Skip to main content

An Introduction to Managing Microsoft 365 Updates that Present Legal and Compliance Considerations

Increasingly, opportunities for cloud-based collaboration and efficiencies, and challenges presented by the rapid proliferation of complex data, are incentivizing organizations to transform their corporate data governance and ediscovery operations from traditional self-managed infrastructure to the Microsoft 365 (M365) Cloud. Benefits in terms of convenience, security, robust functionality, and native capabilities related to ediscovery and compliance are the primary drivers of this move.

A computer with Microsoft 365 pulled up on a web browser.

While there are many benefits to moving into the M365 ecosystem, it requires legal and compliance teams to take on new considerations regarding the constant evolution that characterizes cloud software. With continually changing applications, establishing static workflows for ediscovery, legal holds, data dispositions, and other legal operations is not enough. As the M365 software and functionality changes, workflows must be constantly evaluated to ensure their validity, relevance, and defensibility.

Exacerbating this challenge is the reality that the traditional IT change management paradigm designed to preemptively address cross-organizational considerations (including impacts to legal, compliance, and ediscovery operations) does not fit the Cloud/SaaS framework. Organizations must now rethink their change management approach as they modernize with M365.

This is the first in a series of blog posts devoted to highlighting key changes that have been released into the M365 production environments. One of the biggest challenges for organizations is identifying which of the myriad of updates pose potential risks to ediscovery operations. Distinguishing the changes that do and do not pose a significant ediscovery impact can be extremely difficult unless the reviewer has some level of subject-matter expertise and understands the specific workflows deployed within the organization. Here are some common scenarios with potential ediscovery impact that could easily go unnoticed by the untrained eye:

  • Updates that create a new data source
  • Updates that change a backend data storage location
  • Updates altering the risk profile of features that were previously disabled due to legal / privacy risk
  • Updates that render an existing ediscovery process obsolete

Each subsequent blog post in this series will highlight an example of a software update related to our key software scenarios, detailing the nature of the change, the potential impact, as well as when and why organizations should care.

To further discuss the above approach to monitoring and assessing changes, or to talk about specific Microsoft 365 updates that have occurred carrying potential ediscovery and compliance impacts, please get in touch with me at

About the Author

Jamie Collins is the product manager for Lighthouse CloudCompass, a program devoted to keeping customers up to date on impactful changes flowing through Microsoft 365. With over a decade of experience working inside large technology companies and over six years working on Lighthouse’s Advisory Services team, Jamie is passionate about the role of technology in the legal and ediscovery space.

Profile Photo of Jamie Collins