21.2 Investigate Insider Risk Activities in the Microsoft Purview Portal
Key Takeaways
- Investigate insider risk from the alert itself using Activity explorer, User activity, All risk factors, and (when available) Content preview; confirming an alert to create or add to a case is a separate action covered in the previous chapter.
- Insider Risk Management generates a single aggregated alert per user and adds new insights to that alert; status values are Needs review, Confirmed, Dismissed, and Resolved, and severity (High, Medium, Low) can change if you do not triage.
- Activity explorer is the timeline of potentially risky events for the alert; Content preview (preview) works for selected SharePoint, Exchange, and OneDrive activities, not for endpoint USB, print, or delete events.
- The User activity tab is the bubble-chart chronology of alerts, sequences, and the user's current risk score (default last three months, with 1/3/6 month filters)—use it to decide whether isolated events are actually a sequence.
- Creating a case requires the Insider Risk Management or Insider Risk Management Investigators role group; Analysts can triage and dismiss but are not in Microsoft's create-case role list. Needs review alerts are deleted after 120 days.
Microsoft Purview Insider Risk Management (IRM) correlates signals to surface potentially malicious or inadvertent insider risks such as IP theft, data leakage, and security violations. Users are pseudonymized by default, and role-based access plus audit logs protect user-level privacy. Exam SC-401 splits two related skills: the previous chapter covered managing alerts and cases and the workflow including notice templates. This section is the investigation skill: how you use the Purview portal to review the activities behind an alert before you decide to confirm, dismiss, or escalate.
Start in the alert queue, not in a case
Policies generate alerts from the indicators you configured. For any generated alerts, IRM produces a single aggregated alert per user and adds new insights for that user to the same alert. That design is why an investigator opens one alert and still sees a growing activity story rather than a separate ticket per USB copy.
On the Standard dashboard, filter Status to Needs review (and Severity to High when you must start with the noisiest risk). Spotlighted alerts on the classic dashboard are a second fast path; Microsoft documents that an alert is automatically spotlighted when it has a risk score of 85 or higher and at least three listed conditions are met (a matching high-confidence insight, priority content or a potential high-impact user, the user manually brought into scope, or two or more high-confidence insights). In the unified Alerts (preview) experience, Spotlight is removed; Microsoft states that after August 31, 2026 only the unified experience is supported, and you prioritize agent-triaged alerts with the Needs attention filter instead.
If you enable the Triage Agent in Insider Risk Management, the agent categorizes alerts as Needs attention or Less urgent. Microsoft documents that the agent analyzes the most recent 30,000 activity events for the user in the alert, evaluates recorded activities beyond only the policy that fired, and marks missing detail as "Not found by agent." You can disagree with Agent categorization using Is this incorrect? (preview). The file-risk section of the Triage Agent is deprecated.
If you scope policies by administrative units, you see only alerts for users in your AU (for example, only Germany). Unrestricted administrators see all users. Restricted administrators cannot access alerts for users assigned to them only through security groups or distribution groups added in administrative units; Microsoft recommends adding users directly to administrative units so restricted admins can see those alerts.
Alert details: what to read before you click Confirm
Open the Alert details page. You can confirm and create a new case, confirm and add to an existing case, or dismiss the alert. The page shows current status and risk severity High, Medium, or Low. Severity is calculated from activity type, number and frequency, user history, and boosters; you cannot customize the programmatic severity assignment. If you leave the alert sitting and risky activity continues to accrue, severity can increase.
Summarize with Copilot (from the queue or the details page) returns the policy, the activity that generated the alert, the triggering event, the user, last working date when applicable, key user attributes, and top risk factors. Suggested prompts include listing data exfiltration activities, sequential activities, unusual behavior, key actions in the last 10 days, and a 30-day activity summary.
Header context on the Standard dashboard includes Activity that generated this alert (the top potentially risky activity and policy match; this value can update over time), Triggering event (the most recent event that started scoring; Communication Compliance scoped triggers apply to the risky-user data-leak and security-violation templates), User details (anonymized if you enabled anonymization), and User alert history for the last 30 days. Policies scoped only to priority content show Only activity with priority content was scored for this alert. Potential high-impact users are highlighted in the header.
In the unified experience, system-generated notes record status changes, assignment changes, and closure (some notes may be missing for activity prior to July 1). Analysts can add up to 50 manual notes per alert or case; notes cannot be edited or deleted, and Microsoft states there is no sync between IRM alert notes and Microsoft Defender. Expanded user profile details (office location, employee type, department, last working date, Entra account deletion date, past alert and case history, priority user group, policy inclusion, HR connector last working date) are not visible when pseudo-anonymization is enabled.
Investigation tabs: Activity explorer versus User activity
These tabs are how you investigate activities. Creating the case is optional and comes after you decide the activity is worth a formal investigation.
All risk factors
Available in both dashboard views. Summaries can include cumulative exfiltration, health record access, priority content, risky browser usage, sequences, top exfiltration activities, unallowed domains, and unusual activity for this user. Content detected links into Activity explorer. Remember that an alert can show a sequence risk factor even when the activity that generated the alert was a simple USB copy—the generating activity is not always the category that looks most dramatic in the filter list.
Activity explorer tab
Activity explorer is the timeline analytics tool for the alert: every associated potentially risky event, filterable by activity scope (all scored activity for the user versus only scored activity in this alert), risk factor, and review status (including Not yet reviewed, which filters out activity that was part of a dismissed or resolved alert). Open an activity to see the details pane used during triage.
Content preview (preview) lets you review relevant files without creating a case, so you can confirm sensitive data, catch a false positive, or decide to escalate. Microsoft documents preview for activities that access or transmit content:
- SharePoint and OneDrive for Business: file accessed, file download, full file sync download
- Exchange: email sent (hygiene events), Data loss prevention rule matches
Content preview is not supported for state changes, permission changes, deletions, or signal-only events: file or folder deletion and recycle bin events, endpoint activities (deletion, copying, printing, USB transfers), browser or removable media events, metadata-only events, and renamed files. If the exam scenario is a USB copy, do not pick Content preview as the way to open the file in the alert.
Counts in the explorer can disagree with the timeline. Cumulative exfiltration deduplicates similar activities and is computed from policy and settings at computation time—changing allowed domains or file-type exclusions later does not rewrite earlier totals. External email risk scores can be based on number of emails sent rather than raw event-log counts. Sequence detections can include events excluded from scoring (for example a .png globally excluded but used in an obfuscation sequence); excluded steps are marked Excluded, and the scatter-plot icon shows a risk score of 0 when every event in a step is excluded.
User activity tab
Both dashboard views include User activity, which Microsoft calls one of the most powerful investigation tools for alerts and cases. It is the visual chronology: historical timeline of alerts, alert details, the user's current risk score, and sequences of related events drawn with connecting lines. Default view is the last three months, with 1 Month, 3 Months, and 6 Months tabs. Filters (preview) include risk category (activities with risk scores greater than 15 unless in a sequence, and sequence activities) and activity type (Access, Deletion, Collection, Exfiltration, Infiltration, Obfuscation, Security, Custom Indicator, Defense Evasion, Privilege Escalation, Communication Risk, User Compromise Risk, and AI Usage). Sort by date occurred or risk score. Each bubble shows date, activity category, numerical risk score, and links to associated files or email. Cumulative exfiltration activities opens a chart of how activity builds over time. A color-coded legend maps risk category. Sequence details include name, date range, combined sequence risk score, and event counts.
The case-action toolbar (resolve, email notice, escalate) appears when you are viewing a case. On an alert you have not confirmed, your job is still to read this chart so you do not dismiss a "one-off" that is actually the middle of a download-exfiltrate-delete sequence.
Data risk graph
When Microsoft Sentinel integration is in place and anonymized usernames are not enabled, the Data risk graph tab shows connections among users, files, and activities. You cannot use this feature with anonymized usernames.
Act on the alert: confirm, dismiss, or assign
| Status | Meaning |
|---|---|
| Needs review | New alert; no triage action yet. Microsoft deletes these 120 days from creation. |
| Confirmed | You confirmed the alert and assigned it to a new or existing case. |
| Dismissed | You judged the activity benign during triage. Capture a reason and notes in the user's alert history. Reason classifications include Activity is expected for this user, Activity is impactful enough for me to investigate further, and Alerts for this user contain too much activity. |
| Resolved | The alert is part of a closed and resolved case. |
You can bulk-dismiss Needs review alerts (preview) up to 400 at a time. Dismissing requires membership in Insider Risk Management, Insider Risk Management Analysts, or Insider Risk Management Investigators.
Creating a case is a different permission cut. Microsoft's procedure states you must be in Insider Risk Management or Insider Risk Management Investigators to create a case. From the alert, choose Actions > Confirm alerts & create case, name the case, add contributors, and add comments (which become a case note). Create case with content download on (preview) is optional; you can enable downloads later on an active case if you skip it at creation. You can instead confirm and add the alert to an existing case for that user—each case focuses on one user.
Assign ownership from the dashboard or the details page to yourself or another user in Insider Risk Management, Analysts, or Investigators. One admin at a time. Admins in a Microsoft Entra security group are not supported for alert assignment; the admin must be directly assigned to a required role. Custom groups must include the Case management role (present in Analysts and Investigators; you must add it explicitly to a custom group). AU-scoped assignment can go only to IRM users whose role covers the user in the alert.
IRM throttles trigger processing so misconfigured connectors or DLP policies cannot flood the queue; signals beyond the throttling limits are not processed. Microsoft publishes the numeric throttle limits in the Insider Risk Management limits article—do not invent a number on the exam if the item does not state it.
Reports (last 30 days) include total alerts that need review by severity, open alerts over the past 30 days, and average time to resolve high, medium, and low severity alerts.
When the investigation shows a true insider-risk pattern, you confirm into a case and pick up notice templates and case resolution from the previous chapter. When it shows expected job activity or a noisy indicator, you dismiss and, if the pattern repeats, tune indicators—without opening a case just to look at Activity explorer.
An Insider Risk Management analyst needs to confirm whether a SharePoint download in an alert actually contained customer data before deciding to escalate. Which Purview capability is designed for that check without opening a case?
A user is in the Insider Risk Management Analysts role group and has finished reviewing User activity sequences for an alert. The user needs to open a new IRM case. What does Microsoft document?
An IRM alert has sat in Needs review for four months with no owner. What does Microsoft publish about that alert's retention and about severity while it waits?