eDiscovery Certification Council

FORMAT/STYLE

Virtual Instructor Led Training (VILT) or Instructor Led Training (ILT).

DURATION

3 days

INTENDED AUDIENCE

  • eDiscovery Analysts
  • eDiscovery Project managers
  • eDiscovery Consultants
  • eDiscovery Technicians/Specialists
  • Digital Investigators 
  • Project Administrators 
  • litigation support professionals
  • information managers
  • IT and computer forensic experts of all kinds
  • eDiscovery vendors employees

Prerequisite

The main requirement for participating in this training course is having a general knowledge of the eDiscovery concepts.

REGISTRATION

Visit: www.eDiscoveryCertificateCouncil.org/List ofTrainingProviders   

submit@ediscoverycertificationcouncil.org

Practical, hands-on training for technicians responsible for cloud evidence.

The Microsoft 365 & Cloud Data eDiscovery Specialist (MCDES) program is an advanced, practitioner-level course designed for technicians who work directly with Microsoft 365, Teams, SharePoint, OneDrive, Exchange, and modern cloud data sources. This course is built for professionals who are responsible for placing legal holds, running searches, exporting data, and ensuring that cloud-based evidence is collected correctly the first time—without breaking defensibility. 

Microsoft 365 & Cloud Data eDis…

MCDES is not a high-level overview. It is a hands-on, workflow-driven program that teaches you how cloud eDiscovery actually works in real matters—and how technician-level decisions can make or break a case.

Learning Outcomes

You’ll learn how to:

  • Identify where data actually lives across Microsoft 365 services
  • Place and manage defensible legal holds on custodians and locations
  • Execute accurate searches across Exchange, Teams, SharePoint, and OneDrive
  • Handle Teams chats, threaded conversations, and reactions correctly
  • Build review sets and prepare clean, review-ready exports
  • Document your work to support chain of custody and defensibility
  • Avoid common cloud-specific mistakes that lead to re-collections and challenges

Syllabus

Microsoft 365 & Cloud Data eDiscovery Specialist

Module 1 – Introduction to Cloud eDiscovery

  • Core eDiscovery processes
  • EDRM model stages
  • Key differences between on-premises and cloud eDiscovery
  • Main challenges in cloud-based discovery (volume, velocity, variety)
  • Basic legal and regulatory drivers for eDiscovery

Module 2 – Microsoft 365 eDiscovery Fundamentals

  • Microsoft 365 Compliance Center / Purview portal navigation
  • Content Search vs eDiscovery (Standard) vs eDiscovery (Premium)
  • Creating and managing eDiscovery cases
  • Types of legal holds and preservation notices
  • Basic search syntax and KQL queries

Module 3 – Identification & Collection in Microsoft 365

  • Data sources in Microsoft 365 (Exchange, SharePoint, OneDrive, Teams, etc.)
  • Custodian identification and management
  • Data mapping and location identification
  • In-place preservation / litigation hold application
  • Collection methods and export options from locations

Module 4 – Review, Tagging & Export Workflows

  • Review sets in eDiscovery (Premium)
  • Analytics features (near-duplicates, email threading, themes, relevance)
  • Tagging / labeling strategies (relevance, privilege, issue codes)
  • Redaction tools and privileged content handling
  • Export formats (PST, native, reports) and delivery options

Module 5 – Compliance, Security & Data Privacy

  • Microsoft Purview compliance features relevant to eDiscovery
  • Key data privacy regulations (GDPR, CCPA, HIPAA, LGPD)
  • Handling personally identifiable information (PII) and sensitive data types
  • Audit logging and activity monitoring in eDiscovery
  • Security controls and access permissions for eDiscovery cases

Module 6 – Cross-Platform eDiscovery & Multi-Cloud

  • eDiscovery challenges in hybrid and multi-cloud environments
  • Collecting from non-Microsoft platforms (Google Workspace, AWS S3, Box, etc.)
  • Third-party connectors and ingestion methods
  • Unified search across multiple cloud providers
  • Data migration and normalization issues in cross-platform discovery

Module 7 – Capstone Simulation & Assessment

  • End-to-end eDiscovery workflow (from identification to production)
  • Realistic case scenario decision-making
  • Prioritization of data sources and custodians
  • Privilege review and clawback procedures
  • Defensible collection and production documentation