Share via


Insider Risk Management

Important

Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

Employees now have more access to create, manage, and share data across a broad spectrum of platforms and services. In most cases, organizations have limited resources and tools to identify and mitigate organization-wide risks while also meeting compliance requirements and employee privacy standards. These risks include potential data theft by departing employees and risk of data leaks of information outside your organization by accidental oversharing or malicious intent.

Microsoft Purview Insider Risk Management uses the full breadth of service and third-party indicators to help you quickly identify, triage, and act on potentially risky activity. By using logs from Microsoft 365 and Microsoft Graph, Insider Risk Management allows you to define specific policies to identify risk indicators. After identifying the risks, you can take action to mitigate these risks, and if necessary open investigation cases and take appropriate legal action.

Watch the following videos to learn how Insider Risk Management can help your organization prevent, detect, and contain risks:

Insider Risk Management solution & development:


Insider Risk Management workflow:

Configure Insider Risk Management

Use the following steps to configure Insider Risk Management for your organization:

Insider risk solution Insider Risk Management steps

  1. Learn about Insider Risk Management
  2. Plan for Insider Risk Management and verify licensing
  3. Configure Insider Risk Management settings
  4. Configure permissions and policy prerequisites & connectors
  5. Create and configure Insider Risk Management policies

More information about Insider Risk Management