By default, searches are performed in context of the user initiating the search. This is called User Context.
If a privacy officer is configured, it is also possible to execute searches on the whole tenant archive by requiring authorization to the privacy officer. This is called Global Context.
For more information about Privacy Officer you can refer to this page.
The OTP authentication code provided by the privacy officer enables full access global searching for 15 minutes to the user. Compliance is maintained by logging every action and search into the Audit Log. At the end of the 15 minutes the privacy officer will also receive a report with the list of all actions and searches done.
If no privacy officer is configured, the administrator can perform searches on the whole tenant archive without further authorization.