What is Microsoft Purview Insider Risk Management?
Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage and security violations. Organizations use it to create policies that manage security and compliance. According to Microsoft, the solution is built with privacy by design: users are pseudonymized by default, and role-based access controls and audit logs help ensure user-level privacy.
Employees now have more access to create, manage and share data across a broad spectrum of platforms and services. In most cases, organizations have limited resources and tools to identify and mitigate organization-wide risks while also meeting compliance requirements and employee privacy standards. Insider Risk Management is part of Microsoft Purview; for an overview of the whole platform, see our page on Microsoft Purview.
Core Features
Signal correlation: The solution uses the full breadth of service and third-party indicators to help you quickly identify, triage and act on potentially risky activity.
Policies for risk indicators: Using logs from Microsoft 365 and Microsoft Graph, you define policies that evaluate specific risk indicators.
Pseudonymization by default: Users are pseudonymized by default, decoupling analysis from identifying individuals.
Role-based access control and auditing: Permissions govern who sees which information, and audit logs make access traceable.
Case handling and escalation: Identified risks can be mitigated, tracked as investigation cases and, if needed, escalated to eDiscovery for additional legal review.
Typical Use Cases
Departing employees: Detecting potential data theft associated with an upcoming departure.
Data leakage: Uncovering leaks of information outside the organization, through accidental oversharing or malicious intent.
IP protection: Identifying activity that suggests intellectual property is leaving the organization.
Security violations: Detecting behavior that breaches security requirements, including triage and response.
Benefits
- Detection of both malicious and inadvertent insider risks in one solution
- Privacy-conscious analysis through pseudonymization by default
- Traceability through role-based access controls and audit logs
- Use of existing signals from Microsoft 365 and Microsoft Graph
- A direct path from detection through investigation to escalation into eDiscovery
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you in adopting Insider Risk Management: planning and licensing verification, configuring settings, permission and role model, building policies and connectors, and aligning with data protection and works council requirements.
Contact us for a no-obligation consultation on Insider Risk Management with Microsoft Purview.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Microsoft Purview Insider Risk Management?
Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage and security violations. It enables organizations to create policies to manage security and compliance. Insider Risk Management is part of Microsoft Purview; for an overview of the whole platform see our page on [Microsoft Purview](/en/cloud/azure/products/purview/).
How is employee privacy protected?
According to Microsoft, the solution is built with privacy by design: users are pseudonymized by default. Role-based access controls and audit logs are additionally in place to help ensure user-level privacy.
Which data sources are analyzed?
Insider Risk Management uses the full breadth of service and third-party indicators. Per Microsoft, it relies on logs from Microsoft 365 and Microsoft Graph, on which policies evaluate defined risk indicators.
Which risks does the solution address?
Microsoft names potential data theft by departing employees and the risk of data leaks outside the organization through accidental oversharing or malicious intent. Overall the focus is on IP theft, data leakage and security violations.
How is Insider Risk Management configured?
Microsoft describes five steps: learn about Insider Risk Management, plan for it and verify licensing, configure the settings, configure permissions and policy prerequisites and connectors, and then create and configure the policies.
What happens with detected risks?
After identification you can take action to mitigate the risks. If necessary, you open investigation cases and take appropriate legal action. Cases can also be escalated to Microsoft Purview eDiscovery when additional legal review is required.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
