purview-insider-risk-management
Microsoft Purview Insider Risk Management
Insider Risk Management (IRM) correlates signals from across M365, endpoints, Defender, Entra, and HR systems to surface risky user activity — most importantly intent over time (e.g., the classic "departing employee exfiltrating customer lists 3 weeks before their last day"). It pairs with Adaptive Protection, which dynamically tightens DLP and CA policy on users whose risk score is rising.
When to use
Operationalizing insider risk detection beyond the program-level baseline: policy template selection, HRIS connector setup, alert tuning, case investigation, and Adaptive Protection rollout.
Do not use this skill for outbound DLP authoring (purview-dlp-policy,
purview-advanced-dlp), eDiscovery (purview-ediscovery), or the high-level insider
risk program framing (insider-risk-baseline).