18.3 Enable Insider Risk Levels for Adaptive Protection

Key Takeaways

  • Adaptive Protection assigns Elevated, Moderate, or Minor insider risk levels in Insider Risk Management; those levels are not the same as Low/Medium/High alert severity.
  • Enable levels with Quick setup or Custom setup: pick an IRM policy, edit each level’s alert-based or activity-based conditions, then turn Adaptive Protection On.
  • Past activity detection and the insider risk level timeframe default to 7 days and can be set from 5 to 30 days; past activity detection applies only to activity-based conditions.
  • DLP, Conditional Access, and Data Lifecycle Management consume the levels; this exam skill is enabling the levels in IRM, not rebuilding DLP policy structure from earlier chapters.
  • Quick setup can take up to 72 hours; custom enablement can take up to 36 hours; turning Adaptive Protection Off resets levels and can take up to six hours, without auto-deleting the related policies.
Last updated: August 2026

18.3 Enable Insider Risk Levels for Adaptive Protection

Quick Answer: Adaptive Protection is enabled in Insider Risk Management > Adaptive protection. You assign an IRM policy, define Elevated, Moderate, and Minor insider risk levels, then turn Adaptive Protection On. Those levels are not alert severity. Downstream DLP uses the condition User's insider risk level for Adaptive Protection is; Data Lifecycle Management can preserve content deleted by Elevated users for 120 days; Conditional Access can require a matching insider risk level. Building DLP rule trees was an earlier skill—here the job is to enable and tune the levels in IRM so those controls have something to consume.

Adaptive Protection uses machine learning over IRM signals to identify the most critical risks and then dynamically apply prevention. Context-aware detection, dynamic controls, and automated mitigation are the three outcomes Microsoft emphasizes. IRM is available in commercial clouds in Azure-supported regions and is not available for US Government cloud programs. Confirm licensing on Microsoft’s subscription matrix; Adaptive Protection with DLP, Data Lifecycle Management, and Conditional Access is not a free add-on you should invent a price for.

Insider risk levels versus alert severity

ConceptValuesWhat it measures
Insider risk levels (Adaptive Protection)Elevated, Moderate, MinorAdmin-defined conditions such as high-severity alerts, confirmed alerts, or a count of daily activity insights
Alert severity (IRM triage)Low, Medium, HighScore calculated from active IRM alerts so analysts can prioritize work

If you treat “Elevated” as a synonym for “High alert,” you will miss exam items. A user can have a High severity IRM alert and still not meet your custom Elevated definition, or can meet Elevated from three high-severity sequence insights without you ever opening the Alerts dashboard in this chapter’s workflow.

Built-in level definitions Microsoft publishes:

  • Elevated: users with high severity alerts; users with at least three sequence insights that each have a high severity alert for specific risk activities; or one or more confirmed high severity alerts.
  • Moderate: users with medium severity alerts; or users with at least two data exfiltration activities with high severity scores.
  • Minor: users with low severity alerts; or users with at least one data exfiltration activity with a high severity score.

Levels are based on insights, not raw event counts. If a policy watches SharePoint downloads and a user downloads 10 files in one day that score high severity, that is one insight containing 10 events. A built-in Elevated definition that wants three high-severity sequence insights still needs two additional insights, not two additional files.

If a user is in scope for multiple IRM policies selected in Adaptive Protection and receives different alert severities, Adaptive Protection assigns the highest matching level. A condition such as Copy to USB for Moderate fires only from policies that actually score Copy to USB.

Customize Elevated, Moderate, and Minor

Path: Insider Risk Management > Adaptive protection > Insider risk levels. Select the IRM policy (or policies) Adaptive Protection should read, then Edit on Elevated, Moderate, or Minor.

Insider risk level based on has two modes:

  • Alert generated or confirmed for a user. Choose severity for generated alerts and/or confirmed alerts (High, Medium, or Low). These conditions are not additive: if any selected condition is met, the level is assigned. You can remove one condition and add it back with Add condition.
  • Specific user activity. Configure Activities (the list follows indicators in the selected IRM policy), Activity severity (High / Medium / Low from risk-score ranges), and Activity occurrences during detection window. These conditions are additive: all must be met. Optionally select Assign this insider risk level to any user who has a future alert confirmed, even if conditions above aren't met. Remember that “occurrences” counts daily insights, not files inside an insight.

Two timeframe sliders sit next to the level definitions:

  • Past activity detection. How many days back Adaptive Protection looks when the level is based on daily activity. Default 7 days; choose 5–30. This setting does not apply to alert-based levels. Microsoft’s example: Elevated requires three high-severity sequences and past detection is 3 days. Sequences on T-3, T-2, and T-1 are in scope; one sequence on T-4 plus two on T-3 is not.
  • Insider risk level timeframe. How long a level stays assigned before it automatically resets. Default 7 days; choose 5–30. The level also resets when the associated alert is dismissed, the associated case is resolved, or an admin Expires the level on Users assigned insider risk levels. If the user meets the same level’s criteria again, the timeframe extends by the defined number of days.

Risk level expiration options: automatic expiration when an alert is dismissed or a case is closed is on by default. Disable it if you need the Adaptive Protection level to survive triage. That choice is an IRM-level setting, not a DLP rule.

Quick setup versus custom setup

Quick setup is the fastest path when you do not already have IRM, DLP, Data Lifecycle Management, or Conditional Access policies. Start from the Adaptive Protection cards, the DLP Overview card, or Adaptive protection > Dashboard > Quick setup. Scoped admins cannot turn on quick setup.

What quick setup configures (do not memorize unpublished extras):

  • A Data leaks IRM policy named Adaptive Protection policy for Insider Risk Management, scoped to all users and groups, with selected exfiltration triggering events, a subset of Office indicators, and the activity is over user's usual activity for that day booster.
  • Built-in Adaptive Protection levels: Elevated = at least three high severity exfiltration sequences; Moderate = at least two high severity activities (excluding some download types); Minor = at least one high severity activity (excluding some download types).
  • Analytics on; if IRM settings were empty, privacy anonymization, default timeframes, default alert volume, and first-alert admin email.
  • Two DLP policies in test (audit only) mode: Adaptive Protection policy for Endpoint DLP and Adaptive Protection policy for Teams and Exchange DLP, blocking Elevated and auditing Moderate/Minor.
  • A Conditional Access policy in Report-only mode that blocks Elevated users from Office 365 apps.
  • An organization-wide Data Lifecycle Management auto-apply label policy that preserves SharePoint, OneDrive, or Exchange Online content deleted by Elevated users for 120 days. Admins contact Microsoft support to restore preserved content.

Quick setup can take up to 72 hours. Administrators receive email when it completes. Do not disable Adaptive Protection before setup finishes—Microsoft warns that doing so can cause policy errors.

Custom setup is the exam path when IRM already exists. Steps Microsoft documents:

  1. Create or choose an IRM policy whose users, indicators, and thresholds match the risk you want Adaptive Protection to read. Create insider risk policy preselects Data leaks, but you may use any template. Complete that template’s prerequisites (HR connector, DLP trigger, and similar) or Adaptive Protection will have no insights to convert into levels.
  2. Configure insider risk level settings as described above.
  3. Optionally create or edit DLP / Conditional Access policies that consume the levels. You already learned DLP construction; the Adaptive Protection-specific pieces are the condition User's insider risk level for Adaptive Protection is (values Elevated, Moderate, Minor) and the current location support: Exchange, Microsoft Teams, and devices. Test DLP with policy tips before you rely on enforcement.
  4. Turn Adaptive Protection On at Adaptive Protection settings. Microsoft documents up to 36 hours before levels and downstream actions apply.

For Data Lifecycle Management, if Adaptive Protection was already on, you may need to explicitly opt in to the automatically created retention label policy. You can later turn off Adaptive protection in Data Lifecycle Management without disabling Adaptive Protection; that deletes the DLM policy and it stays off until you enable the setting again.

Permissions, dashboard, and disable

TaskRole group
Configure Adaptive Protection and update settingsInsider Risk Management or Insider Risk Management Admins
View users’ assigned insider risk levelsInsider Risk Management, Analysts, or Investigators
Create/manage DLP policies with the Adaptive Protection conditionCompliance Administrator, Compliance Data Administrator, DLP Compliance Management, or Global Administrator
Create/manage Conditional Access policies with the Insider risk conditionGlobal administrator, Conditional Access Administrator, or Security Administrator

The Adaptive Protection page tabs (Insider risk levels, Users assigned insider risk levels, Data Loss Prevention, Conditional Access) hide if you lack the matching role group.

After enablement, Users assigned insider risk levels shows each user, current level, days since assignment, days until reset, active alerts, and confirmed-violation cases. Expire clears the Adaptive Protection level without deleting IRM alerts or cases. If the user is still in the selected IRM policy, a new triggering event can assign a level again. Filter the list by level when you are tuning thresholds.

Privacy trap: if IRM Show anonymized versions of usernames is on, Adaptive Protection’s IRM views can stay anonymized, but Conditional Access does not anonymize, and referential integrity means actual names appear in related DLP alerts and activity explorer. Do not promise anonymization across the whole Adaptive Protection stack.

Microsoft publishes a limit of 10,000 users in a DLP policy for each risk level. If too many or too few users receive levels, either edit the level conditions (severity, occurrence count, alert-confirmed versus activity-based) or edit the underlying IRM policy thresholds that produce High/Medium/Low insights.

Disable Adaptive Protection from Adaptive Protection settings > Off. The system stops assigning and sharing levels; existing levels reset; Microsoft documents up to six hours. IRM, DLP, Data Lifecycle Management, and Conditional Access policies are not automatically deleted.

Scenario

Tailwind Traders already has a Data leaks IRM policy on all employees. An information security administrator opens Adaptive protection, selects that policy, sets Elevated to confirmed high severity alerts, Moderate to two high-severity exfiltration insights in the past 7 days, and Minor to one high-severity insight, leaves past activity detection and the level timeframe at the 7-day defaults, and turns Adaptive Protection On. Thirty hours later a researcher who produced two high-severity USB insights appears as Moderate. Existing DLP policies that include User's insider risk level for Adaptive Protection is Moderate begin auditing that researcher’s Endpoint activity. The administrator does not rebuild those DLP policies here—they only confirm the IRM level is flowing. When the IRM case is later resolved, the Moderate level expires automatically unless the admin disabled automatic expiration.

Loading diagram...
IRM insider risk levels feeding DLP, DLM, and Conditional Access
Test Your Knowledge

How do Adaptive Protection insider risk levels differ from Insider Risk Management alert severity?

A
B
C
D
Test Your Knowledge

You already have a production Data leaks Insider Risk Management policy. What is the custom-setup sequence to start assigning Adaptive Protection levels from that policy?

A
B
C
D
Test Your Knowledge

Which statement about Adaptive Protection past activity detection and the insider risk level timeframe is published by Microsoft?

A
B
C
D