Brings a user into an Insider Risk Management policy so scoring of their activity begins. Examples are a high-severity DLP alert or a resignation date from the HR connector.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Triggering event in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Insider Risk Management
A Microsoft Purview solution that scores risky user activity, such as leaking or stealing data, from activity indicators and raises alerts. DLP policies are not edited here.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- Microsoft Purview Data Loss Prevention
Policies in Purview that look for sensitivity labels or sensitive information types in content held in many places, including Microsoft 365 Copilot, and respond by auditing, warning or blocking. You can simulate a policy before enforcing it.
- HR connector
A Microsoft Purview connector that loads human resources information from CSV files into Insider Risk Management. Resignation and leaving dates, changes in job level, performance reviews and improvement plans can then act as triggers or indicators.
Related terms
- Past activity detection
The period before a triggering event whose activity Insider Risk Management still scores. Adaptive Protection has a separate setting of the same name, 7 days by default and adjustable from 5 to 30, used when assigning insider risk levels.
- Policy indicator
An activity that an Insider Risk Management policy watches for, picked from the indicators enabled in global settings. A user's activity against it is only scored once a triggering event has happened.