A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Adaptive Protection in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Capability
Something that a person, organisation or system is able to do.
- Insider Risk Management
A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
- Risk
As ISO 31000 puts it, how uncertainty affects objectives; that effect can be good or bad.
- Microsoft Purview Data Loss Prevention
Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
Related terms
- Insider risk
Lets Conditional Access react to the risk level that Adaptive Protection in Microsoft Purview gives a user (minor, moderate or elevated), blocking them or asking for stronger controls.
- Insider risk level
Based on what Insider Risk Management sees a person do, or the alerts raised about them, Adaptive Protection rates them Minor, Moderate or Elevated. Policies for Conditional Access, DLP and data lifecycle management can then tighten controls for riskier people; this rating is separate from how severe an alert is.
- Past activity detection
The period before a triggering event whose activity Insider Risk Management still scores. Adaptive Protection has a separate setting of the same name, 7 days by default and adjustable from 5 to 30, used when assigning insider risk levels.
- Quick setup
Switches on Adaptive Protection in the quickest way, in up to 72 hours. Behind the scenes Purview creates default risk levels, a Data leaks insider risk policy, two simulated DLP policies, a lifecycle policy for data and a Conditional Access policy set to report only.
- Risk level
The low, medium or high value that Microsoft Entra ID Protection gives to show how likely it is that an account or a sign-in has been compromised; Conditional Access policies based on risk respond to it. Insider risk levels in Microsoft Purview Adaptive Protection (Elevated, Moderate, Minor) are a different scale.