Which Insider Risk Management policy template fits each scenario, with its triggering event, prerequisites and user limit.
From Ultra Transcenders SC-401 by Tony Rough (coming December 2026)
Every policy is based on a template that fixes its triggering events and prerequisites, so matching the requirement to the template is the key design decision.
| Template | Triggering event | Prerequisites | Users in scope (limit) |
|---|---|---|---|
| Data theft by departing users | Resignation or termination date from HR, or Entra account deletion | HR connector optional | 20,000 |
| Data leaks | High-severity DLP alert or built-in exfiltration triggers | DLP policy with High alerts (Exchange, SharePoint, OneDrive) or custom triggering indicators | 15,000 |
| Data leaks by priority users | As Data leaks | As Data leaks, plus priority user groups | 1,000 |
| Data leaks by risky users | HR performance, improvement plan or job level events; threatening, harassing or discriminatory messages | HR connector and/or Communication Compliance integration | 7,500 |
| Security policy violations | Defense evasion or unwanted software detected by Defender for Endpoint | Defender for Endpoint and its Purview integration | 1,000 |
| Security policy violations by departing users | Resignation, termination or Entra account deletion | Defender for Endpoint integration; HR connector optional | 15,000 |
| Security policy violations by priority users | Defender for Endpoint detections | Defender for Endpoint integration, priority user groups | 1,000 |
| Security policy violations by risky users | HR stressor events or risky messages | HR connector and/or Communication Compliance, plus Defender for Endpoint | 7,500 |
| Patient data misuse (preview) | EMR defence evasion; user and patient address matching | Healthcare or Epic connector, HR connector | 5,000 |
| Risky AI usage | No separate trigger listed; detects sensitive prompts and responses in Microsoft 365 Copilot, Microsoft Copilot and agents, and browsing to generative AI sites | Edge or Chrome extension, at least one browsing indicator | 10,000 |
| Risky browser usage (preview) | Browsing that matches a selected browsing indicator (for example, phishing sites) | Browser signal detection prerequisites | 7,000 |
| Risky Agents (preview) | Risky prompts, sensitive responses, sensitive file or risky site access by agents | Copilot Studio or Microsoft Foundry agents; applied by default | Not listed |
In practice: leavers map to Data theft by departing users; oversharing by anyone to Data leaks with a dedicated high-severity DLP policy; sensitive roles or projects to the priority users variants; employment stressors to the risky users templates; malware or disabled security tools to the security policy violations family. Risky AI usage is also offered as a one-click policy in DSPM for AI (see Protecting data used by AI). Each template supports up to 100 policies, and user limits count users brought into scope by a trigger across all policies of that template.
Common trap: Data theft by departing users can’t work without an HR connector - the connector is optional; the template can use Microsoft Entra account deletion as its triggering event, although HR data gives earlier warning through resignation dates.
This note is one section of Ultra Transcenders SC-401: Administering Information Security in Microsoft 365, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · SC-401 terms in the glossary · All SC-401 study notes
How EDM SITs match your own records: schema, primary and supporting elements, new and classic experiences, and hashing and uploading data.
How to design sensitivity labels: the four label scopes, label priority and order, sublabels and label groups, and label limits.
How to roll out a DLP policy safely with simulation mode and policy tips, and the four policy states with their PowerShell Mode values.
Which Windows, Windows Server and macOS devices Endpoint DLP supports, the prerequisites, and how to onboard devices to Microsoft Purview.
Which setting wins when several retention policies and labels apply to one item, with worked examples, and how to use Policy lookup.
What Audit (Premium) adds over Audit (Standard): default retention periods, 10-year retention, intelligent insights and the licences each needs.
How to build Microsoft Purview eDiscovery searches with the condition builder and KeyQL, with example queries and the search limits to know.