KavachIQ/Recovery scenarios/Bulk mailbox deletion and retention drift
Illustrative recovery scenario

Recovery scenario: bulk mailbox deletion and retention drift in Microsoft 365.

See how KavachIQ helps a Microsoft 365 team recover mailboxes that are beyond the native recovery window, restore the correct retention posture, and produce evidence for compliance review after a high-volume deletion event.

This page describes an illustrative scenario. It is not a customer testimonial and does not contain fabricated metrics. It is intended to help Microsoft 365 teams, IT and security leaders, and procurement reviewers understand KavachIQ in the context of a realistic Exchange-heavy incident.

Related: compromised Global Admin · destructive deletion across SharePoint and OneDrive

SECTION 1 · INCIDENT SETUP

What the incident looks like in Microsoft 365

A large batch of mailboxes is removed in a short window. Retention policies and labels have drifted around the same time. Some mailboxes are already beyond the native recovery window. Compliance and legal need answers before the team can close the incident.

Bulk mailbox deletion

A large batch of mailboxes is removed in a short window. A scripted offboarding, a mistaken admin action, or an abused privileged session all produce the same pattern.

Calendar and contacts loss

Mailbox deletion also removes the calendar and contacts for every affected user. Meeting history and shared calendars surface the issue quickly.

Retention policy drift

Retention tags, retention labels, and retention policies were modified around the same time. What is still recoverable via native tools is now uncertain.

Native recovery windows

Deleted mailboxes enter the 30-day soft-delete window. Some are already beyond that window or have been explicitly purged. Native recovery for those cases is limited or unavailable.

Legal hold uncertainty

Mailboxes under legal hold or litigation hold may be partially preserved, but the team has to confirm hold state per mailbox before any restore action.

Cause is unclear at first

Script? Admin error? Compromised identity? Recovery has to move forward while the cause is investigated, without restoring unsafely.

SECTION 2 · WHY MANUAL RECOVERY IS HARD

Where teams run into trouble

Some of this work is possible with native tools and PowerShell. What makes it painful at scale is the combination of tight recovery windows, retention ambiguity, and compliance expectations.

01

Recovery windows are tight. Microsoft 365 soft-delete for mailboxes is 30 days by default, and purged mailboxes are not recoverable through native tools.

02

Retention drift makes the surviving state ambiguous. Which retention labels and policies were active at the time of deletion is not trivial to reconstruct.

03

Soft-delete, hard-delete, and purge are easy to confuse. Admins spend time in PowerShell validating state per mailbox before they can decide on a restore path.

04

Restore is fragmented. Mailbox-by-mailbox restore via native tools or PowerShell scripts is slow and hard to prioritize when hundreds of mailboxes are affected.

05

Compliance review runs in parallel. Legal and compliance need evidence of what was deleted, when, by whom, and what was restored, before sign-off.

SECTION 3 · HOW KAVACHIQ HANDLES RECOVERY

Six phases, applied to this incident

KavachIQ runs the same six-phase workflow on every recovery. Applied to a bulk mailbox deletion and retention-drift event, this is what each phase does.

PHASE 01Protect

Exchange Online state is already captured on a schedule.

  • Mailboxes, calendars, and contacts snapshotted with per-tenant encryption. Snapshots are WORM-locked for the SLA retention window.
  • Retention policy state (tags, labels, policies) is captured alongside mailbox data so the control plane context is preserved.
  • Identity and Entra ID state are snapshotted in parallel, in case the incident correlates with an admin or policy change.
PHASE 02Monitor

Baselines track normal mailbox and retention activity per tenant.

  • Mailbox count, deletion rate, and purge rate are baselined over rolling windows.
  • Retention tag, label, and policy counts are tracked. Large shifts in retention configuration are surfaced.
  • Correlated identity signals (recent privilege changes, new service principals) feed into the change picture.
PHASE 03Detect

Bulk deletion and retention drift are flagged with evidence.

  • Bulk mailbox deletion that exceeds baseline produces a specific, evidence-backed alert with the affected user list and the time window.
  • Retention policy or retention label changes are reported as part of the same incident, not as a separate noise source.
  • If the event correlates with a suspicious identity change, KavachIQ links the two so the team sees the full picture.
PHASE 04Assess

Blast radius is computed across mailboxes, retention state, and hold status.

  • Diff the current Exchange state against the last known-good snapshot. See which mailboxes are missing, which are soft-deleted, and which are beyond the native recovery window.
  • Compare retention tags, labels, and policies before and after. Surface any drift that needs to be reverted alongside the mailbox restore.
  • Confirm legal-hold and litigation-hold state per mailbox before planning restore actions. Hold-bearing mailboxes require a different restore path.
PHASE 05Recover

Guided mailbox restore in a business-safe order.

  • Restore identity controls first if any admin or policy drift is detected alongside the deletions.
  • Recover mailboxes for critical users first. Executives, compliance officers, legal, and finance come back before broader mailbox restore.
  • Restore retention tags, labels, and policies to the known-good state so restored mailboxes land under the correct retention posture.
  • Recover broader mailbox population after priority users are verified. Calendar and contacts are restored alongside mailbox content.
PHASE 06Verify

Mailbox recovery is confirmed with evidence.

  • Checksum validation confirms restored mailbox content matches the protected snapshot.
  • Sign-in and mailbox access checks verify users can open their mailbox, calendar, and contacts cleanly.
  • Retention policies and holds are confirmed active on the restored mailboxes. A recovery report bundles the timeline, actions taken, and snapshots used.
SECTION 4 · RECOVERY ORDER

Business-safe restore order for this incident

Identity-first thinking still applies. Confirm the control plane is trustworthy, then recover mailboxes in the order that restores business continuity fastest and that supports compliance review.

  1. 01

    Confirm identity and admin integrity

    If any admin, role, or policy drift is detected alongside the mailbox deletions, restore Entra controls first. Do not restore mailbox content into a tenant whose control plane is still in question.

  2. 02

    Critical mailboxes first

    Executives, compliance officers, legal, finance, and incident-response mailboxes are restored first. Calendar and contacts are restored alongside mailbox content so priority users can return to normal operations.

  3. 03

    Retention posture, before broader restore

    Retention tags, labels, and policies are reverted to the known-good state. Legal holds and litigation holds are confirmed active before the broader mailbox restore runs.

  4. 04

    Broader mailbox restore, verified end-to-end

    Remaining mailboxes are restored with checksum and sign-in verification. A recovery report documents what was deleted, when, by whom, and what was restored, for compliance review.

SECTION 5 · OPERATIONAL OUTCOMES

What changes for the team

KavachIQ does not prevent every mailbox deletion or retention change. It changes how a Microsoft 365 team runs the recovery, and how defensibly compliance can sign off on being back online.

Recovery past native windows

Mailboxes purged or past the 30-day soft-delete window are recoverable from KavachIQ snapshots, not dependent on Microsoft 365 native recovery timelines.

Clear retention state, before and after

Retention tag, label, and policy state is visible per mailbox before deletion and after restore. Drift is addressed explicitly, not assumed to be intact.

Prioritized mailbox restore

Critical users come back first. Legal, compliance, finance, and executive mailboxes are verified before broader mailbox restore runs.

Reduced PowerShell burden

Coordinated, guided restore replaces cycles of mailbox-by-mailbox PowerShell scripts and admin-center clicks.

Evidence for compliance review

A timestamped log of detected deletions, policy changes, decisions, and restore actions supports legal and compliance review after the incident.

Talk through your Microsoft 365 recovery scenario

Walk the bulk mailbox deletion scenario, or your specific incident, with a KavachIQ recovery engineer. Bring the mailbox, retention, and compliance questions that matter for your tenant.

© 2026 KavachIQ. All rights reserved.