Digital Investigation with Microsoft Purview eDiscovery Premium
- Technical Administrator, Digital Forensics Expert
Training Overview
Learning Objectives
Trainees will be able to:
- Getting Started with eDiscovery Premium and Understanding EDRM
- Models Targeting Data and Key Individuals and Creating Data
- Collections Analyzing Data and Filtering Content Exporting Data and
- Ensuring Compliance in Investigations.
Understanding EDRM Models
- Discover the EDRM Model
- Know the Steps Supported by eDiscovery Premium
- Search, Audit, and Investigate Data
Getting Started with eDiscovery Premium
- Understand the Required Permissions in Microsoft Purview
- Access eDiscovery Premium
- Apply Global Settings
- Create a Case
- Close or Delete a Case
Managing an eDiscovery Premium Case
- Add Custodians, Data Sources, and Stakeholders to a Case
- Review Custodian Activities
- Communicate with Custodians
- Conduct Preliminary Queries
- Create, Configure, and Test a Data Collection
- Review Statistics to Decide Next Steps
- Modify and Regenerate Collection Configuration
- Validate the Collection
- Maintain and Review Collection History
Indexing and Processing Data
- Process and Index Data
- Operate on a Review Set
- Analyze Data in a Review Set
- Add External Data to a Review Set or Transfer Data Between Review Sets
- Review Content in a Review Set
- Filter Results by Query (and Save Queries)
- Classify/Tag Query Results
- Analyze Teams and Yammer Conversations
- Analyze and Cleanse Data
- Identify Data in a Review Set
- Build a Dashboard
- Detect Duplicates and Email Chains
- Machine Learning Analysis
- Review, Annotate, and Redact Content
- Tag Results in a Review Set
Filtering Results in a Review Set
- Filter and Query Results in a Review Set
Finalizing the Investigation and Producing a Report
- Compile a Report
- Select and Extract Relevant Information
- Provide a Summary of:
- Involved Parties
- Selected Data Sources for the Case
- Communications with Custodians
- Data Collections
- Export a Review Set
Published on 12/15/2023
In this training, we mix theory with technical workshops to quickly make you operational. Additionally, each participant receives course materials at the end of the training.
One of our consultant trainers conducts the training. With solid field experience, they make the learning process both interactive and enriching.
For assessment, the trainer regularly asks questions and uses various methods to continuously measure your progress. This approach promotes a dynamic and engaging learning experience.
After the training, we ask you to complete a satisfaction questionnaire. Your feedback helps us to maintain and constantly improve the quality of our training.
Finally, we offer the flexibility to deliver this training both in-person and remotely, and it can be customized to meet your company’s specific needs upon request.
To enroll in this training, it is essential to have a solid understanding of Microsoft 365 and its services or experience in conducting digital data investigations.
Familiarity with the KQL language is an advantage.
You can register for one of our training courses up to two business days before it starts, if there are still available places and you signed quote.
If you have specific needs related to a disability, please do not hesitate to make a request; we are happy to adjust our services according to the type of disability.
SC-5006 : Enhance security operations by using Microsoft Security Copilot
SC-5008: Configure and govern entitlement with Microsoft Entra ID
SC-100 : Microsoft Cybersecurity Architect

SC-300 : Microsoft identity and access administrator

SC-401 : Protect sensitive information with Microsoft Purview in the AI era

SC-200 : Microsoft Security Operations Analyst

SC-900 : Introduction to Microsoft Security, Compliance, and Identity
