Tag Archives: e-discovery

True Index-in-Place Capability for Global Enterprise eDiscovery and Information Governance Only Possible with Distributed Micro-Indexing Architecture

By John Patzakis and Chas Meier

As legal and compliance teams grapple with exponential data growth, the need for faster, more efficient eDiscovery has never been greater. One key trend emerging from the 2025 State of Industry Report by eDiscovery Today is the growing demand for in-place indexing, with 15.5% of respondents citing it as a critical priority. But achieving true ‘index-in-place’ without bulk data transfers or excessive infrastructure costs—requires a fundamentally different architecture: distributed micro-indexing.

Unlike traditional eDiscovery tools that rely on centralized crawling and bulk data transfers, X1 Enterprise’s distributed micro-indexing architecture allows organizations to search, analyze, and collect data directly at the source—without moving vast amounts of information to a separate processing environment. This means faster insights, lower costs, and reduced security risks.

However, with this capability being highly valued, many vendors have parroted this messaging but have offerings that do not qualify as true index-in-place. Unlike traditional enterprise search or eDiscovery platforms that rely on centralized indexing (e.g., crawling, copying, and transferring all the data into a single repository), X1’s micro-indexing distributes the workload. It creates small, efficient indexes at the data source—whether a user’s laptop, email server, or a cloud source such as Microsoft 365 —and unifies search results on-demand. Transferring data in bulk to a central appliance or server farm via a crawling agent or Robocopy function does not qualify. A true index-in-place using distributed micro-indexes uniquely enables scalability, targeted collection and minimizes security and data governance risks in eDiscovery and information governance matters.

Earlier this year, a Fortune 500 company faced a massive eDiscovery and GDPR compliance challenge: indexing and searching over 70 terabytes of data across Microsoft 365 and on-premises sources—all without disrupting operations. With X1 Enterprise, they accomplished this in just a few weeks—a feat impossible with traditional solutions that rely on slow, centralized processing.

X1’s unique approach is based upon distributed, micro-indexing search and collection capabilities. Below are the top ten benefits of this architecture tailored to eDiscovery and enterprise data governance and how it differs from alternative approaches.

  1. Rapid, In-Place Data Identification: Legal teams can locate relevant documents across endpoints, cloud sources, and network drives instantly—without waiting for slow, centralized crawls. X1’s micro-indexing creates lightweight, decentralized indexes at the endpoint level (e.g., individual laptops, servers, or cloud accounts).
  2. Real-Time Search Across Distributed Systems: Execute complex, Boolean-rich searches across terabytes of data in Microsoft 365, OneDrive, SharePoint, and beyond. X1 enables real-time, federated searches across up to hundreds of terabytes of multiple data sources (e.g., Microsoft 365, local drives, email archives) from a single interface, leveraging micro-indexes updated at the source.
  3. Minimized Over-Collection Risks: X1’s Micro-indexing allows precise targeting of relevant data, minimizing the need to collect entire datasets for review. X1’s granular indexing supports instantaneous keyword searches and metadata filtering at the source.
  4. Lower eDiscovery Costs: By eliminating the need to transfer and reprocess massive datasets, X1 slashes infrastructure and vendor fees. By indexing and searching data in-place (without moving it to a central repository), X1 nearly eliminates reliance on third-party processing tools and expensive manual services, with dramatically reduced time to review.
  5. Optimized M365 eDiscovery Support: Avoids Microsoft Purview throttling, supports modern attachments, and enables cost-effective, high-speed data access. Each custodian is assigned an individual micro-index which enables X1 to achieve unmatched throughput, support modern attachments without premium licensing, address inactive mailboxes and more.
  6. Massive Scalability: X1’s micro-indexing distributes the workload on a parallelized basis, allowing the index and searching of hundreds of terabytes of data in-place at speeds not seen before in the enterprise eDiscovery and information governance industry. Micro-indexes are updated incrementally and in real-time as new data comes in, rather than requiring batch copying and re-indexing of an entire corpus.
  7. Support for Remote and Hybrid Workforces: X1’s endpoint indexing works seamlessly on distributed devices, ensuring data from remote employees or cloud platforms is readily accessible without requiring physical access.
  8. Proactive Compliance & Risk Monitoring: Instantly identify PII, unencrypted sensitive files, and policy violations across the enterprise. With micro-indexes updated in real-time, X1 allows organizations to monitor for policy violations (e.g., PII exposure, unencrypted sensitive files) across endpoints, fileshares and M365 accounts instantly.
  9. In-Place Remediation and Governance: As the data remains in place, remediation is effectively and accurately applied at scale. This contrasts to other “copy and move” processes that are merely working off-site with copies of your data, rendering effective remediation efforts extremely costly and burdensome, if not impossible.
  10. Data Minimization and GDPR Compliance: X1’s capabilities directly map to the GDPR’s proportionality and data minimization requirements. In contrast, tools that require full disc imaging or bulk copy and transfer for basic eDiscovery collection are extremely problematic.

Conclusion
For legal, compliance, and IT teams struggling with slow, expensive, and inefficient eDiscovery workflows, distributed micro-indexing is the future. X1 Enterprise’s unique in-place search ensures rapid results, reduced costs, and ironclad compliance—without moving or duplicating sensitive data. If your organization relies on Microsoft 365, remote workforces, or high-volume data environments, X1 provides the speed, scalability, and security you need.

Ready to Learn More?
Discover how X1 Enterprise can revolutionize your eDiscovery and compliance strategy. Schedule a demo today at sales@x1.com or visit www.x1.com/solutions/x1-enterprise-platform.

Leave a comment

Filed under Best Practices, Case Study, Cloud Data, Corporations, Data Audit, eDiscovery, eDiscovery & Compliance, Enterprise eDiscovery, Information Governance, Preservation & Collection

Inactive Mailboxes, Unlocked: How X1 Enterprise Transforms M365 Data Discovery and Compliance

By Chas Meier and John Patzakis

In today’s compliance-driven environment, organizations must retain, discover, and manage large volumes of email data—even when the employees who once owned that data have long since departed. In Microsoft 365 (M365), this is managed through the concept of “inactive mailboxes.” An inactive mailbox is a mailbox that remains accessible for legal, regulatory, or compliance reasons, but no longer corresponds to an active user. While these preserved data stores are critical for eDiscovery, compliance, and investigations, they can pose significant challenges when it comes to efficiently locating, searching, and collecting the information they contain.

Fortunately, the latest innovations from X1 Enterprise are transforming how organizations handle these inactive mailboxes, making it easier and more streamlined than ever to discover and collect critical information—no matter where it resides.

What Are Inactive Mailboxes in M365?
Inactive mailboxes are mailboxes retained after a user leaves an organization, even after their license is removed. By placing a mailbox on legal hold or under a retention policy before deprovisioning the user, you can preserve it indefinitely without incurring licensing costs. This ensures the data remains accessible for compliance and eDiscovery. Best practices include applying holds before removing accounts, treating inactive mailboxes as part of ongoing governance efforts, and lifting holds once no longer needed.

The Process of Searching Inactive Mailboxes in Purview
In Microsoft Purview (the compliance and security center for Microsoft 365), users granted the eDiscovery manager role and each provisioned with an E5 license can search across both active and inactive mailboxes to fulfill legal or regulatory requirements. Generally, the process involves:

  1. Identifying the Inactive Mailboxes: Administrators must first know which mailboxes are inactive. Inactive mailboxes do not appear in the standard active user lists and often require additional steps to locate—either through the Purview interface, the Microsoft 365 admin center, or by running PowerShell scripts.
  2. Setting Up Permissions and Scope: The person performing the search needs appropriate eDiscovery roles in Purview. Once permissions are granted, they create a new content search or eDiscovery case and include the specific inactive mailboxes in the scope.
  3. Applying Search Criteria: Administrators can filter the search by date, keywords, sender/recipient, or other criteria. After running the search, Purview indexes the content and returns results for review and export.

Why Users Find It Challenging
Users face significant challenges when searching inactive mailboxes due to limited visibility—these mailboxes do not appear with active ones, requiring extra effort to locate and include them. Additionally, complex eDiscovery and compliance roles can be difficult to manage, particularly in organizations with large teams or complicated approval processes. A lack of a unified interface means working across multiple portals, tools, or scripts, leading to a fragmented and easily mismanaged workflow. Finally, without an intuitive, consolidated process, adding inactive mailboxes into search scopes, running queries, and ensuring data completeness is time-consuming and more prone to errors.

As organizations scale and accumulate thousands of these mailboxes, these difficulties multiply. Managing a vast, growing inventory of inactive mailboxes transforms a cumbersome task into a formidable burden, slowing down investigations, audits, and regulatory responses, and increasing the risk of overlooking critical data.

Many organizations resort to re-hydrating inactive mailboxes by applying an active M365 license to each one (“throwing licensing”), copying all M365 mailboxes of departed employees in a separate non-Microsoft archive (“throwing archiving”), or bringing inactive mailboxes into the litigation workflow (“throwing services”) to address the problem when faced with eDiscovery requests. Each of these approaches is extremely expensive, burdensome, and fraught with risk.

Driving the Transformation of Inactive Mailboxes through New Capabilities
X1 Enterprise has long been a trusted solution for comprehensive and targeted search across M365 data sources, file servers, and endpoints. With the new release of X1 Enterprise version 5.3, X1 is taking an industry-leading step forward in how organizations manage and leverage their inactive mailboxes.

How X1 Enterprise Revolutionizes Inactive Mailbox Management:

  • Unified Discovery Experience: With X1 Enterprise 5.3, legal and compliance professionals can now select inactive mailboxes directly within the platform. Instead of treating inactive mailboxes as separate or isolated repositories, X1 provides a consistent, familiar interface—just like working with active mailboxes.
  • Centralized Indexing and Search: Once selected, inactive mailboxes can be staged, indexed, searched, and collected using the same intuitive workflows. This streamlines eDiscovery, ensures rapid insights, and reduces the administrative burden on IT and compliance teams.
  • Seamless Integration with Microsoft Purview: X1 Enterprise automatically discovers and presents your full list of inactive mailboxes stored in Microsoft Purview (formerly Office 365 Security & Compliance Center) using only a single E5 license. This direct integration ensures that all preserved mailboxes are readily visible and actionable.
  • Consistent Identification and Collection Workflows: By applying the same workflows to both active and inactive mailboxes, X1 Enterprise eliminates confusion and complexity. The result is a more efficient and effective approach to responding to legal requests, regulatory audits, and internal investigations.

Benefits of the New Approach:

  1. Faster Response Times: Legal and compliance teams can rapidly identify and collect relevant information from inactive mailboxes without reinventing the wheel for each scenario.
  2. Improved Efficiency: In-place indexing and targeted searching with X1 Enterprise reduces administrative overhead and streamlines processes without the need to “boil the ocean,” thereby vastly reducing licensing costs with no need for 3rd party services or archiving platforms.
  3. Reduced Risk: Consistent workflows lower the chance of missing critical data or mismanaging preserved mailboxes.
  4. Enhanced Transparency: Having a clear, uniform process for both active and inactive mailboxes bolsters your overall information governance framework.

In Conclusion: Embrace the Future of Inactive Mailbox Management
Inactive mailboxes are here to stay, as legal and regulatory requirements continue to mandate the preservation of key business communications. Instead of viewing these repositories as a burden, forward-thinking organizations can leverage advanced technologies like X1 Enterprise 5.3 to take control of their compliance landscape.

Ready to Learn More?
The X1 Enterprise Platform is available now from X1 and its global channel network in the cloud, on-premises, and with our services available on-demand. For a demonstration of the X1 Enterprise Platform, contact us at sales@x1.com. For more details on this innovative solution, please visit www.x1.com/solutions/x1-enterprise-platform.

Leave a comment

Filed under Best Practices, Cloud Data, Corporations, eDiscovery, eDiscovery & Compliance, Enterprise eDiscovery, ESI, Information Governance, Information Management, m365, Preservation & Collection

Microsoft 365 eDiscovery Throttling is Structural and Won’t Be Going Away

By Chas Meier

Users of Microsoft 365 for eDiscovery and Information Governance continue to encounter significant problems with low throughput and defensibility. Many customers report to us that Purview eDiscovery Premium’s documented limitations, including a 2GB per hour indexing limit, prevent them from using the platform to handle anything other than small matters. A routine eDiscovery matter involving one hundred custodians each with about 10GB of M365 data typically requires several weeks to complete with MS Purview Premium. This is a non-starter for legal teams who are up against pressing litigation timelines.

It is important to understand that because M365 is built on a large-scale multi-tenancy SaaS architecture, such challenges are a feature, not a bug of the system. Multi-tenancy is an architecture where shared computing resources are apportioned across large numbers of users. This architecture enables Microsoft to provide the service at a lower cost since computing services are shared.

However, multi-tenant architecture enables scale (in terms of multitudes of users) and efficiency through uniformity. These architectures are not designed for outlier workloads like eDiscovery that routinely require intensive surges in computing resources to collect, process and search terabytes of data. In fact, multi-tenancy cloud architects would identify eDiscovery workloads as a “noisy neighbor” that threatens the overall performance and user experience of the system, and thus must be managed through quality-of-service mechanisms like throttling and time-outs.

I think of multi-tenant architectures like the business model utilized by a gym. The gym has more and better equipment than I have at home, which is attractive so many will join through a membership. The gym has a fixed amount of square footage and equipment which is more than any individual needs and is sufficient to support those that show up, occasionally having to coordinate access to the equipment but manageable. However, what if a small group showed up at the gym every day for most of the day and hogged the equipment? What if more people showed up, became frustrated, and dissatisfied? Gym management would be forced to act to ensure fair access to the equipment.

Throughout my career as an eDiscovery service provider, we made large investments in infrastructure and capacity to the point of overkill to equip ourselves to service a client’s need to address high volumes of data in short timelines without impacting their business-as-usual activities. We were like the fire department for big unstructured data needs.

A huge differentiator in X1’s approach is to divide and conquer large scale projects by leveraging the cumulative power of a decentralized computing orchestrated through a unified management, search, and collection console. Think of this like deploying a fire suppression system proactively before the fire.

Last year, X1 introduced M365 data connectors into our X1 Enterprise platform to satisfy a critical need for enterprises to conduct cost-efficient yet highly scalable eDiscovery search and collection of M365 data. The response has been tremendous, with X1 seeing record demand in large part, due to the architectural limitations and deficiencies noted above.

X1 Enterprise Collect provides users the unique ability to index and search M365 data in-place and then collect in a targeted and iterative manner. This at speeds and throughput far exceeding other tools, including Microsoft Purview Premium. X1 achieves such scalability through a decentralized custodian-based approach that does not rely on the M365 or Purview search Index, which has known issues with the number of file types supported, consistency of search results, and throughput. X1’s approach enables a very scalable, defensible, and robust data collection at speeds far exceeding that of M365 Purview and other approaches.

For a demonstration of the X1 Enterprise Collect Platform, contact us at sales@x1.com. For more details on this innovative solution, please visit www.x1.com/solutions/x1-enterprise-platform.

Leave a comment

Filed under Best Practices, Cloud Data, Corporations, eDiscovery, eDiscovery & Compliance, Enterprise eDiscovery, ESI, Information Governance, Preservation & Collection

Index and Search In-Place Workflows Are Essential for Information Governance

By John Patzakis and Charles Meier

Information Governance

Accurate pre-collection data insight is a game-changing capability that enables organizations and their legal teams to determine the scope, volume, and content of electronic information before the very disruptive and expensive step of collecting the data. This insight is enabled through distributed index and search in-place technology.

A true distributed index and search in-place capability for unstructured data requires a software-based indexing technology be deployed directly onto fileservers, laptops, or in the cloud to address Microsoft 365 and other cloud-based data sources. This indexing occurs where the data sources reside without requiring a bulk transfer of the data to a central location. Once indexed, searches can be performed in seconds, supporting complex Boolean operators, metadata filters and regular expressions. Searches can be iterated and refined without limitation, which is critical for large data sets.

While our previous blog post addressed the critical importance of this capability in eDiscovery matters, it is equally essential in information governance projects such as PII audits, the purging of redundant, obsolete or trivial (ROT) data, and due diligence and data separation efforts in support of corporate mergers and acquisitions. Many X1 customers have recently employed our indexing in-place technology on such projects with remarkable success.

Incredibly, many of these customers also received alternative proposals that leverage traditional eDiscovery workflows presenting much higher estimated costs and much longer durations. Traditional eDiscovery workflows mandate broad and manual data collection, copying and migration efforts, large scale data processing, and loading the data into a different platform for review and analysis. There are three fundamental reasons why this “traditional approach” is fatally flawed for information governance projects.

  1. Prohibitive Cost and Risk. The data scope of information governance projects involves terabytes and sometimes petabytes of data. Mass collection, copying and migration of these data sets with manual hand-offs for later analysis in a centralized location is extremely expensive, disruptive, and time consuming. Also, mass duplication and egress of enterprise data under control to execute ROT, PII, data separation or other due diligence projects is completely antithetical to their very purpose.
  2. The “Now What?” Problem. Let’s assume an organization has decided to incur the enormous cost, disruption and risk associated with the mass copying, migration, and centralization of unstructured data, and after loading the data into a review process, a key subset of documents and emails are finally identified for purging or other remedial action. Now what? You are merely working with copies! The live “original” emails and documents are in M365, email accounts, file servers or on laptops. It is possible to manually retrace and remediate, but that process is expensive and disruptive.
  3. Instant Staleness. Finally, a mass copying and migration effort often requiring several weeks to complete, is immediately stale once eventually completed as the live data in its original location has inevitably changed.

X1 solves these challenges though our proprietary and patented distributed index and search in-place technology that enables scale by bringing true distributed indexing in-place to laptops, file shares, M365 and other cloud sources. X1 Enterprise Collect significantly streamlines information governance workflows by identifying and allowing for the remediation of targeted data in-place, thereby eliminating the need for expensive and cumbersome data duplication and migration.

For a demonstration of the X1 Enterprise Collect Platform, contact us at sales@x1.com. For more details on this innovative solution, please visit www.x1.com/x1-enterprise-collect-platform.

Leave a comment

Filed under Cloud Data, compliance, Corporations, eDiscovery, eDiscovery & Compliance, Enterprise eDiscovery, ESI, Information Governance, law firm, Preservation & Collection

Index-In-Place eDiscovery Tech is in High Demand, but Beware of False Vendor Claims

By John Patzakis

Proportionality-based eDiscovery is a goal that all in-house corporate legal teams want to attain. Under Federal Rule of Civil Procedure 26(b)(1), parties may discover any non-privileged material that is relevant to any party’s claim or defense and proportional to the needs of the case. However, most core eDiscovery costs (outside of attorney review) stem from over-collection of electronically stored information (ESI), and over-collection thwarts the ability to attain proportionality. Law firm Nelson Mullins notes that “over preservation tends to have its own costs relating to storage of large amounts of electronically stored information (ESI) and the resources needed to manage it; leads to increased downstream e-discovery costs associated with collection, processing, and review.”

This is why accurate pre-collection data insight is a game-changing capability that enables counsel to set reasonable discovery limits and ultimately process, host, review and produce much less ESI. Counsel can further use pre-collection proportionality analysis to gather key information, develop a litigation budget, and better manage litigation deadlines. Such insights can also foster cooperation by informing the parties early in the process about where relevant ESI is located, and what keywords and other search parameters can identify and pinpoint relevant ESI.

And the means to enable this capability is distributed index and search in-place technology. Indexing and search in-place in this context means that a software-based indexing technology is deployed directly onto fileservers, laptops, or in the cloud to address cloud-based data sources. This indexing occurs without a bulk transfer of the data to a central location. Once indexed, the searches are performed in a few seconds, with complex Boolean operators, metadata filters and regular expression searches. The searches can be iterated and repeated without limitation, which is critical for large data sets.

However, with this capability being highly valued, many vendors have parroted this messaging, but have offerings that do not qualify as true index-in-place. True distributed index-in-place means that the search indexes are forward-deployed, and are actually installed on the target laptop, Mac computer, fileserver or into the cloud near where the target cloud data sources exist. Transferring data in bulk to a central appliance or server farm via a collector agent or Robocopy function does not qualify. A true index-in-place capability uniquely enables scalability, targeted collection and also minimizes security and data governance risks in eDiscovery and information governance matters.

Conversely, a process requiring massive data copying, migration and centralization does not scale and creates significant data, governance and privacy issues by needlessly duplicating data. For instance, if a matter requires that 10 terabytes be scanned to determine if relevant ESI exists within that data corpus, and the eDiscovery collection platform being used has no index-in-place capability, then all 10 terabytes must be copied and transferred to the tool for indexing and analysis. These limitations stem from tool vendors simply utilizing open source indexing platforms like Lucene or Elastic Search that are not forward-deployable and must reside in centralized locations with a very large amount of computing resources to make them viable for the type of data and data volumes typically seen in discovery and information governance matters.

This is why X1 leverages proprietary and patented index and search technology that is readily forward deployable and thus can scale and allow true distributed indexing in-place. X1 Enterprise Collect significantly streamlines the eDiscovery workflow with integrated culling and deduplication, thereby eliminating the need for expensive and cumbersome ESI processing tools. That way, the ESI can be populated straight into Relativity from an X1 collection without multiple hand offs, extensive project management and inefficient data processing.

The ability to directly and transparently collect data from custodian laptops, desktops, Microsoft 365 and other cloud sources into a RelativityOne/Relativity workspace is a game-changer that enables attorneys to begin review in hours rather than weeks.

For a demonstration of the X1 Enterprise Collect Platform, contact us at sales@x1.com. For more details on this innovative solution, please visit www.x1.com/x1-enterprise-collect-platform.

Leave a comment

Filed under Best Practices, Cloud Data, Corporations, ECA, eDiscovery, Enterprise eDiscovery, ESI, law firm, Preservation & Collection, proportionality