Lets Conditional Access react to the risk level that Adaptive Protection in Microsoft Purview gives a user (minor, moderate or elevated), blocking them or asking for stronger controls.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Insider risk in context, with comparison tables and the common traps.
Terms in this definition
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Risk level
The low, medium or high value that Microsoft Entra ID Protection gives to show how likely it is that an account or a sign-in has been compromised; Conditional Access policies based on risk respond to it. Insider risk levels in Microsoft Purview Adaptive Protection (Elevated, Moderate, Minor) are a different scale.
- Adaptive Protection
A Microsoft Purview capability in which Insider Risk Management rates each person as Minor, Moderate or Elevated risk. DLP, Conditional Access and data lifecycle policies then adjust automatically, so the tightest restrictions fall on the highest-risk people only.
- Microsoft Purview
Family of Microsoft products for data governance, security and compliance. Its Data Map stores only metadata, such as lineage, schema and classification, never the data itself.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
Related terms
- Data risk graph
Shows a map of a user's activity and files linked to an insider risk alert across the last 30 days, built on Microsoft Sentinel. Microsoft is retiring it on 24 November 2026.
- Data theft by departing users
An insider risk template aimed at people leaving the organisation: it scores downloads, printing, copying to personal cloud storage and similar exfiltration near their leaving date, taken from the HR connector or the deletion of their Entra account.
- DataSecurityBehaviors
Daily summaries of possibly suspicious behaviour detected by Insider Risk Management, exposed for advanced hunting in preview. Data appears only once insider risk data is shared with Defender.
- DataSecurityEvents
Each user action that breaks a Purview policy, enriched with labels and sensitive information types, exposed as an advanced hunting table in preview. Data appears only once insider risk data is shared with Defender.
- EMR
Electronic medical record systems used by healthcare providers. Their audit data, brought in by the Microsoft Healthcare connector, lets the Patient data misuse insider risk template spot inappropriate viewing, changes and exports.
- Microsoft Purview extension
Installed in Chrome or Firefox on onboarded devices so that Endpoint DLP and insider risk monitoring can watch what happens in those browsers. Edge works without it.
- Past activity detection
The period before a triggering event whose activity Insider Risk Management still scores. Adaptive Protection has a separate setting of the same name, 7 days by default and adjustable from 5 to 30, used when assigning insider risk levels.
- Quick setup
Switches on Adaptive Protection in the quickest way, in up to 72 hours. Behind the scenes Purview creates default risk levels, a Data leaks insider risk policy, two simulated DLP policies, a lifecycle policy for data and a Conditional Access policy set to report only.