Introduction
Insider risk management is the part of Microsoft Purview that monitors user activity for behavior that could indicate data theft, policy violations, or accidental exposure. Unlike DLP which looks at the content of messages and files, insider risk management looks at patterns of behavior – someone downloading an unusually large number of files from SharePoint, a departing employee copying sensitive data to a USB drive, or a user repeatedly accessing documents outside their normal scope.
This guide walks you through setting up your first insider risk policy so you can start detecting these signals without drowning in noise. Before you start, insider risk management requires Microsoft 365 E5 or the E5 Compliance add-on. It is not available with E3 licensing. You also need the Insider Risk Management or Insider Risk Management Admin role. If you need help with permissions, refer back to the first-day setup guide.
Choosing the Right Policy Template for What You Actually Need
Microsoft provides several pre-built policy templates. Each comes pre-configured with the relevant indicators and triggering events. Here is what each template watches for and when you should use it.
Data theft by departing users is the most commonly deployed template and the one I recommend starting with. It monitors users who have submitted resignation notices in HR systems or whose accounts are marked for deletion, looking for suspicious download activity, file copying to external services, or unusual email forwarding patterns. The HR connector integrates with your HR system to automatically flag departing employees.
Data leaks monitors for sensitive data being shared externally through email, Teams, or cloud services – broader than the departing users template and applies to everyone in scope. Risky browser activity watches for users visiting potentially malicious websites or attempting to bypass web controls, requiring integration with Microsoft Defender for Endpoint. Security policy violations catches users who disable security features or tamper with audit logs.
Data leaks by risky users is an adaptive template that uses machine learning to identify users whose behavior deviates significantly from their baseline. It is the most sophisticated but requires the most tuning. Start with Data theft by departing users. It has a clear triggering condition and straightforward indicators, giving you a manageable number of alerts to learn from.
Configuring Indicators Without Generating Noise
Indicators are the specific user activities your policy watches for. The more indicators you enable, the more alerts you generate – and insider risk alerts require human triage. There is no auto-remediation. Each indicator is categorized under a risk area: Office indicators cover SharePoint downloads and file deletions. Device indicators cover file copies to USB and printing sensitive documents. HR indicators rely on the HR connector for resignation dates.
For your first policy, limit yourself to 5 to 8 high-signal indicators. I recommend: downloading content from SharePoint, exporting to external services, sending email with attachments outside the organization, downgrading or removing sensitivity labels, and copying files to USB devices. Each is a deliberate action with a clear connection to potential data theft.
You also set a threshold per indicator. A single download from SharePoint is normal. Fifty downloads in an hour is worth investigating. Start with moderate thresholds – 5 to 10 occurrences in a 24-hour window – and adjust based on what you see in the first weeks. If you are unsure about tuning, the common configuration mistakes guide covers insider risk tuning issues in detail.
How Alerts Work and How to Triage Them Without Getting Overwhelmed
Insider risk alerts appear in the Alerts queue under Insider risk management. Each alert shows the user, the triggering activity, severity level, indicator matches, and a timeline of recent activity. The timeline view is your main investigative tool – did the user download 200 files and then immediately connect a USB device?
After reviewing, dismiss the alert as benign, escalate it to a case, or resolve it with a note. A good triage rhythm is 5 to 10 minutes per alert. If you need to reconstruct a user’s full activity across Microsoft 365, use the unified audit log. For legally sensitive investigations, eDiscovery provides the proper chain of custody.
Adaptive protection uses machine learning to calculate a dynamic risk score based on user behavior patterns over time. A user with consistently high download volumes as part of their job will not trigger the same alerts as someone who suddenly spikes. Adaptive protection requires at least 30 days of baseline data, so expect higher alert volumes in your first month.

Setting Up the HR Connector to Automate Departing Employee Detection
The Data theft by departing users policy needs to know who is leaving. The HR connector pulls resignation and termination data directly from your HR system into Purview so departing employees are automatically monitored. Microsoft provides native connectors for Workday, SAP SuccessFactors, and a generic CSV connector.
If you cannot set up the HR connector right away, use the Azure AD account deletion indicator as a fallback. It triggers monitoring when an account is disabled or deleted. The downside is a shorter detection window – by the time an account is disabled, data may already be gone. The HR connector gives you more lead time because it triggers when the resignation is submitted, not when IT processes the account.
Rolling Out Your Policy and Tuning It Over Time
Insider risk management does not have a formal simulation mode like DLP policies. Instead, scope your policy to a small pilot group first – your IT team or a single department. Let it run for two weeks and review every alert daily. This teaches you what normal looks like.
After the pilot, expand gradually – one department at a time. Monitor for two weeks at each stage. A well-tuned insider risk policy should generate no more than 5 to 10 alerts per week for a mid-sized organization. If you are seeing 50 alerts a day, your thresholds are too low or indicators too broad.
Review your policy configuration quarterly. As teams adopt new tools and workflows, previously rare indicators may become common. Once everything is stable, use the monitoring dashboards to track insider risk alerts alongside your DLP and label activity metrics from a single pane. If you also need to monitor message content for policy violations, Communication Compliance is the complementary tool.


Leave a Reply
You must be logged in to post a comment.