Legal Hold

Doug Chanin
Doug Chanin
  • Updated

Topic

This article describes the Legal Hold feature in NinjaOne SaaS Backup.

Environment

NinjaOne SaaS Backup End-User Portal

Description

Legal hold is a risk‑mitigation and compliance process used to preserve all potentially relevant data when a legal case, investigation, or audit is expected or underway. When a legal hold is applied, the affected data is retained indefinitely and overrides all existing retention policies, ensuring NinjaOne SaaS Backup will not allow data deletion while the hold remains active.

You can apply a legal hold at both the account and message levels. Account level applies to individual email accounts, departments, or all. The message level applies to saved search creation.

Legal hold is only available to organizations with an active Archiver subscription and to users with the Owner, Full administrator, Compliance and Review Officer, or Data Protection Officer roles.

Creating a Legal Hold

Legal holds can be created by content type (email or message) and by scope (single or in bulk). You can only create message-level legal holds for individual items. However, you can create account-level legal holds either individually or in bulk.

When creating an account-level legal hold, you can choose one of the following three options to determine where the hold will be applied:

  • Email Account:  You can specify one or multiple email accounts. You can add email accounts manually or import them in bulk using the provided CSV template.
  • Department: You can specify one or multiple departments.
    If you apply the hold at the department level, it will automatically apply to all email accounts within the selected departments.
  • All: The hold will apply to all email accounts in your organization.

Creating a message-level legal hold requires a saved search, as message-level legal holds apply only to individual items. 

Create an Account-Level Legal Hold for Email Accounts

NinjaOne SaaS Backup allows you to create multiple legal holds based on your organization's needs. Follow the steps below to create an account-level legal hold for email accounts.

  1. From the NinjaOne SaaS Backup End-user dashboard, navigate to Compliance Legal Hold.
  2. To create a legal hold for the account level, stay on the Account Level tab, then click + Create New
fig1.png
Figure 1: Legal Hold- Account Level (click to enlarge)
  1. The Create New Legal Hold dialog will appear. Enter a name for the legal hold in the provided field. We recommend using a meaningful name that reflects the purpose of the legal hold. This step can help you keep track of your legal holds when you have multiple instances to monitor.
The maximum number of characters allowed is 35, containing only letters and numbers. No special characters are allowed except the currency symbols and underscore. You cannot enter a name that already exists. 
  1. Select Email Account from the For drop-down menu. This field determines where the legal hold will be applied.
  2. In the email account selected box, select Manage.
fig2.png
Figure 2: Create New Legal Hold (click to enlarge)
  1. The Manage Email Accounts for Legal Hold dialog will appear. You can enter email addresses manually using the provided field, or download the linked CSV template to add multiple email accounts in bulk. If you are not adding accounts in bulk, you can proceed to step 10.
  2. Fill in the CSV file with the users' email addresses, then upload the completed file.

NinjaOne SaaS Backup will process and validate the email accounts in your CSV file. This process may take a few moments. 

fig3.png
Figure 3: Manage Email Accounts for Legal Hold (click to enlarge)
  1. Click Continue. NinjaOne SaaS Backup will redirect you to the Create New Legal Hold dialog, where you can see the total number of email accounts that you have added. 
  2. Check I agree with this Retention Policy Behavior to confirm that you agree to the retention policy behavior.
  3. Click Continue again to continue the validation of the added email addresses.
fig4.png
Figure 4: Create New Legal Hold (click to enlarge)

Once validation is complete, NinjaOne SaaS Backup will display which email addresses are valid and which are invalid. An email may be detected as invalid if:

  • The email format is incorrect. 
  • The system cannot find the email account in your organization. 
  1. Click Submit & Enable Hold to proceed.
fig5.png
Figure 5: Confirmation page (click to enlarge)

NinjaOne SaaS Backup will display the notification: Legal hold successfully created.

Important Notes

  • You will not be able to complete the creation or editing process of a legal hold if all added email accounts are invalid. 
  • The Already on Hold status message indicates that you, or the organization, have included the email account in other legal hold cases, but you can still add it to the current one. This message allows you to track custodians across multiple cases and prevents accidentally releasing preserved data when removing them from one hold while they remain subject to others.

Email Handling During Legal Hold

When you have a legal hold at the account or message level, NinjaOne SaaS Backup preserves the email, and no one can permanently delete it, even if you've applied a retention policy to the same email. An email or account is released from preservation only after you have removed all legal holds that apply to it. These rules also apply when multiple legal holds exist. Releasing one hold does not affect other active holds.

Editing a Legal Hold

From the dashboard, navigate to Compliance → Legal Hold.

  1. Click the actions menu on the Legal Hold card. Then select the Edit button.
  2. The Edit Legal Hold dialog will appear. You can update the legal hold name, recipients, and email addresses included in the legal hold.
  3. Check I agree with this Retention Policy Behavior to confirm that you agree to the retention policy behavior.
  4. Click Continue to display the Create New Legal Hold dialog, where you can see the total number of email accounts that you have added. 
  5. Select I agree with this Retention Policy Behavior to confirm that you agree to the retention policy behavior.
  6. Click Continue again to continue the validation of the added email addresses.

Once validation is complete, NinjaOne SaaS Backup will list which email addresses are valid and which are invalid. 

  1. Click Submit & Update Hold to proceed.

Deleting a Legal Hold

  1. From the dashboard, navigate to Compliance → Legal Hold.
  2. Click the More button (3 dots icon) on the Legal Hold card. Then select the "Delete" button.
  3. NinjaOne SaaS Backup will display a confirmation dialog. Click I Agree to proceed with deleting the legal hold.

NinjaOne SaaS Backup will display a success banner indicating it deleted the hold.

Frequently-Asked Questions (FAQ)

Below are some frequently asked questions with answers from our support team.

What is the maximum number of email accounts allowed in a legal hold?

A Legal Hold supports up to five hundred email accounts, whether added individually or via CSV import. The CSV upload file size is limited to 5 MB. NinjaOne SaaS Backup can process a maximum of five hundred accounts per legal hold instance. Should you need to preserve more accounts, you can create an additional legal hold instance to cover the rest.

What happens if I accidentally enter duplicate email addresses?

Our system counted duplicate emails as a single entry, so don't worry if you have many email lists and think they might be duplicates.

What will happen if I upload a file in the wrong format?

You can only upload CSV files. The system restricts uploads to the CSV format.

Can I upload the CSV document more than once?

Yes. You can upload a CSV file multiple times, but you can only upload one file at a time. You can remove the previously uploaded file and upload a new one; NinjaOne SaaS Backup will add the email accounts from the latest CSV file. Removing the uploaded file will not remove email accounts that NinjaOne SaaS Backup has already added.

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request