purview-insider-risk-management

Installation
SKILL.md

Microsoft Purview Insider Risk Management

Insider Risk Management (IRM) correlates signals from across M365, endpoints, Defender, Entra, and HR systems to surface risky user activity — most importantly intent over time (e.g., the classic "departing employee exfiltrating customer lists 3 weeks before their last day"). It pairs with Adaptive Protection, which dynamically tightens DLP and CA policy on users whose risk score is rising.

When to use

Operationalizing insider risk detection beyond the program-level baseline: policy template selection, HRIS connector setup, alert tuning, case investigation, and Adaptive Protection rollout.

Do not use this skill for outbound DLP authoring (purview-dlp-policy, purview-advanced-dlp), eDiscovery (purview-ediscovery), or the high-level insider risk program framing (insider-risk-baseline).

Policy templates — pick by use case

Installs
34
GitHub Stars
173
First Seen
Jun 20, 2026
purview-insider-risk-management — vinayaklatthe/microsoft-security-skills