FREE STUDY NOTES · SC-401

Choosing an Insider Risk Management policy template in Microsoft Purview

Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.

From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)

Every policy is based on a template that fixes its triggering events and prerequisites, so matching the requirement to the template is the key design decision.

Template Triggering event Prerequisites Users in scope (limit)
Data theft by departing users Resignation or termination date from HR, or Entra account deletion HR connector optional 20,000
Data leaks High-severity DLP alert or built-in exfiltration triggers DLP policy with High alerts (Exchange, SharePoint, OneDrive) or custom triggering indicators 15,000
Data leaks by priority users As Data leaks As Data leaks, plus priority user groups 1,000
Data leaks by risky users HR performance, improvement plan or job level events; threatening, harassing or discriminatory messages HR connector and/or Communication Compliance integration 7,500
Security policy violations Defense evasion or unwanted software detected by Defender for Endpoint Defender for Endpoint and its Purview integration 1,000
Security policy violations by departing users Resignation, termination or Entra account deletion Defender for Endpoint integration; HR connector optional 15,000
Security policy violations by priority users Defender for Endpoint detections Defender for Endpoint integration, priority user groups 1,000
Security policy violations by risky users HR stressor events or risky messages HR connector and/or Communication Compliance, plus Defender for Endpoint 7,500
Patient data misuse (preview) EMR defence evasion; user and patient address matching Healthcare or Epic connector, HR connector 5,000
Risky AI usage No separate trigger listed; detects sensitive prompts and responses in Microsoft 365 Copilot, Microsoft Copilot and agents, and browsing to generative AI sites Edge or Chrome extension, at least one browsing indicator 10,000
Risky browser usage (preview) Browsing that matches a selected browsing indicator (for example, phishing sites) Browser signal detection prerequisites 7,000
Risky Agents (preview) Risky prompts, sensitive responses, sensitive file or risky site access by agents Copilot Studio or Microsoft Foundry agents; applied by default Not listed

In practice: leavers map to Data theft by departing users; oversharing by anyone to Data leaks with a dedicated high-severity DLP policy; sensitive roles or projects to the priority users variants; employment stressors to the risky users templates; malware or disabled security tools to the security policy violations family. Risky AI usage is also offered as a one-click policy in DSPM for AI (see Protecting data used by AI). Each template supports up to 100 policies, and user limits count users brought into scope by a trigger across all policies of that template.

Common trap: Data theft by departing users can’t work without an HR connector - the connector is optional; the template can use Microsoft Entra account deletion as its triggering event, although HR data gives earlier warning through resignation dates.

Get the whole book

This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · SC-401 terms in the glossary · All SC-401 study notes

More SC-401 study notes