moving private channel messages into group mailboxes towards the end of 2025; after the move the Teams channel messages location applies to them too; if private channels need different settings, Microsoft says to create a separate policy for their parent teams.
- Call logs. "By default, Teams call logs are retained indefinitely." A retention policy for call logs can only delete them. Call logs are records of calls, not recordings of what was said.
The practical consequence is that a set of Teams retention policies is usually three or four policies, not one: chats, channel messages, the SharePoint sites and group mailboxes behind teams, and OneDrive accounts. A policy on chats alone keeps the conversation and loses the attachment.
How retention and deletion actually run behind the Teams app
Teams stores messages in its own chat service and copies them into hidden folders in Exchange Online mailboxes for compliance: a folder in each participant's mailbox for chats, and one in the team's group mailbox for channel messages. Those folders are not for users or administrators to open; they are what eDiscovery searches. This has consequences that surprise people on both sides.
- A deleted message can still be retained. Under a policy that retains, users can still edit or delete messages in the Teams app, and a chat or channel message deleted within the retention period is not gone. The original is copied or moved to a hidden folder called SubstrateHolds and stays searchable by eDiscovery until the end of the retention period. When a user deletes a message it disappears from the app at once but, Microsoft notes, "doesn't go into the SubstrateHolds folder for 21 days".
- Deletion is not instant. An Exchange timer job runs typically every one to seven days. When a message reaches the end of the retention period it is moved to SubstrateHolds, stays there at least a day and is permanently deleted on a later run. Microsoft's worked example shows that a policy set to delete after one day "could take 16 days before the message is permanently deleted", and messages can remain visible in the Teams app for up to seven days after the period expires.
- What people see is not the record. Microsoft is explicit: "Messages visible in the Teams app are not an accurate reflection of whether they're retained or permanently deleted for compliance requirements." Check with eDiscovery, not by scrolling.
- Users are told when messages go. In chats, users see "We've deleted older messages due to your org's retention policy"; in channels, "This message has been deleted because of a Retention Policy" replaces the parent message. The wording is not configurable, and Microsoft advises organisations to tell users and the help desk what their settings will do.
- Retention beats deletion. Under the principles of retention, if one policy retains and another deletes, the message is kept; if two retain for different periods, the longest wins. An eDiscovery hold, or a Litigation Hold on the mailbox, suspends permanent deletion until it is released.
- Leavers. If a member of staff leaves and their account is deleted while a retention policy covers them, their chat messages are kept in an inactive mailbox, still subject to the policy and available to eDiscovery.
Choosing the retention periods
Microsoft provides the mechanism; the periods are the organisation's decision, and they belong in its retention schedule rather than in an administrator's head. Microsoft observes that, in many cases, "organizations consider private chat data as more of a liability than channel messages", and suggests separate policies for chats and channels, or different periods for different teams. For a school, charity or care provider, the questions that decide the periods are these:
- What records are made in chat? If safeguarding concerns, decisions about residents or trustee decisions are ever discussed in Teams, those messages are part of records with long retention periods, and a short delete-only policy on chats would destroy them. The better answer is usually to move the record into the proper file and keep the chat period modest, but only once that habit is real.
- What does the sector schedule say? Schools commonly use the IRMS toolkit and the Department for Education's record keeping and management guidance; care providers often adopt the NHS Records Management Code of Practice; charities set their own, and our data retention policy guide covers how.
- What does storage limitation require? UK GDPR Article 5(1)(e) says personal data must be kept "for no longer than is necessary". Keeping every Teams chat forever is a decision too, and not usually a defensible one.
- How will you answer requests? A subject access request or a Freedom of Information request is searched with eDiscovery across the retained copies. Retention that is shorter than the time requests commonly take to arrive means the record is gone before anyone asks; a hold must be applied as soon as a request or claim is live.
- Does the policy need locking? Preservation Lock stops anyone, including administrators, from turning off or weakening a policy. Once applied it cannot be turned off, so use it deliberately.
Teams chats, all staff: retain for 2 years from creation, then delete · Teams channel messages, safeguarding and senior leadership teams: retain for 7 years, then delete · Channel messages, all other teams: retain for 3 years, then delete · SharePoint and group sites behind teams: per the document retention schedule · OneDrive accounts: retain for 2 years, then delete; leavers' accounts reviewed · Call logs: delete after 1 year · Holds: data protection lead applies an eDiscovery hold on receipt of a subject access request, complaint or claim · Users told: in the staff privacy notice and the staff messaging policy.
The periods here are illustrations, not recommendations. The point is that every location is named, each has a period and a reason, and someone owns the holds.

What a Teams retention policy cannot reach
A retention policy governs content in your tenant, for users in your tenant. Microsoft's documentation is clear about the edges, and they matter more in schools, charities and care than in most offices, because so many of the people these organisations talk to are not staff with a licence.
- Guests. If an external person joins using a guest account in your tenant, messages are stored in your users' mailboxes and in a shadow mailbox for the guest, but "retention policies aren't supported for shadow mailboxes". Your users' copies are governed; the guest's are not.
- People in another organisation. If someone joins from another Microsoft 365 organisation, their copies sit in their own tenant, and your policies cannot delete them.
- People with no account at all. Parents, families, many volunteers, bank and agency staff and the people a care service supports usually have no account in your tenant and no licence. They cannot be in a Teams chat unless you give them access, and a Teams retention policy only covers the users it applies to.
- Conversations in other apps. A staff group on a consumer messaging app, a text message to a parent, a call from a personal mobile: none of these reaches Microsoft 365, and no retention setting can reach them. The ICO's guidance on non-corporate communications channels asks public authorities, including schools, to use corporate channels for official business and, where that is not possible, to store the information on corporate systems "as quickly as possible".
- Items the policy excludes. Voice memos from the mobile app, reactions and the other exclusions above, and files unless the right OneDrive, SharePoint or group policies exist.
None of this is a flaw in Microsoft 365. Teams is designed for an organisation's own people with its own accounts, and within that design the retention model is thorough. The gap is that the work of a school, a charity or a care service is not confined to its own people.
The conversations that never enter the tenant
Ask a care manager where the last difficult conversation about a resident happened and it is rarely a Teams chat. The office staff have licences; the night carers, the bank staff and the resident's daughter do not. The fall was reported in a group on personal phones, the daughter's worry arrived as a text, and the retention policy the administrator carefully configured covers none of it. Schools have the same shape with parents and supply staff, and charities with volunteers.
The retention schedule says how long those records should be kept. The retention policy can only keep what reaches the tenant. The gap between the two is the conversations that decide things about the people the organisation is responsible for.
ComplyChat is built to bring those conversations into the organisation's own record without giving everyone a Microsoft 365 licence. A mobile number verified by SMS is an identity, so a volunteer, a bank carer or a parent can be in a channel without an account on your systems. Messages are recorded on the server as they are sent, and everyone added to a channel is told it is on the record and can object or leave. On paid plans the lasting record files into your own Microsoft 365 once your tenant is connected, under your own retention rules. It lands in a restricted SharePoint document library, which your Teams chat and channel retention policies do not reach, so your schedule governs it through a Microsoft Purview retention policy applied to that archive. If everyone who needs to be in the conversation already has a licensed account, Teams with a sound retention policy is the answer and you do not need us. ComplyChat Free is one private group, direct messages, up to 25 staff and three calendar months of recent history, with no Microsoft 365 archive, so it cannot meet a retention duty.
A question for the next leadership meeting: for each group of people your organisation talks to about the people in its care, staff, volunteers, bank workers, families, which of them are covered by your Teams retention policy, and where do the conversations with the rest go?
Official guidance and your next step
Microsoft documents the model in three places: Manage retention policies for Microsoft Teams for administrators, Learn about retention for Teams for the detail of what is kept and when it is deleted, and Learn about retention policies and retention labels for the principles that apply across Microsoft 365. Microsoft updates these pages often; quotations here are from them as published on 25 September 2026. For the data protection side, read the ICO's guidance on storage limitation, and note that the Data (Use and Access) Act 2025 has amended UK GDPR and the Data Protection Act 2018, and its last data protection provisions came into force on 19 June 2026, so check the date on any ICO page you rely on.
This guide explains how Microsoft's retention features work as documented; it is not legal advice and not a configuration guide for your tenant.
One step to take this week: ask whoever administers your Microsoft 365 for a list of every retention policy that covers Teams chats, Teams channel messages, SharePoint and OneDrive, with its period, its action and any users or teams excluded. If the list is empty, Teams is keeping or losing messages by default rather than by decision.
The lasting record of a ComplyChat channel files into the customer's own Microsoft 365, so the retention model in this guide is the one a ComplyChat customer's archive lives under. We want the people who set those policies to understand them well, and to see clearly which conversations they can and cannot reach.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Managing retention policies for Microsoft Teams learn.microsoft.com
- Learn about retention for Teams learn.microsoft.com
- Record keeping and management guidance gov.uk
- Non-corporate communications channels ico.org.uk
- Learn about retention policies and retention labels learn.microsoft.com
- Storage limitation ico.org.uk


