493756 – Microsoft Purview compliance portal: Insider Risk Management- Multi selectable DLP policies as an IRM triggering event

cloudscout.one Icon

check before: 2025-08-01

Product:

Purview Communication Compliance, Purview Data Loss Prevention, Purview Information Protection, Purview Insider Risk Management

Platform:

Web, World tenant

Status:

In development

Change type:

Links:

Details:

Insider Risk Management is releasing the ability to select multiple Data Loss Prevention (DLP) policies as triggering events in a policy. Previously, admins could only select one DLP policy as a triggering event within Insider Risk Management policies. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

Change Category:
XXXXXXX ... free basic plan only

Scope:
XXXXXXX ... free basic plan only

Release Phase:
General Availability, Preview

Created:
2025-05-21

updated:
2025-05-21

Public Preview Start Date

XXXXXXX ... free basic plan only

Docu to Check

XXXXXXX ... free basic plan only

MS workload name

XXXXXXX ... free basic plan only

summary for non-techies**

Microsoft Purview's Insider Risk Management now allows administrators to use multiple Data Loss Prevention (DLP) policies as triggers, providing a more comprehensive view of potential insider risks while ensuring user privacy through pseudonymization and role-based access controls.

Direct effects for Operations**

Increased Complexity in Policy Management
The introduction of multi-selectable DLP policies may lead to confusion among administrators, resulting in misconfigured policies that could either overlook potential risks or trigger unnecessary alerts.
   - roles: IT Administrators, Compliance Officers
   - references: https://techcommunity.microsoft.com/t5/security-compliance-identity/insider-risk-management-in-microsoft-purview/ba-p/3651230" target="_blank" rel="nofollow noopener noreferrer">https://techcommunity.microsoft.com/t5/security-compliance-identity/insider-risk-management-in-microsoft-purview/ba-p/3651230, https://www.microsoft.com/en-us/microsoft-365/blog/2022/09/20/announcing-new-features-in-microsoft-purview-compliance/ " target="_blank" rel="nofollow noopener noreferrer">https://www.microsoft.com/en-us/microsoft-365/blog/2022/09/20/announcing-new-features-in-microsoft-purview-compliance/

User Experience Degradation
If multiple DLP policies are not properly configured, users may experience increased false positives, leading to unnecessary investigations and potential disruptions in their workflow.
   - roles: End Users, IT Support Staff
   - references: https://www.microsoft.com/en-us/microsoft-365/blog/2022/09/20/announcing-new-features-in-microsoft-purview-compliance/, https://techcommunity.microsoft.com/t5/security-compliance-identity/insider-risk-management-in-microsoft-purview/ba-p/3651230" target="_blank" rel="nofollow noopener noreferrer">https://techcommunity.microsoft.com/t5/security-compliance-identity/insider-risk-management-in-microsoft-purview/ba-p/3651230

Configutation Options**

XXXXXXX ... paid membership only

Data Protection**

XXXXXXX ... paid membership only

IT Security**

XXXXXXX ... paid membership only

explanation for non-techies**

XXXXXXX ... free basic plan only

** AI generated content. This information must be reviewed before use.

a free basic plan is required to see more details. Sign up here


A cloudsocut.one plan is required to see all the changed details. If you are already a customer, choose login.
If you are new to cloudscout.one please choose a plan.



Last updated 3 weeks ago

Share to MS Teams

Login to your account

Welcome Back, We Missed You!