Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Important
Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.
Policy timeframes in Microsoft Purview Insider Risk Management let you set past and future review periods that start after policy matches events and activities for the Insider Risk Management policy templates. Depending on the policy template you choose, you can set the following policy timeframes:
- Activation window: Available for all policy templates, Activation window is the number of days that the window activates after a triggering event. The window activates for 1 to 30 days after a triggering event occurs for any user assigned to the policy. For example, you configure an Insider Risk Management policy and set Activation window to 30 days. Several months pass since you configured the policy, and a triggering event occurs for one of the users included in the policy. The triggering event activates Activation window and the policy is active for that user for 30 days after the triggering event occurred. 
- Past activity detection: Available for all policy templates, Past activity detection is the number of days that the window activates before a triggering event. For activities in the audit log, the window activates for 0 to 90 days before a triggering event occurs for any user assigned to the policy. For example, you configure an Insider Risk Management policy and set Past activity detection to 90 days. Several months pass since you configured the policy, and a triggering event occurs for one of the users included in the policy. The triggering event activates Past activity detection and the policy gathers historic activities for that user for 90 days prior to the triggering event. - Note - For email activities, the past activity detection period is 10 days. 
Set policy timeframes
- In Insider Risk Management settings, select Policy timeframes. 
- Move the slider for Activation window and Past activity detection to the number of days that you want. 