Microsoft Teams meetings help our globally distributed and digitally connected employees create meaningful hybrid work experiences. When those meetings are recorded and transcribed, or their data becomes available to AI-powered digital assistants, their value extends far beyond the meeting itself.
Once captured, meeting data becomes a source of organizational knowledge that helps employees catch up on discussions, revisit decisions, track commitments, and surface unresolved issues. AI-powered experiences such as Microsoft 365 Copilot and Work IQ can connect insights across meetings, helping teams understand how conversations, decisions, and workstreams evolve over time and ensuring important information doesn’t get lost.
Although these features have proven to be incredibly useful to our employees and our wider organization, there are also concerns about how retaining Microsoft Teams meeting data and AI insights might affect our security posture, records retention policy, and privacy. Just like any other company, we at Microsoft must balance these different factors accordingly.
At Microsoft Digital, the company’s IT organization, we’re leading cross-disciplinary conversations on this topic to help ensure that we get it right.
The value of Teams meeting data
Within a meeting, the Microsoft 365 Copilot sidebar experience helps our late-joining employees catch up on what they’ve missed, provides intelligent prompts to review unresolved questions, summarizes key themes, and creates notes or action items.

“The value of a meeting should not end when the meeting ends. Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”
Chanda Jensen, senior product manager, Microsoft Digital
The benefits of AI in meetings extend beyond the live meeting experience as well. When meeting content is available after the meeting, AI can transform conversations into accessible organizational knowledge. Transcripts and underlying documentation—including, notes, decisions, and action items—enable participants to revisit discussions, catch up on missed meetings, verify decisions, and accelerate follow-up work.
Our Microsoft Teams meeting data retention efforts focus on three key categories of artifacts: Underlying documentations, transcripts, and the AI-generated artifacts that help power Microsoft 365 Copilot and Work IQ experiences.
Microsoft Teams meeting data and AI artifact retention
Meeting recordings
90-day Teams meeting expiration policy
- Cloud video recording
- Audio
- Screen-sharing activity
Transcripts
90-day Teams meeting expiration policy
- Transcript
- Captions
AI-generated meeting artifacts
90-day Teams meeting expiration policy
- Meeting summaries and intelligent recaps
- Notes, decisions, and action items
- Copilot interactions (queries and responses)
- Insights and organizational knowledge derived from meeting content
Transcription provides the underlying documentation that makes these AI-powered experiences possible. By making transcription and AI capabilities available in meetings while preserving organizer, administrative, compliance, and sensitivity controls, organizations can choose how these capabilities are used while enabling users to benefit from more effective collaboration and knowledge retention.
“The value of a meeting should not end when the meeting ends,” says Chanda Jensen, senior product manager in Microsoft Digital. “Transcription and AI help transform conversations into durable knowledge—making decisions easier to find, commitments easier to track, and information easier to access for everyone who needs it.”
Policy considerations for meeting data retention
The value of these tools is clear, but data-retention obligations also play an important compliance role that organizations like ours need to consider.

“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data. We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”
Rachael Heade, director of records compliance, Microsoft Corporate, External, and Legal Affairs (CELA)
First, producing and retaining this kind of data can be complex if it isn’t governed properly. For us at Microsoft, this data represents day-to-day general business practices that elevate productivity, and factors such as security and privacy must be considered when managing it. Second, data-rich artifacts like video recordings require a lot of space, quickly eating up cloud storage budgets.
“When individuals generate recordings or other artifacts during meetings, we tend to think of them as an individual’s data, but they actually represent the company’s data,” says Rachael Heade, director of records compliance in Microsoft’s legal division. “We want to empower individuals, but we have to remember the retention and volume impacts of these artifacts on the company can be substantial.”
In light of these potential impacts, some organizations simply opt out of enabling Microsoft Teams meeting recordings.
Asking the right questions to assemble the proper guardrails
Leaders in Microsoft Digital and Corporate, External, and Legal Affairs (CELA), our legal division, are working to balance the benefits of Microsoft Teams meeting data retention with our compliance obligations, aiming to provide empowering experiences for our employees while also keeping company data safe.
“Organizations are always concerned about centralized control over the retention and deletion of data artifacts,” Heade says. “You have excited employees who want to use this technology, so how do you set them up so they can use it confidently?”
Like many policy conversations, getting this right starts with the governance team in Microsoft Digital and our internal partners asking employees from across the company who are responsible for data governance the right questions:
- When should a meeting be recorded and when shouldn’t it?
- What kind of data gets stored?
- Who can initiate recording, and who can access it after the meeting?
- How long should we retain meeting data?
- Where does the data live while it’s retained?
- How can we control data capture and retention?
- What does this mean for eDiscovery management?
These questions help us think about the proper data-retention guardrails. Our IT perspective is only one part of the puzzle, so we’re actively consulting with CELA, corporate security, privacy, the Microsoft Teams product group, the company’s data custodians, and our business customers throughout this process.

“As an organization, this is about thinking through your tenant position and getting it to a reasonable state.”
David Johnson, tenant and compliance architect, Microsoft Digital
Our conversations have brought up distinctions that any organization should consider as they build policy around Microsoft Teams meeting retention:
- The length of time a meeting’s data remains fresh, relevant, or useful
- Consideration of the difference between AI-generated archival content versus the full meeting transcript
- The different risks inherent with recordings compared to transcriptions
- Establishing default policies while allowing limited variability and flexibility when employees require it
“As an organization, this is about thinking through your tenant position and getting it to a reasonable state,” says David Johnson, tenant and compliance architect in Microsoft Digital.
From sharing perspectives to crafting policy
Our policies around Microsoft Teams meeting data retention continue to evolve, but we’ve already implemented some highly effective practices, policies, and controls. Every organization’s situation is unique, so it’s important that you speak to your legal professionals to craft your own policies. But our work should give you an idea of what’s possible through the out-of-the-box features within Microsoft Teams.
The policies we’ve put in place represent a mix of technical defaults, meeting options, and empowering employees to make informed decisions about usefulness and privacy. They also build on the foundations of our work with sensitivity labeling, which helps secure data across our tenant.
Here are some of the practices we follow and features we use:
- Transcript attribution opt-out gives employees agency and reassures them that we honor their privacy.
- Recommending that employees “tell and confirm” before recording empowers and supports our people to speak up when they don’t believe the meeting should be recorded or don’t feel comfortable with this choice. Employees in the meeting can also stop the recording, if needed, or determine if automatic recording was set up but is not appropriate.
- Visual indicators that a meeting is being recorded and that transcription has started, allowing users to request that a meeting stop being recorded or to leave the call.
- User education, through an internal recording smart-use statement document, helps employees understand the implications of recording, when not to record, and when not to speak in a recorded call.
- We do not use compliance recording. While compliance recording could enforce full consent collection, unmuting themselves, we decided that opt-outs and user notices provided sufficient agency to our employees.
- We offer meeting labels that limit who can record, meaning only the organizer or co-organizer can initiate recordings for meetings labeled “highly confidential.”
- Meeting labels are informed by content shared within the meeting. If content is shared in the meeting that has a higher label than the meeting itself, the organizer is prompted to re-label it.
- Meeting labels are inherited and applied to all meeting artifacts, recordings, transcripts, and notes. This means that meeting knowledge remains protected, and any AI consumption of that recording will automatically inform the consumer of the sensitivity and required protections.
- Only meeting organizers can download meeting recordings, keeping the meeting data contained and restricting sharing.
- The default OneDrive and SharePoint meeting expiration is set to 90 days to ensure we minimize the risk of data leakage or cloud-storage bloat.
- The default Meeting AI Archive is set to an 18-month retention policy. That allows questions and decisions from the meeting to be leveraged by the team for post-meeting insights but ensures that data is not kept forever.
- Deletion is applied in a consistent manner under the business general categories of our retention schedule. The schedule supports our designation of the Teams artifacts as productivity tools and resources, but not as official company records. This stance controls data volume, reduces review and production burden, and ultimately reduces risk (including security and privacy factors).
Balancing productivity with sensible data governance
At Microsoft, we apply different retention periods to different types of meeting data, based on their purpose and business value. Full meeting recordings and transcripts are governed by a default 90-day expiration policy, helping reduce privacy, security, and storage risks while ensuring employees can still benefit from recordings in the near term.
“The bottom line is that we rely on our employees to be good stewards of the company. Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”
David Johnson, tenant and compliance architect, Microsoft Digital
Separately, AI-generated meeting knowledge—such as questions, decisions, and other insights extracted from meetings and used to support discovery and knowledge-sharing—can be retained for up to 18 months, allowing teams to benefit from the value of those insights long after the original transcript has expired.
These policies are designed to balance employee productivity with responsible data governance, ensuring that important information remains available when useful but is not retained indefinitely. They reflect the three core tenets we use to inform our governance efforts: empower, trust, and verify.
“The bottom line is that we rely on our employees to be good stewards of the company,” Johnson says. “Because we’ve got a good governance model in place for Teams and solid overall hygiene for our tenant, we’re well set up to deal with the evolution of the product and make these decisions.”
The net outcome of all of this work is that our organization is more confident in our approach to meeting knowledge, resulting in more meetings being recorded or transcribed and generating more valuable post-meeting artifacts.
We can’t specifically recommend that an organization follow our blueprint entirely, but asking questions similar to the ones we’ve outlined here can help you build a strong Teams data-governance foundation. With a firm grasp of the technology and close collaboration with key stakeholders, you can guide your own policy decisions and unlock more value for your employees.
Key takeaways
Here are some tips for approaching meeting data retention policies and practices at your company:
- Face your fears and get comfortable with being a little uncomfortable. First establish your concerns about Teams data retention, then work toward optimizing your policy compliance.
- Consider how to support your company’s compliance obligations while still allowing your employees to take advantage of the product’s data-retention features. Let those things live together side-by-side.
- Connecting with your legal team is essential, because they’re the experts on assessing complex compliance questions. Leveraging legal expertise not only drives clarity on complex compliance questions but also allows you to surface opportunities and constraints around how and when to use meeting data features specific to your business or industry.
- Investigate meeting labels and what policies you might want to apply to different meetings, based on sensitivity and other attributes.
- Engage your security team to discuss how labeling and post-meeting protections can address any company security concerns.
Try it out
Related links
- Learn how we’re transforming our approach to sensitivity labels at Microsoft with Microsoft Entra.
- Read about five ways we’re getting more out of Microsoft Teams in the era of AI and Copilot.
- Discover our guide to tackling Microsoft 365 Copilot governance internally.
- Check out our Microsoft Teams Premium overview for administrators.

