KQL Query for Content Search Recipients

Plan and manage eDiscovery and Content search
Answer Correct answer: B — Add Recipients: (“[email protected]” “[email protected]”) to filter emails for either recipient using implicit OR logic within parentheses.

You have a Microsoft 365 subscription. From Microsoft Purview, you plan to create a content search for email messages that have a recipient of either [email protected] or user2.contoso.com. You need to add a condition to the KQL editor for the content search. Which KQL query should you add as a condition?

  1. Recipients: “user””#1-2””@contoso.com”
  2. Recipients: (“[email protected]” “[email protected]”) Correct Answer
  3. Recipients: (“user””#1-1””@contoso.com”)
  4. Recipients= “[email protected]” OR Recipients= “[email protected]”

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of KQL field-value equality syntax and boolean logic, specifically distinguishing between standard SQL-style OR and KQL's specific requirement for parentheses around grouped conditions.

Determines the correct Kusto Query Language (KQL) syntax to filter email recipients in Microsoft Purview Content Search using logical operators.

Learners often select option D because it uses the 'OR' operator, failing to notice that KQL requires explicit grouping with parentheses for multiple values or complex boolean expressions involving the same field.

Community Discussion (5 comments)

thetootall 👍 1 Selected: D
Equals operator is "=" and OR operator is also correct for specifying 2 or more conditions
Sibimsh 👍 2 Selected: D
It's D
Amin4799 👍 1 Selected: D
you should use the OR operator.
SDiwan 👍 2 Selected: D
D, is correct equals operator is "=" and or operator is also correct.
mb0812 👍 1 Selected: D
D, others are wrong

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is the correct answer. In Microsoft Purview Content Search, the KQL editor requires strict syntax adherence. To search for multiple values in a single field like 'Recipients', you must group them within parentheses: (value1 value2). This tells the engine to match any item where the Recipients field contains either [email protected] OR [email protected]. The space inside the parentheses acts as an implicit OR.

Why the Other Options Are Wrong

Option D is incorrect because while it uses the 'OR' operator, KQL syntax for simple field matches does not typically use the '=' sign in this context, and more importantly, without parentheses enclosing the entire condition or proper tokenization, it can fail or be syntactically invalid depending on the parser version. However, the most critical error in D is often cited as the lack of parentheses for the grouped logic if interpreted as a complex expression, but primarily, Option B is the documented standard shorthand for multi-value searches. Option A and C contain nonsensical characters like '#1-2' which are not valid KQL wildcards or ranges for this purpose.

Community Comment Notes

The community overwhelmingly voted for D, arguing that the equals sign and OR operator are correct. As user SDiwan noted, "D, is correct equals operator is '=' and or operator is also correct." Another user, thetootall, stated, "Equals operator is '=' and OR operator is also correct for specifying 2 or more conditions." While intuitive for those coming from SQL backgrounds, this ignores the specific KQL implementation details in Purview where the parenthesized list is the preferred and robust method for multi-value matching in a single field.

Exam Strategy

Memorize the specific KQL syntax quirks for Microsoft Purview. For multi-value searches in a single field, always look for the parenthesized list format (val1 val2) rather than repeating the field name with OR operators, unless constructing a highly complex query.

Frequently Asked Questions

Why is the OR operator used differently here?

In KQL for Purview, listing values in parentheses (A B) implicitly means A OR B. Repeating the field with OR is less efficient and can sometimes cause syntax issues.

Can I use wildcards in the Recipients field?

Yes, but you must use standard wildcard syntax like *. The options provided with #1-2 are invalid KQL syntax.

Related Analysis

← Back to SC-400 Study Guide