A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
Also called Microsoft Purview Insider Risk Management.
Read more: Microsoft Learn
In the Ultra Transcenders books
SC-500SC-900AB-900SC-200SC-401
Each book explains Insider Risk Management in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Risky user
An account flagged as possibly compromised by ID Protection in Microsoft Entra, typically because of suspicious sign-ins or credentials found leaked. Admins can review these accounts in a dedicated report.
- Microsoft Purview Data Loss Prevention
Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
Related terms
- A5
The highest Microsoft 365 plan for education, equivalent to E5 for schools and universities. It includes premium Purview and Defender capabilities, for example Endpoint DLP, Audit (Premium), Insider Risk Management and the premium eDiscovery features.
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
- Data Connector Admin
The Purview role required on the Data connectors page to set up connectors, for example the HR connector that Insider Risk Management relies on.
- Data Security Posture Management
Brings together DLP, Insider Risk Management and sensitivity-label insights in Microsoft Purview to surface risks to sensitive data, and adds data risk assessments plus remediation for oversharing.
- DataSecurityBehaviors
Daily summaries of possibly suspicious behaviour detected by Insider Risk Management, exposed for advanced hunting in preview. Data appears only once insider risk data is shared with Defender.
- Device onboarding
Brings Windows and macOS computers under Endpoint DLP and Insider Risk Management once device monitoring is switched on in Purview's settings. Computers already in Defender for Endpoint show up there with no extra work.
- Forensic evidence
Records screen clips of security-relevant activity on onboarded devices running the Purview Client, as an optional add-on to Insider Risk Management that is off until enabled. Capturing requires two people to approve, via Insider Risk Management Approvers.
- Global exclusions
Keep things such as domains, keywords, file types and paths, SharePoint sites, sensitive info types or trainable classifiers out of scoring in all Insider Risk Management policies at once. Detection groups can fine-tune them.