19.1 Manage Insider Risk Alerts and Cases

Key Takeaways

  • New Insider Risk Management (IRM) alerts start as Needs review; Confirmed means you assigned the alert to a new or existing case, Dismissed means you judged it benign, and Resolved appears after the related case is closed.
  • Alert severity is High, Medium, or Low, calculated programmatically from risk scores. You cannot customize that mapping, and severity can increase if you leave an alert untriaged while more risky activity accrues.
  • Creating a case from an alert requires the Insider Risk Management or Insider Risk Management Investigators role group. Analysts can dismiss, assign, and investigate existing cases but cannot create the case or open Content explorer or forensic evidence.
  • Each case is scoped to one user. The User activity timeline is the primary tool for sequencing alerts, risk scores, and related events; Content explorer is a post-confirm snapshot for Investigators (and the umbrella Insider Risk Management group), not Analysts.
  • Microsoft publishes a maximum of 100 active cases, which are retained indefinitely. Needs review and Dismissed alerts, plus resolved cases, are deleted 120 days after creation or resolution.
Last updated: August 2026

Insider Risk Management (IRM) in Microsoft Purview is only as useful as the triage discipline behind it. Policies and indicators produce alerts; humans decide whether those alerts are noise, a coaching moment, or a case that needs investigation. SC-401 tests that you can work the Alerts and Cases dashboards in the Microsoft Purview portal (Insider Risk Management solution), apply the right status, and use the User activity timeline without confusing IRM roles with Data Loss Prevention (DLP) queues or Microsoft Defender XDR incidents. Deeper DLP alert handling and Defender XDR correlation are the next chapter. This section stays on the Purview IRM alert-to-case path.

How alerts appear

When risk indicators match an IRM policy, the service creates an alert. Microsoft publishes that IRM generates a single aggregated alert per user; new insights for that user are added to the same alert rather than spawning a separate alert for every event. New alerts that nobody has touched receive the Needs review status. You work them from the Standard alert dashboard, the Triage Agent dashboard (if the agent is enabled), or the unified Alerts (preview) list that combines both.

Triage order is deliberate: start with Needs review, then highest severity. Filter by Status, Severity (High, Medium, Low), Time detected (UTC), Policy, Assigned to, Triggering event, Activity that generated the alert, Risk factors, and Alert dismissal reason. You can save up to five filter sets as reusable cards. Search supports user principal name (UPN), assigned admin name, or Alert ID. If policies are scoped by administrative units, restricted admins see only in-scope users; unrestricted admins see the tenant. Microsoft recommends adding users directly to admin units, because users added only through security groups or distribution groups may not surface alerts to restricted admins.

Alert status and severity

You triage alerts into four published statuses:

StatusMeaning
Needs reviewNew alert; no triage action yet
ConfirmedYou confirmed the alert and assigned it to a new or existing case
DismissedYou judged the activity benign during triage
ResolvedThe alert belongs to a case that has been closed

Dismissal is not a silent click. You can record a reason and notes that remain in the user's alert history for later reviewers. Published reason classifications include Activity is expected for this user, Activity is impactful enough for me to investigate further, and Alerts for this user contain too much activity. Members of Insider Risk Management, Analysts, or Investigators can bulk-dismiss Needs review alerts; Microsoft publishes a maximum of 400 alerts in one dismiss action.

Severity is High, Medium, or Low. The service calculates an alert risk score from activity type, number and frequency of events, the user's risk history, and boosters, then maps that score to a severity level. You cannot customize that mapping. If you leave an alert untriaged and more risky activity accrues, severity can increase. High means serious, repetitive activity that correlates strongly with other significant risk factors. Medium is moderate, frequent activity with some correlation. Low is minor, more infrequent activity that does not correlate with other significant risk factors.

Classic Spotlight on the Standard dashboard automatically highlights alerts with a risk score of 85 or higher when at least three published conditions are also met (for example high-confidence device or Office insights, priority content or a potential high-impact user, a user manually brought into scope, or two or more high-confidence insights). Microsoft is retiring Spotlight in the unified Alerts (preview) experience after August 31, 2026; in that view, prioritize agent-triaged work with the Needs Attention filter instead.

Investigate before you confirm or dismiss

Open an alert and read the header: the activity that generated the alert, the triggering event that brought the user into policy scope, user details (anonymized if privacy settings require it), and user alert history for the last 30 days. The All risk factors tab summarizes cumulative exfiltration, priority content, sequences, unallowed domains, unusual activity for this user, health record access, risky browser usage, and top exfiltration activities. Filtering the queue by a risk factor does not mean the firing activity itself fell in that category—an alert can show sequence context even if the immediate event was a USB copy.

Activity explorer is the event-level timeline for the alert. Filter by activity scope (all scored activity for the user versus only this alert), risk factor, and review status (including Not yet reviewed, which hides activity that was already part of a dismissed or resolved alert). Content preview (preview) lets you inspect some SharePoint, Exchange, and OneDrive items during triage without creating a case—useful for false-positive checks. Preview is not supported for deletions, recycle-bin events, endpoint copy/print/USB, browser or removable-media events, metadata-only events, or renamed files.

The User activity tab is the investigation workhorse for both alerts and cases. It plots a historical timeline of alerts, the user's current risk score, and sequences of related events connected by lines so isolated-looking bubbles are not treated as one-offs. The default chart range is the last three months, with 1 month / 3 months / 6 months filters. You can filter by risk category (including activities with risk scores greater than 15, unless they are already in a sequence) and by activity type (Access, Deletion, Collection, Exfiltration, Infiltration, Obfuscation, Security, Custom Indicator, Defense Evasion, Privilege Escalation, Communication Risk, User Compromise Risk, and AI Usage). Sequence details include a combined sequence risk score and counts of related events, including links to associated files or email.

If Microsoft Sentinel integration is configured and usernames are not anonymized, the Data risk graph tab shows connections among users, files, and assets. The anonymized-usernames privacy setting blocks this graph.

Microsoft Copilot in Purview can summarize an alert from the queue or the details page (policy, activity, triggering event, user, last working date if applicable, and top risk factors). Suggested prompts include listing exfiltration or sequential activities and summarizing the last 10 or 30 days. Treat Copilot as acceleration, not as a substitute for Activity explorer. When the Triage Agent is enabled, it categorizes alerts as Needs attention or Less urgent. Microsoft publishes that the agent analyzes the most recent 30,000 activity events for the user and evaluates recorded activities broadly, not only the indicators on the policy that fired. Missing details are marked Not found by agent. You can flag incorrect categorization with Is this incorrect? (preview).

Confirm versus dismiss, then escalate to a case

Confirming is how an alert becomes a case. On the alert, use Actions > Confirm alerts & create case, or confirm the alert into an existing case for that user. Each case is one user. You can add multiple alerts for that same user to one case; you do not create a second case just because a second policy fired. When you create the case you name it, optionally add contributors and comments (comments become the first case note), and optionally enable content download. If the tenant is already at the published limit for cases with content downloaded, you can still create the case but must leave download off and enable it later if capacity returns.

Creating a case requires membership in Insider Risk Management or Insider Risk Management Investigators. The Analysts role group can access and investigate alerts and existing cases, dismiss alerts, and assign ownership, but cannot create the case. Admins configure policies and settings and cannot access or investigate alerts or cases. Auditors view and export audit logs; they do not triage. Approvers approve forensic evidence capturing requests; they do not run the alert queue. This split is a favorite exam trap: "can investigate" is not the same as "can confirm and create a case," and "can configure IRM" is not the same as "can open Content explorer."

Assignment follows the same three groups that can dismiss: Insider Risk Management, Analysts, and Investigators. You can assign an alert or case to yourself or to another user in those groups. One owner at a time. Microsoft Entra security groups are not supported as assignees; the person must be assigned the role directly. Custom role groups need the Case management role (already included in Analysts and Investigators).

Work the case

The Cases dashboard lists Case ID, name, Active or Closed status, user, content download on/off, time opened, total policy alerts, last activity, and last updated by. Opening a case surfaces Case overview (including the user's risk score, recalculated every 24 hours from active alerts associated with that user), Alerts, User activity, Activity explorer, Forensic evidence, Content explorer, Case notes, and Contributors.

Content explorer is Investigator and umbrella Insider Risk Management territory. After you confirm an alert, Content explorer shows nothing unless someone is in Insider Risk Management Investigators or Insider Risk Management. Analysts cannot use it. For new cases, content usually appears in about an hour (longer for large snapshots) and then refreshes daily. It holds a snapshot of SharePoint, Exchange, and OneDrive items while originals stay in place. You can export as PDF or original format. Documents associated with device-indicator activities are not included. Information Rights Management on copies is preserved, so Investigators still need those rights to open protected files.

Case notes are permanent: after save, you cannot edit or delete them. Microsoft publishes a preview limit of 50 manual notes per alert or case, not counting system-generated notes (status change, assignment change, closure, or escalation). Notes you typed when creating the case are stored here. There is no sync between IRM alert notes and Microsoft Defender.

Published retention and case caps (use these; do not invent others):

ItemPublished limit
Maximum active cases100
Active cases and associated artifactsRetained indefinitely (never expire)
Alerts in Needs review or Dismissed120 days from alert creation, then deleted
Resolved cases and artifacts120 days from case resolution, then deleted
User activities reports120 days from report creation, then deleted

IRM alerts can also appear in the Microsoft Defender portal when Share user risk details with other security solutions is turned on in IRM data-sharing settings. Defender New and In progress map to IRM Needs review; Defender True positive maps to Confirmed; expected activity and false positive map to Dismissed. Updates sync both ways, typically within 30 minutes. Full XDR hunting, DLP alert response, and SIEM export belong in the next chapter.

Exam traps

  • Do not treat DLP incident-report High/Medium/Low as something you type onto an IRM alert. IRM severity is calculated.
  • Do not assume Analysts can confirm an alert into a new case because they can open the Cases dashboard.
  • Do not wait forever on Needs review: untriaged alerts can climb in severity, and Needs review/Dismissed alerts are deleted after 120 days.
  • Do not expect endpoint USB/copy events to appear as files in Content explorer; that snapshot is Microsoft 365 service content.
Loading diagram...
IRM alert triage into cases, closure, and published retention
Test Your Knowledge

An Insider Risk Management Analyst reviews a High severity alert and wants to confirm it into a new case so Content explorer can capture the related SharePoint files. Which statement is correct?

A
B
C
D
Test Your Knowledge

A new IRM alert appears for a user and nobody has taken a triage action yet. What is the alert's status, and what do Confirm versus Dismiss do?

A
B
C
D
Test Your Knowledge

Which statement about IRM alert severity is accurate?

A
B
C
D