370560 – Microsoft Purview compliance portal: Insider Risk Management-Insider risk context in Microsoft Defender user entity page (archived)

cloudscout.one Icon

check before: 2025-02-01

Product:

Defender, Purview, Purview Communication Compliance, Purview compliance portal, Purview Insider Risk Management

Platform:

US Instances, Web, World tenant

Status:

Launched

Change type:

Links:

Details:

With this update, any SOC analyst with the required customer-determined permissions can access an insider risk summary of user activities that may lead to potential data security incidents, as a part of the user entity investigation experience in Microsoft Defender. This feature can help SOC analysts gain insider risk context for a specific user and make more informed decisions on responses to potential incidents. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:
General Availability, Preview

Created:
2023-12-21

updated:
2026-01-21

Public Preview Start Date

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

summary for non-techies**

Microsoft Purview's Insider Risk Management update integrates with Microsoft Defender to provide Security Operations Center analysts with direct access to user activity summaries, enabling them to monitor and respond to potential security incidents while maintaining user privacy through pseudonymization and controlled access.

Direct effects for Operations**

Data Security Incident Risk
Without proper preparation, the implementation of insider risk management features may lead to misinterpretation of user activities, resulting in false positives for potential data security incidents. This can cause unnecessary investigations and strain on resources.
   - roles: SOC Analyst, IT Security Manager
   - references: https://techcommunity.microsoft.com/t5/security-compliance-identity/insider-risk-management-in-microsoft-purview/ba-p/3651230, https://www.microsoft.com/en-us/security/blog/2021/06/24/insider-risk-management-in-microsoft-365/

User Privacy Concerns
If the insider risk management features are deployed without adequate communication and training, users may feel their activities are being excessively monitored, leading to decreased trust and morale within the organization.
   - roles: End User, HR Manager
   - references: https://www.forbes.com/sites/bernardmarr/2021/06/28/the-importance-of-user-privacy-in-the-age-of-data-analytics/?sh=5c1c1e1e7b5b, https://www.microsoft.com/en-us/security/blog/2021/06/24/insider-risk-management-in-microsoft-365/

Configutation Options**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



change history

DatePropertyoldnew
2026-01-21RM Product TagsMicrosoft Purview compliance portalMicrosoft Purview
2025-05-06RM StatusIn developmentLaunched
2024-09-05RM ReleaseNovember CY2024February CY2025
2024-03-19RM ReleaseMarch CY2024November CY2024
2024-03-19RM PreviewDecember CY2023April CY2024

Last updated 1 week ago ago

Leave a Reply

Share to MS Teams

Login to your account

Welcome Back, We Missed You!