18.1 Create and Manage Insider Risk Management Policies
Key Takeaways
- Create Insider Risk Management policies in the Microsoft Purview portal under Insider Risk Management > Policies using either Quick policy or the full Create policy wizard.
- Included users and groups are watched for triggering events; excluded users and groups are never scored by that policy; a user becomes in-scope for risk scores only after a trigger or after Start scoring activity for users.
- You cannot change a policy name or template after creation; Start scoring activity for users lasts 5–30 days and supports up to 4,000 manually added users; deletion can take up to 72 hours and never deletes associated cases.
- Published in-scope user limits apply per template type (for example Data leaks 15,000 and Data theft by departing users 20,000), not to how many names you can list on the policy.
- Indicator thresholds and sequence detection are configured in the wizard; global indicators start disabled and must be turned on in Insider risk settings before a policy can select them.
18.1 Create and Manage Insider Risk Management Policies
Quick Answer: Create Insider Risk Management (IRM) policies in the Microsoft Purview portal at Insider Risk Management > Policies. The wizard binds a template to included users or groups, optional exclusions, priority content, triggering events, policy indicators, and indicator thresholds. People listed on the policy are candidates. They receive risk scores only after a triggering event—or after an admin uses Start scoring activity for users. Guest accounts are not supported. You cannot rename a policy or change its template after you create it.
IRM policies are the objects that decide who is eligible for scoring and which activities can raise alerts. Settings, indicators, and templates from the previous chapter are prerequisites. Until at least one policy exists, IRM has nothing to score. After you submit a policy, Microsoft documents that you typically start receiving alerts from activity indicators after about 24 hours.
This section stays on creating and managing the policy object. Confirming alerts, opening cases, and sending notice templates belong to the next chapter.
Policy dashboard
Sign in at purview.microsoft.com, open Insider Risk Management, and select Policies. The dashboard splits User policy and Agent policy. Agent policies cover Microsoft Copilot Studio and Microsoft Foundry agents. For SC-401, user policies are the operational focus.
Columns to recognize:
- Policy name — the friendly name from the wizard (locked after create).
- Status — Healthy, Recommendations, or Warnings. Select the policy to read the Notifications guidance.
- Active alerts — current open alerts for the policy.
- Confirmed alerts — alerts that became cases in the last 365 days.
- Actions taken on alerts — confirmed plus dismissed in the last 365 days.
- Policy alert effectiveness — confirmed alerts divided by actions taken over the past year.
You need the Insider Risk Management or Insider Risk Management Admins role group to see policy health. If a policy is scoped by administrative units, you only see health for policies in your units. Unrestricted administrators see every policy in the tenant.
Quick policies versus the full wizard
Create policy > Quick policy is the fast path when you are new to IRM or when analytics already pointed at a risk area. Microsoft documents these quick policies: Critical assets protection, Data leaks, Data theft from Microsoft 365 apps by users leaving your organization, Data theft from non-Microsoft 365 apps by users leaving your organization, and Email exfiltration. Settings populate from recommended best practices or from the latest analytics scan. You must be an unrestricted administrator to create quick policies. After creation you can still edit conditions, and you can subscribe to email when the policy has a warning or generates a high-severity alert.
The full Create policy workflow is what the exam tests in depth. Analytics can also offer a Get started jump into a matching quick policy after you review a data-leak or departing-user scan.
Walk the Create policy wizard
Template, name, and admin units
- Policy template. Choose a category, then a template. Review prerequisites, triggering events, and detected activities on that page. Templates that depend on the HR connector, a high-severity DLP policy, Defender for Endpoint alert sharing, or priority user groups will not score as expected if those prerequisites are missing. You cannot change the template later, so pick the right one (or copy the policy later and start a new template).
- Name and description. Name is required and cannot be changed after create. Description is optional and is the field you can update on Edit policy.
- Admin units (only if the tenant uses them). Scoped admins see only units assigned to their role. View my permissions summarizes your role groups and units. Priority-user-group templates cannot be combined with admin-unit scoping.
Users in scope versus excluded users
On Users and groups, choose one of these inclusion models:
- Include all users and groups. IRM watches the whole tenant (or the whole administrative unit, if the policy is unit-scoped) for triggering events. This option is required if you want real-time analytics estimates for indicator thresholds. Microsoft also notes that tenant-wide inclusion provides better overall protection.
- Include specific users and groups. Supported group types are Microsoft 365 groups, distribution groups, and security groups (mail-enabled and non-mail-enabled). Non-mail-enabled security groups cannot be selected when the policy is scoped by administrative units. If the policy is unit-scoped, you can choose only users inside that unit. Guest accounts are not supported.
- Adaptive scope. This control appears after you choose specific users and groups. Create the adaptive scope before the policy. Admin units further limit which adaptive scopes you can apply.
- Add or edit priority user groups. Appears for the Data leaks by priority users template. You must already have priority user groups in Insider risk settings. A priority user group can contain up to 10,000 users.
Then comes Exclude users and groups (optional) (preview). Exclusion is the exam trap. Example: include the whole organization but exclude executive-level sales managers. Select Add users to exclude or Add groups to exclude. If the policy is admin-unit scoped, you can exclude only identities inside that unit.
Treat these three populations as different:
| Population | What IRM does |
|---|---|
| Included users and groups | Watched for triggering events. Listing someone here does not by itself assign a risk score. |
| Excluded users and groups | Never scored by this policy, even if they are members of an included group. |
| In-scope for scoring | Users who already had a triggering event, or who were added with Start scoring activity for users. Published template limits apply to this population. |
You can add any number of users to a policy. Microsoft’s published limits apply to unique users receiving risk scores per template type (users brought in-scope after a trigger), not to the length of the include list. The Users in scope column on the Policies tab shows that scored count.
Priority content, triggers, indicators, and thresholds
On Content to prioritize, either skip priority content or prioritize SharePoint sites, sensitive information types, sensitivity labels, trainable classifiers (up to 5), and file extensions (up to 50, with or without the leading dot). The person running the wizard can select only SharePoint sites they can access; another admin can add sites later. Admin units do not filter the SharePoint picker.
On the scoring page, choose Get alerts for all activity or Get alerts only for activity that includes priority content. Cumulative exfiltration always receives a risk score, even when you choose priority-content-only scoring. If you score only priority content, Microsoft documents that no changes are applied to risk score boosters.
Triggers depend on the template:
- Data leaks and Data leaks by priority users: either User matches a data loss prevention (DLP) policy (the DLP policy must generate High severity alerts; Low or Medium will not bring users into IRM) or User performs an exfiltration activity plus one or more indicators. If an indicator is greyed out, it is not enabled globally—use Turn on indicators.
- Data leaks by risky users / Security policy violations by risky users: Communication Compliance risk triggers and/or HR connector events.
- Other templates use built-in triggers (HR employment dates, Microsoft Entra account deleted, Defender for Endpoint alerts, and similar). You still must select a triggering event; otherwise the policy never assigns scores.
For exfiltration triggers you can keep Use default thresholds (Recommended) or set custom thresholds, including Activity is above user's usual activity for the day when that anomalous option is enabled in Insider risk settings > Policy indicators.
On Policy indicators, select the indicators this policy should score. Global indicators start disabled; a policy cannot select an indicator that is off in settings. For data theft and data leaks templates, also enable sequence detection and cumulative exfiltration. Sequences are groups of two or more related activities in a defined order: Collection, Exfiltration, Obfuscation, and Clean-up. File names map activities across a sequence. An event you globally excluded from scoring (for example .png files) can still appear inside a sequence when it looks like obfuscation.
Cumulative exfiltration uses machine learning to compare a user’s sharing over time with organization norms (and, when Entra hierarchy and job titles exist, with SharePoint, similar-organization, and similar-job-title peer groups). It is enabled by default on the data-leak and departing-user data-theft templates.
On Decide whether to use default or custom indicator thresholds, keep defaults for all indicators or specify custom thresholds per indicator. View impact (when analytics is on) shows how many users a threshold would bring into scope. Microsoft’s published operational guidance is to start with built-in triggering thresholds and user-specific indicator thresholds, then customize if the policy produces no alerts.
Review and Submit create and activate the policy.
Policy timeframes are tenant settings, not wizard fields, but they control what the policy actually scores after a trigger: Activation window is 1–30 days after the trigger; Past activity detection is 0–90 days before the trigger for audit-log activities. Email lookback is 10 days. Configure those sliders under Insider risk settings > Policy timeframes.
Manage policies after creation
Edit policy updates the description, scope, exclusions, priority content, triggers, indicators, and thresholds. It does not unlock name or template.
Copy clones an existing policy so you can rename the copy and change the pieces that differ, instead of rebuilding the wizard from scratch.
Start scoring activity for users bypasses the triggering-event workflow. Select one or more policies, enter a Reason (it appears on the user’s activity timeline), set This should last for to 5–30 days, and add users or import a CSV of user principal names. Microsoft publishes a maximum of 4,000 users in scope from this feature. Typical uses: a named incident, risk concerns before the HR connector is live, or an urgent investigation. Manually added users can take several hours to appear on the Users dashboard; activities for the previous 90 days can take up to 24 hours to display.
Delete is irreversible and can take up to 72 hours. Choose Delete only the policy or Delete the policy and all associated alerts and users. Associated cases are never deleted. If a user is in more than one policy, deleting one policy removes them only from that policy. If the policy is the one Adaptive Protection is using, the portal warns that Adaptive Protection stops assigning insider risk levels until you choose a different policy.
Policy health and published limits
Status Warnings mean the policy may not identify risky activity. Common notifications: no users or groups; no indicators; no triggering event; DLP policy missing, turned off, or not High severity; HR connector not uploading for more than 7 days; Defender for Endpoint alerts not shared; no devices onboarded while device indicators are selected; no priority user groups on a priority-user template; triggering event firing for over 15% of users; approaching the template’s in-scope user limit.
Microsoft publishes these in-scope user limits per template type (summed across all policies that use that template). Confirm current numbers on Limits in Insider Risk Management; do not invent others.
| Template | In-scope user limit |
|---|---|
| Data leaks by priority users | 1,000 |
| Security policy violations / by priority users | 1,000 |
| Patient data misuse (preview) | 5,000 |
| Risky browser usage (preview) | 7,000 |
| Data leaks by risky users / Security policy violations by risky users | 7,500 |
| Risky AI usage | 10,000 |
| Data leaks / Security policy violations by departing users | 15,000 |
| Data theft by departing users | 20,000 |
| Forensic evidence | Unlimited |
Other published policy limits: 100 policies per template type; 50 priority file extensions, SITs, sensitivity labels, and sites; 5 priority trainable classifiers. Trigger volume per UTC day is also capped (custom indicators and HR connector signals 15,000 each, other triggers 5,000, organization maximum 50,000). If volume limits are near capacity, signal processing can delay.
Scenario
Contoso creates a Data leaks policy named “All-staff exfiltration,” includes all users, excludes the Board-Directors group, prioritizes the Project-Atlas SharePoint site plus the Confidential sensitivity label, uses User performs an exfiltration activity with default thresholds, and enables Office plus device indicators with sequence detection. A director in Board-Directors who emails a Confidential file outside the tenant is not scored. An engineer not in that group who copies Atlas files to USB can be brought in-scope after the exfiltration trigger and can generate a high-severity sequence insight. If legal later needs to score a contractor who has no trigger yet, an admin uses Start scoring activity for users for 14 days with a written reason—without waiting for DLP or HR events.
A Data leaks policy uses Include all users and groups and also lists the Executive-Leadership security group on Exclude users and groups. A vice president in Executive-Leadership emails a Confidential file to a personal Gmail account. How does this policy treat that vice president?
An Insider Risk Management admin needs to assign risk scores to three users today for a live incident, and none of those users has hit a policy triggering event. Which statement matches Microsoft’s published behavior for Start scoring activity for users?
After you create a Data leaks policy named Atlas-Exfil, which management statement is true?