16.3 Integrate Insider Risk Management with Microsoft Defender for Endpoint

Key Takeaways

  • Insider Risk Management security policy violation templates use Microsoft Defender for Endpoint alerts to score intentional or unintentional security-control violations such as installing unwanted software or disabling device security features.
  • You must have an active Microsoft Defender for Endpoint subscription and enable Defender for Endpoint for Insider Risk Management integration in the Defender portal under Settings > Endpoints > Advanced features.
  • The published advanced-feature toggle is Share endpoint alerts with Microsoft Compliance Center; forwarded alert data is stored in the same location as your Office 365 data.
  • In Insider Risk Management Intelligent detections, import Defender for Endpoint alerts by triage status: Unknown, New, In progress, and/or Resolved.
  • Defender for Endpoint alerts are imported daily; if you select multiple triage statuses, Insider Risk Management can import multiple user activities for the same alert as the triage status changes.
Last updated: August 2026

Users in a modern workplace often have permission to install software or temporarily disable device security features so they can do their jobs. Whether that behavior is accidental, convenient, or malicious, it can weaken the organization. Microsoft Purview Insider Risk Management does not replace Microsoft Defender for Endpoint as an EDR product. For security policy violation scenarios, IRM imports Defender for Endpoint alerts and then scores those security-related activities in the insider-risk model—next to exfiltration, HR stressors, and other signals.

The SC-401 skill is plan and implement integration with Microsoft Defender for Endpoint. That means you must know where the toggle lives, which IRM templates depend on it, how triage-status filtering works, and why a policy can look “empty” when sharing is off or the filter is too narrow. Detailed IRM indicator catalogs, template authoring, forensic evidence, Adaptive Protection levels, and case workflow belong to later chapters. This section stays on the integration contract.

Why the integration exists

Microsoft describes a family of IRM templates for intentional or unintentional security policy violations. Typical endpoint behaviors include installing malware or other potentially harmful applications and disabling security features. Defender for Endpoint is the enterprise platform that prevents, detects, investigates, and responds to advanced threats on devices. IRM’s job is to place those security-violation alerts in an insider-risk context: the same user who just turned off antivirus may also be a departing employee, a priority user, or someone on a performance improvement plan.

Four published templates require this integration:

TemplateWhat MDE contributesExtra planning dependency
Security policy violationsDefense evasion of security controls or unwanted software detected by Defender for EndpointActive MDE subscription plus IRM integration
Security policy violations by departing usersSame MDE security alerts, scored against employment statusHR connector or Microsoft Entra account deletion as the trigger
Security policy violations by risky usersSame MDE security alerts, scored against employment stressorsHR connector and/or Communication Compliance risky-user signals, and MDE integration
Security policy violations by priority usersSame MDE security alerts for high-impact identitiesMDE integration and priority user groups assigned to the policy

Microsoft’s troubleshooting article is blunt: if Microsoft Defender for Endpoint alerts are not being shared with the Microsoft Purview portal, security-violation policies will not receive those alerts. If a security-violation policy is not assigning risk scores, one published check is that the alert triage status filter in Intelligent detections is not too narrow.

You also need to meet Defender for Endpoint’s own minimum requirements (supported operating systems, onboarding, licensing). Microsoft does not publish an SC-401-specific device count or alert-volume quota for this integration. Do not invent one. Confirm an active Microsoft Defender for Endpoint subscription and a supported onboarding state; then enable sharing.

Defender portal: turn on alert sharing

Enable the integration in the Microsoft Defender portal (IRM articles still say “Defender Security Center” in places; the current path is the Defender portal):

  1. Sign in to the Microsoft Defender portal.
  2. Go to Settings > Endpoints > Advanced features.
  3. Locate Share endpoint alerts with Microsoft Compliance Center.
  4. Toggle the setting On.
  5. Select Save preferences.

Microsoft’s description of this advanced feature is the sentence you should be able to quote: the endpoint alert sharing setting sends endpoint security alerts and their triage status to the Microsoft Purview portal. You can use those alerts to improve insider risk management policies and address internal risks before they cause harm. Forwarded data is stored in the same location as your Office 365 data. That storage statement matters for residency conversations: this is not a separate “Defender-only” copy in an unpublished region; it follows the Office 365 data location.

Sharing does not start scoring by itself. Microsoft says that after you set up the Security policy violation indicators in Insider Risk Management settings, Defender for Endpoint shares alerts with insider risk management for applicable users. In other words, the Defender toggle is necessary but not sufficient. An IRM admin still has to opt in to the security-violation indicators (admin explicit opt-in from the previous section) and later create a policy from a security-violation template. You will configure those indicators and templates in the next IRM chapters; for this skill, remember the two-sided handshake: Defender sharing and IRM security-violation indicators.

Do not confuse this toggle with neighboring advanced features that are not the IRM integration:

  • Microsoft Defender for Cloud Apps integration forwards Defender for Endpoint signals to Defender for Cloud Apps for cloud-app visibility. That is not IRM.
  • Microsoft Intune connection shares device data for device-risk Conditional Access. That is not IRM.
  • Automatically resolve alerts changes how Defender itself closes alerts. It is not the IRM connector, but it does change triage status, which does affect what IRM imports.

Auto-resolve interaction. If Defender auto-resolves alerts where no threat was found or where threats were remediated, those alerts can move to Resolved without an analyst clicking anything. If your IRM import filter includes only New, you may never see alerts that auto-resolve quickly. If your filter includes Resolved, IRM will ingest those closed alerts as activities. If a SOC analyst manually sets status to In progress or Resolved, auto-resolve will not overwrite that manual status. Plan the IRM triage filter with your SOC’s auto-resolve setting in mind.

Purview portal: import by Defender triage status

The IRM side of the integration is Intelligent detections, documented as the setting that lets you import and filter Defender for Endpoint alerts for activities used in policies created from Insider Risk Management security violation policy templates.

Path: Microsoft Purview portal → Settings (upper-right) → Insider Risk ManagementIntelligent detectionsMicrosoft Defender for Endpoint alert statuses.

You can define one or more of the following alert triage statuses to import:

  • Unknown
  • New
  • In progress
  • Resolved

Those four values are the published list. Exam distractors often invent severity names (Critical, High) or IRM alert statuses (Needs review, Confirmed). Severity is not the import filter. Triage status is the import filter.

Alerts from Defender for Endpoint are imported daily. This is not a documented real-time streaming pipe. Plan investigations with a daily latency. If a question asks when an IRM analyst should expect a newly raised Defender alert to appear as IRM activity, the published answer is daily import, not “immediately in the same minute.”

Multiple activities for one alert. Depending on the triage statuses you choose, you might see multiple user activities for the same alert as the triage status changes in Defender for Endpoint. Microsoft’s example: if you select New, In progress, and Resolved, then:

  1. When the Defender alert is generated with status New, IRM imports an initial activity for the user.
  2. When SOC changes the status to In progress, IRM imports a second activity for the same alert.
  3. When the status becomes Resolved, IRM imports a third activity.

This is intentional. It lets investigators follow the progression of the Defender alert and choose the level of visibility their investigation requires. It is also how you accidentally inflate IRM activity volume: import every status and every SOC click becomes another scored activity.

Planning the triage filter

Import choiceWhat IRM seesWhen to use itRisk
New onlyOpening of the alertYou want only freshly raised endpoint detectionsYou miss alerts that skip New or auto-resolve
New + In progressOpen investigation lifecycleYou want visibility while SOC works the alert, but not closuresYou miss the Resolved signal that the endpoint issue is done
Resolved onlyClosures, including auto-resolved itemsYou want confirmed/completed endpoint eventsYou miss in-flight attacks and may import noise from mass auto-resolve
Unknown + New + In progress + ResolvedFull lifecycle, multiple activities per alertYou want maximum visibility for insider investigationsHighest duplicate-activity volume

There is no published “best” combination. Microsoft’s language is that you choose statuses based on the types of signals you are interested in. For SC-401, be ready to defend a choice (for example: import New and In progress to watch live defense-evasion without scoring every Resolved true-positive cleanup) rather than memorize a secret default Microsoft does not publish.

Intelligent detections also contains unrelated controls—boosting unusual download scores, alert-volume sliders, unallowed domains (up to 500), and third-party domains (up to 500). Those are IRM settings you will study in the next chapter. Do not configure them as a substitute for the Defender toggle. Unallowed domains do not import MDE alerts.

End-to-end planning sequence

Use this sequence when an exam scenario asks you to implement MDE integration for IRM:

  1. Confirm licensing and onboarding: supported Microsoft 365 subscription for IRM, active Defender for Endpoint subscription, devices onboarded, minimum requirements met.
  2. In the Defender portal, enable Share endpoint alerts with Microsoft Compliance Center and save preferences.
  3. In Purview, assign Insider Risk Management or Insider Risk Management Admins so someone can change IRM settings (Analysts and Investigators cannot configure this integration).
  4. In Intelligent detections, select the Defender for Endpoint alert triage statuses to import.
  5. Later (next chapters): enable security policy violation indicators, then create a policy from the appropriate security policy violations template. Add HR or priority user groups if you chose a departing, risky, or priority variant.
  6. Validate with Microsoft’s published failure modes: sharing not configured; devices not onboarded; triage filter too narrow; security-violation indicators not selected.

What this integration is not

  • It is not the preview that shares IRM user risk levels into Defender and DLP alerts. That is a different data-sharing setting (IRM → Defender), documented as analyzing activity over 90–120 days. This skill is Defender → IRM alert import for security-violation templates.
  • It is not investigating IRM alerts inside the Microsoft Defender XDR portal. That XDR experience has its own role requirements (Security Operator/Reader plus IRM Analysts or Investigators) and belongs with later alert-response content.
  • It is not Endpoint DLP. Endpoint DLP is a different Purview capability. Virtualized environments that Endpoint DLP supports can feed IRM device indicators, but that is not the MDE security-violation import path.
  • It is not forensic evidence. Investigators may later view forensic captures if that feature is configured, but MDE alert import does not turn on screen capture.

If Microsoft has not published a numeric limit (maximum MDE alerts imported per day, maximum devices, maximum security-violation policies that can consume MDE), do not invent one. Teach the toggle, the four triage statuses, the daily import, and the four security-violation templates that depend on the integration.

Loading diagram...
Defender for Endpoint alert sharing into Insider Risk Management
Test Your Knowledge

Where do you enable Microsoft Defender for Endpoint to send endpoint security alerts and their triage status into Microsoft Purview for Insider Risk Management?

A
B
C
D
Test Your Knowledge

An Insider Risk Management admin is filtering which Microsoft Defender for Endpoint alerts to import for security policy violation policies. Which set of values can be selected in Intelligent detections?

A
B
C
D
Test Your Knowledge

You select New, In progress, and Resolved as the Defender for Endpoint triage statuses to import into Insider Risk Management. What does Microsoft publish about how those alerts arrive?

A
B
C
D