18.2 Manage Forensic Evidence Settings
Key Takeaways
- Forensic evidence is an opt-in add-on; capturing is off by default, and adding users requires dual authorization from Insider Risk Management Approvers.
- Tenant settings set the capturing window (10 seconds to 5 minutes) and per-user upload bandwidth plus offline cache (100 MB, 250 MB, 500 MB, 1 GB, or 2 GB).
- Privacy controls include optional user-notification templates after approval, include/exclude lists for desktop apps and URLs (up to 25 each), pseudonymization, RBAC, and 120-day clip retention.
- Browsing capture requires Purview browser extensions plus at least one browsing indicator; the browsing trigger is a URL-bar update that contains the specified URL.
- Devices must be Windows 10/11 Enterprise 64-bit, onboarded to Purview, and running the Microsoft Purview Client; trial capacity is 20 GB and paid capacity is sold in 100 GB per month units.
18.2 Manage Forensic Evidence Settings
Quick Answer: Forensic evidence is an opt-in add-on. Capturing is off by default. Turn it on at Insider Risk Management > Forensic evidence > Forensic evidence settings, set the capturing window and bandwidth limits, create a forensic evidence policy that includes or excludes apps and URLs, then use dual authorization so an Insider Risk Management Approver approves each user. Microsoft does not document a Windows “I agree” consent checkbox; privacy is implemented with off-by-default capture, approver dual control, optional notification email, include/exclude lists, and 120-day clip deletion.
Visual clips give investigators context that audit events cannot: what was on screen when a user copied SecretResearchPlans.docx to USB, or whether a browser session was a phishing site rather than a legitimate vendor portal. That power is why forensic evidence is not just another IRM policy template. It is a separate, capacity-metered feature with its own settings, client, and approval workflow.
Turn capturing on and set the numeric controls
In the Purview portal, go to Insider Risk Management > Forensic evidence > Forensic evidence settings.
- Forensic evidence capturing. This is the master switch. If you turn it off, Microsoft documents that the action removes all previously added users from forensic evidence policies. Do not treat this toggle as a quiet pause.
- Capturing window. Defines when capture starts and stops around activity. Published values: 10 seconds, 30 seconds, 1 minute, 3 minutes, or 5 minutes. Microsoft’s own example of incident-based capture is “5 minutes before and 10 minutes after” a sensitive download as a policy-design illustration; the settings page itself exposes the window values in the list above. Do not invent other durations.
- Upload bandwidth limit. Amount of capture data uploaded per user, per day. Published values: 100 MB, 250 MB, 500 MB, 1 GB, or 2 GB.
- Offline capturing cache limit. Maximum cache on the device when the client is offline. Same published size menu as upload bandwidth.
- Select Save.
Device health uses these caps as operational signals. At 90% of the configured upload bandwidth or offline cache, the client warns that captures might be overwritten soon. When the configured upload bandwidth limit is reached, no more captures are uploaded for the day. When the offline storage limit is reached, offline captures are overwritten. The remediation Microsoft documents is to increase the matching limit on the Forensic evidence settings page—not to guess an unpublished “unlimited” SKU.
The Microsoft Purview Client is licensed under Microsoft Product Terms. Customers are solely responsible for using Insider Risk Management, including the client, in compliance with applicable law. That legal sentence is part of the product documentation, not optional marketing.
Dual authorization, notification, and privacy
Adding a user to a forensic evidence policy does not make that user eligible for clips. Eligibility is a two-person control:
- Members of Insider Risk Management or Insider Risk Management Admins submit a capturing request (Forensic evidence > User management > Manage forensic evidence requests > Create request).
- Members of Insider Risk Management Approvers approve or reject it from Pending requests. Approvers typically sit in legal, HR, or a designated privacy function.
The request workflow asks for users, a forensic evidence policy (this policy decides what to capture), a required justification, and optionally Send an email notification to approved users. The email uses a notification template (template name, send from, subject, message body) created under Forensic evidence > Notification templates. The mail is sent only if the request is approved. If nobody acts, the request expires six months from the day it was submitted.
This is the exam-correct story for “consent.” Microsoft does not publish a per-device Windows consent prompt as a prerequisite. Organizations that need explicit employee notice use the optional notification template plus their own HR/legal process. Usernames can remain pseudonymized (the IRM default). RBAC separates who can request capture, who can approve it, who can review clips (Insider Risk Management Investigators), and who can bulk-delete a user’s forensic data (Insider Risk Management Admins, and only if Allow deletion of forensic user data by an Administrator or Investigator is On).
Approvers revoke a user from Approved users > Remove. Revoke stops future capturing; it does not delete existing clips. Clips are deleted 120 days after they are captured (or at the end of a preview period, whichever is sooner). Export or transfer clips before that date if you still need them. Investigators can delete individual clips; admins can bulk-delete a user’s forensic data from settings after choosing that user.
Capturing apps, websites, and policy scope
Create policies at Forensic evidence > Forensic evidence policies > Create forensic evidence policy. Continuous (All activities) policies take precedence over selective (Specific activities) policies.
Specific activities captures only when an approved user is in-scope for the forensic evidence policy and a selected device indicator fires—for example copying to personal cloud storage or a portable drive. Review those clips on the Forensic evidence tab of an alert or case. On Choose device activities to capture, select the device indicators you want. If they are not selectable, turn them on when prompted.
To focus on risky apps and sites, select Opening a specific app or website under app and web browsing activities. Then add desktop executables and URLs:
- Up to 25 desktop apps, identified by executable name (
teams.exe,WinWord.exe,msedge.exe,Excel.exe,SnippingTool.exe,mstsc.exe). Find names in Task Manager. Elevation can change the exe (WindowsTerminal.exeversuspowershell.exe)—include both when that happens. - Up to 25 web apps or websites, each URL up to 100 characters (for example
https://teams.microsoft.com). - If an app has desktop and web versions, add both the exe and the URL.
Browsing capture has extra prerequisites. Install the Edge add-on or Chrome extension documented for Insider Risk Management browser signal detection, and turn on at least one browsing indicator. The triggering event for browsing capture is a URL update in the URL bar that contains the specified URL. Enhanced Phishing Protection (preview) can also capture SmartScreen-related clips, such as a user entering their Windows 11 Microsoft password on a phishing site.
All activities captures any activity an approved user performs—typically for a short, high-risk window when indicators might not have reached an alert threshold yet. Review those clips on User activity reports. To protect privacy and capacity, you may Exclude specific apps or websites (same 25 exe / 25 URL caps). Common exclusions are personal webmail and social media.
After policy creation, enforcement can take up to two hours once clients are online. After the client captures a clip, it can take up to one hour before the clip is available to review.
Devices, client, capacity, and health
Supported platforms are Windows 10 and Windows 11 Enterprise, 64-bit (Intel or AMD), including Windows 365. Physical device minimums Microsoft publishes: 8 GB RAM (at least 2 GB free for the client), Intel i5 or AMD Ryzen 5 or higher, a DirectX 11+ GPU with WDDM 1.0 or later—integrated graphics only; discrete GPUs, including NVIDIA RTX PRO series, are not supported—10 GB disk, and 1920 × 1080 display. Hyper-V/VM minimums: 16 GB RAM, eight vCPUs, same disk and display. If you miss these, client issues and unreliable capture quality are expected.
Devices must be onboarded to the Microsoft Purview portal and must have the Microsoft Purview Client installed (Forensic evidence > Client installation). Deploy with Intune or your existing device-management tool. Allowlist the documented storage domains (compliancedrive.microsoft.com worldwide, plus the GCC/DOD variants). Capture data is stored in the region where Exchange Online is set and is assigned only to your tenant. The client also sends diagnostic data (crashes, RAM, process failures) so Microsoft can assess client health.
Capacity is metered at tenant ingest. Organizations with Microsoft 365 E5, Microsoft Purview Suite (formerly Microsoft 365 E5 Compliance), or Microsoft 365 E5 Insider Risk Management can claim a 20 GB trial on the legacy commerce platform (until capacity is used or one year from activation). The paid add-on is sold in units of 100 GB per month. Microsoft estimates 100 GB ≈ 1,100 hours of capture at 1080p. Purchased capacity applies from the purchase date and resets on the first of the month; unused capacity does not carry over. After ingest, the system retains clips 120 days. If trial capacity is exhausted without a paid add-on, you can still view ingested clips but cannot ingest new ones. Use Forensic evidence > Capacity and billing and Microsoft’s Forensic evidence capacity calculator rather than inventing hours-per-user figures.
Device health (preview) at Forensic evidence > Device health shows devices online/offline and devices with warnings or errors for the last 24 hours. Status details you should recognize: GPU/CPU/memory over threshold (capture stops and restarts), no graphics card, monitors off or missing, client not synced for over 24 hours, directory access failure, and the bandwidth/cache 90% / 100% messages already described.
Scenario
A departing firmware engineer is suspected of staging source code. An IRM admin creates a Specific activities forensic policy that captures removable-media and cloud-exfil indicators and includes WinWord.exe, devenv.exe, and https://github.com, while excluding personal webmail URLs. The admin submits a request with a written legal justification and a notification template. An Approver in HR approves. The user’s Windows 11 Enterprise laptop already has the Purview Client. When the engineer copies a repository archive to USB, the client records the configured capturing window, uploads within the 500 MB daily cap, and an investigator later reviews the clip from the alert’s Forensic evidence tab. If the admin had only added the engineer to a Data leaks IRM policy, no clip would exist—dual authorization never ran.
What must be true before Insider Risk Management forensic evidence can capture clips for a specific user?
How do forensic evidence upload bandwidth and offline cache limits behave?
An admin wants a specific-activities forensic evidence policy to record visits to an internal wiki and use of Microsoft Word. Which configuration matches Microsoft Learn?