Dissecting a Microsoft Purview Insider Risk Management Policy

Insider Risk Management policies can surface the gaps in your data protection configuration very quickly!


Tapping into the Information Protection side of things for the first time with Insider Risk Management (IRM) in Microsoft Purview. While we are focusing on external threats, managing the insider risk is equally important. It can be too late before someone leaks data to outside, deletes the important files before he left the business or downloading and sharing confidential data with external parties.


It will quickly indicate the importance of having other guardrails such as DLP policies, SITs, Sensitivity labels before configuring IRM policies as they work together as a closed knitted system.

While there are a number of IRM templates, I want to showcase the data leak scenario which is relevant to any organization.

Below is my take on IRM policy config and the how you can use Adaptive Protection features to eliminate that risk.



Discover more from EMS Route

Subscribe to get the latest posts sent to your email.

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.