Exporting a Microsoft 365 mailbox to a PST file comes up constantly: someone leaves the company and you need to archive their mail, legal asks for a copy of a specific account, or a user just wants a local backup before a big change. There are two clean ways to do it, and picking the right one saves a lot of friction.
The admin route is Content Search in the compliance portal (part of eDiscovery), which exports a mailbox without the user’s password and scales to several mailboxes at once. The user route is Outlook’s built-in import/export, which is perfect when one person wants a copy of their own mail. This guide covers both, the permissions the admin method quietly requires, and the compliance points worth knowing before you start handing PSTs around.
Which method fits your situation
Decide this first — it determines everything that follows.
Content Search vs Outlook export
| Content Search (eDiscovery) | Admin-driven, no user password needed. Best for departed employees, legal/HR requests, multiple mailboxes, or capturing deleted/archived items. |
|---|---|
| Outlook import/export | User-driven, needs access to the signed-in profile. Best for a single user backing up their own mail before a migration or device change. |
The short version: if you’re an admin acting on someone else’s mailbox, use Content Search. If a user can open the mailbox themselves and just wants a copy, Outlook is faster and needs no special roles.
Method 1: Content Search export (the admin way)
This runs from the Microsoft Purview compliance portal and doesn’t require signing in as the user — which is exactly why it’s the standard for offboarding and legal requests.
Step 1: Get the right permissions
This is the step that blocks most people. Being a Global Administrator does not automatically give you eDiscovery rights.
Permissions you need first
- Membership in the eDiscovery Manager role group (Purview compliance portal)
- The Export role assigned (it's what lets you download results as PST)
- Access to the compliance portal at compliance.microsoft.com / purview.microsoft.com
- A supported setup for the eDiscovery Export Tool (the ClickOnce download tool)
To add yourself: in the compliance portal, go to Roles & scopes → Permissions → Microsoft Purview solutions → Roles, open eDiscovery Manager, and add your account. Confirm the Export role is included.
Step 2: Create and run a content search
- In the compliance portal, go to Content search (under eDiscovery or Solutions).
- Click New search and give it a name.
- Under Locations, choose Specific locations and add the user’s mailbox (you can add several).
- Add a query if you only want part of the mailbox (date range, keywords), or leave it blank to take everything.
- Save & run the search and wait for it to finish estimating results.
Step 3: Export the results to PST
- Open the completed search and choose Actions → Export results (or the Export tab).
- Pick the export options — include the Recoverable Items folder if you need deleted mail, and decide how items are organized (one PST per mailbox is the common choice).
- Start the export, then go to the Exports tab and open the export job.
- Copy the export key, click Download results, and let the eDiscovery Export Tool launch.
- Paste the export key, choose a download location, and download. The result is one or more PST files.
Method 2: Outlook import/export (the user way)
When a single user can sign into the mailbox and just wants a local copy, Outlook does this without any admin involvement.
- In the Outlook desktop client, go to File → Open & Export → Import/Export.
- Choose Export to a file, then Next.
- Select Outlook Data File (.pst), then Next.
- Pick the account or folder to export (select the top of the mailbox to take everything, and tick Include subfolders).
- Choose where to save the
.pst, set any duplicate-handling option, and click Finish. - Optionally set a password on the PST when prompted.
When to use each, in practice
A few concrete cases to make the choice obvious:
Pick the method by scenario
| Employee left, mailbox needs archiving | Content Search — no password, captures everything, works on inactive mailboxes. |
|---|---|
| Legal or HR asks for a date-bounded copy | Content Search — scope by date/keyword and export only the relevant mail. |
| User wants a backup before a new laptop | Outlook export — quick, self-service, no admin roles. |
| Several mailboxes at once | Content Search — add multiple locations to one search. |
| Capture deleted / archived items | Content Search — include Recoverable Items and the archive in the export options. |
Compliance and a few cautions
PST exports move mail outside Microsoft 365’s protections, so handle them with care.
- Treat exported PSTs as sensitive data. Once a PST is on a laptop or file share, it’s outside retention, DLP, and audit. Store it encrypted, restrict access, and delete it when it’s no longer needed.
- Preserve the mailbox before exporting a leaver. A deleted mailbox is retained for a period (commonly 30 days) and can be made an inactive mailbox with a hold to keep it indefinitely. Set the hold before removing the license so there’s still something to export.
- PST is a poor ongoing backup. PSTs corrupt, don’t scale, and aren’t centrally searchable. For routine protection, lean on retention policies, litigation hold, or a dedicated backup product rather than scheduled PST dumps.
- Log who exported what. For legal requests especially, record the search, the export, and who handled the file. eDiscovery activities are auditable — use that trail.
Wrapping up
Two methods, one decision: act as an admin on someone else’s mailbox with Content Search, or let a user copy their own mail with Outlook’s export. The admin route needs the eDiscovery Manager and Export roles before it’ll work, and the export tool is picky about browsers — sort both out before you start and the rest goes smoothly. Whatever you produce, remember a PST is a copy living outside Microsoft 365’s protections, so secure it and clean it up when you’re done.
If you’re exporting because someone left, pair this with recovering deleted emails in Exchange Online to make sure nothing important was purged first, and consider converting their account to a shared mailbox if the team still needs the address.