How to run a content search query to find documents over 10 years old
Step by step guide to using Purview to run a query job to return matching items.
Let's say you have a retention policy that all files on a SharePoint site should not be kept for longer than 10 years. That is "today" minus 10 years based on last "Modified date". I.e. targeting files that have not been edited for over 10 years.
You could run a Power Automate flow to get this information, but if you are lacking the tools and know-how to create flows, you can also get this data from Purview using the content search function.
Go into the "eDiscovery" tab and click on "Content search"
Guide to using Content Search


Let's start by assuming you don't already have a search created, so let's create it by clicking on the "Create a search" button.
You can also see other searches that other users have carried out and their status, so make sure whatever you run here isn't confidential.


Select a suitable name for your search and also a description if necessary. Then click "Create".




From here, we need to select both a) a source of data that we want to search. b) condition that matches our criteria.
Adding sources
For this example, we will click the various items to make sure we pick up only this site collection, and only target files and not emails or people.
Scope items by - Choose all sources in the tenant
Locations to include - Choose site only in this case, and only do mailboxes if you have proper eDiscovery permissions. You will also see mailbox columns in the finishing template, and these can be largely ignored since they will be blank.
Search - Past in the site collection URL and click "Search". Then be sure to tick the returned site
Click "Save and Close"


Since we want documents that haven't been modified for the last 10 years, we write the KQL query like this.
LastModifiedTime<2016-06-22


Click on "Run Query" and then "Run Query" again on the next page.


Finally, we get the results. In this case I have nothing matching, but if you did, you can click "Export" and get the results exported to CSV format.
The content search function of Purview isn't only about getting information for retention policies, you can use the content search and KQL query to run searches based on keywords, authors/recipients, and a whole host of other variables.
Adjacent to this is the more powerful eDiscovery tool which is, in my opinion, much more powerful for running in-depth keyword or topic searches but is perhaps too powerful as this tool is capable to searching not only on files and emails, but also on Teams messages, chats, deleted items, secure emails, etc.
Typical search don't need that kind of power unless you operate as an auditor or investigator.
Ending thoughts
Work Save Pray
Guide to how to work, save and live for a better economic future
Go to
© 2026 Work Save Pray. Not affiliated with financial institutions, banks, job agencies nor life coaches.
Practical and honest advice for ordinary people
Contact: info@worksavepray.com
