How to Pilot Microsoft Purview Insider Risk Management
Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.
Microsoft Purview Insider Risk Management can detect data theft and leaks by insiders, but it needs careful setup and governance. Here is how to run a pilot.
Step 1: Set up governance first
- Involve HR, legal, privacy and (where applicable) works councils before configuring anything.
- Define the purpose (for example, protecting confidential data when employees leave), what will be monitored, and who can investigate.
- Keep pseudonymization enabled so investigators see anonymized identities until escalation is justified.
Step 2: Assign roles
Use the Insider Risk Management role groups to separate administrators, analysts and investigators. Keep the investigator group small.
Step 3: Enable data sources
- Turn on Microsoft 365 auditing (required).
- Connect HR data with the HR connector to provide resignation and termination dates for the data theft by departing users template.
- Onboard devices to Microsoft Purview endpoint DLP for device signals such as USB copying.
Step 4: Start with one policy template
The Data theft by departing users template is a common first policy: it is narrowly scoped and has clear business justification. Scope it to a pilot group or to priority content (for example, files with Highly Confidential labels).
Step 5: Tune thresholds
Review alerts weekly for the first month. Adjust indicator thresholds and add exclusions for expected bulk activity (such as legitimate data migrations).
Step 6: Define the response process
Document what happens when an alert is confirmed: HR involvement, legal review, steps to preserve evidence and actions to recover data.
Step 7: Evaluate
After 60–90 days, review alert volume, true positives and investigator time before expanding.
- Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand Platform Changes
- Insider Risk Policy Checklist: Privacy, HR and Legal Sign-Off How-To & Hardening
- CIO Brief: Insider Risk Without Spying on Employees CIO Briefings