17.3 Select an Appropriate Policy Template
Key Takeaways
- Every IRM policy must be assigned a template; Microsoft supports up to 100 policies per template type.
- Match the triggering event to the template: HR resignation/termination or Entra deletion for departing-user templates; High-severity DLP or custom exfiltration for Data leaks; Defender for Endpoint defense evasion for security-violation templates.
- Data leaks by priority users and Security policy violations by priority users require priority user groups created in IRM settings.
- Patient data misuse requires healthcare access indicators, an HR connector for address matching, and a Microsoft Healthcare or Epic connector—not a High-severity DLP trigger.
- Departing-user data theft and departing-user security violations are different templates: files leaving versus Defender for Endpoint malware or disabled security controls.
Templates are scoring models, not finished policies
An Insider Risk Management policy template is a predefined package of which triggering events matter and which risk scoring model to use. Every policy must have an assigned template in the creation workflow before the policy is created. Microsoft supports up to 100 policies for each policy template. This section is selection: match the business event to the template. Wizard steps, forensic evidence settings, Adaptive Protection insider-risk levels, and case workflow are later chapters.
Triggering events are the prerequisites that determine whether a user is active for a policy. If you add a user but no triggering event occurs, the policy does not evaluate that user's activity unless you manually add the user on the Users dashboard. Policy prerequisites are the connectors, indicators, and integrations the template needs in order to receive signals.
Microsoft publishes in-scope user limits per template type. You may add any number of users to a policy; the limit applies to users brought in scope after a triggering event. If you near or exceed the limit, policy performance reduces. Check Policies and the Users in scope column. These maximums apply across all policies that use a given template type.
| Template | Published in-scope user limit |
|---|---|
| Data leaks by priority users | 1,000 |
| Security policy violations by priority users | 1,000 |
| Security policy violations | 1,000 |
| Patient data misuse (preview) | 5,000 |
| Risky browser usage (preview) | 7,000 |
| Data leaks by risky users | 7,500 |
| Security policy violations by risky users | 7,500 |
| Risky AI usage | 10,000 |
| Data leaks | 15,000 |
| Security policy violations by departing users | 15,000 |
| Data theft by departing users | 20,000 |
| Forensic evidence | Unlimited |
Microsoft's published in-scope table does not list a number for Risky Agents (preview)—do not invent one. Forensic evidence appears in that limits table; configuring forensic evidence is a later chapter, not a substitute for a data-theft template.
Microsoft also publishes other policy caps used when you later build a policy (not when you merely pick a template): 50 priority file extensions, 50 priority sensitive info types, 50 priority sensitivity labels, 50 priority sites, and 5 priority trainable classifiers.
Match the triggering event to the template
This is the SC-401 skill: Select an appropriate policy template. Start from the event that should bring a user into scope, then pick the template whose trigger matches.
Data theft by departing users. Trigger: resignation or termination date from the HR connector or Microsoft Entra account deletion. The HR connector is optional if you use Entra deletion. The template scores exfiltration near leave dates: SharePoint Online downloads, printing, and copies to personal cloud messaging and storage. Cloud indicators can include Box, Dropbox, Google Drive, Amazon S3, and Azure.
Data leaks. Trigger: DLP policy activity that creates a High severity alert or built-in exfiltration event triggers you customize. Prerequisites: a DLP policy configured for High severity alerts on Exchange Online, SharePoint Online, or OneDrive for Business or customized triggering indicators. Low or Medium DLP Incident reports severity will not trigger IRM. Each IRM Data leaks policy can assign up to 20 DLP policies. Scope trap: only users included in both the DLP rule and the IRM policy are processed. Over-assigning High to non-exfiltration DLP rules (for example access-denied events) floods IRM with noise. Prefer a dedicated DLP policy that combines the exfiltration events you actually want as triggers.
Data leaks by priority users. Same trigger options as Data leaks, plus you must assign priority user groups from Settings. Scoring is more sensitive; alerts are more likely and tend to be higher severity.
Data leaks by risky users. Trigger: HR performance improvement, poor performance, or job level change and/or Communication Compliance messages with potentially threatening, harassing, or discriminatory language. You must configure the HR connector, Communication Compliance integration, or both. Associated Communication Compliance alerts do not need to be triaged, remediated, or changed in status before they feed IRM.
Patient data misuse (preview). Trigger: defense evasion of security controls from EMR systems and user and patient address matching indicators from HR systems. Prerequisites: healthcare access indicators selected in the policy or insider risk settings; HR connector configured for address matching; Microsoft Healthcare or Epic connector configured. Use this template for unauthorized access, viewing, modification, or export of patient data in EMR systems in support of HIPAA and HITECH safeguarding of protected health information.
Security policy violations. Trigger: defense evasion of security controls or unwanted software detected by Microsoft Defender for Endpoint. Requires an active Defender for Endpoint subscription and integration with the Microsoft Purview portal.
Security policy violations by departing users. Trigger: HR resignation/termination or Entra account deletion (HR optional if using Entra). Still requires Defender for Endpoint. Use this when the concern is malware or disabled security features, not file theft. File theft on the way out is Data theft by departing users.
Security policy violations by priority users. Trigger: Defender for Endpoint defense evasion or unwanted software. Requires Defender for Endpoint and priority user groups.
Security policy violations by risky users. Trigger: the same HR/Communication Compliance stressors as Data leaks by risky users. Requires those connectors and Defender for Endpoint.
AI, browser, and agent templates
Risky AI usage. Microsoft's trigger-and-prerequisite table leaves the triggering-events cell blank for this template—do not invent a fake trigger name. Prerequisites Microsoft does publish: the Microsoft Insider risk extension (Microsoft Edge) or Microsoft Purview extension (Chrome) must be installed; at least one browsing indicator selected in the policy; optionally an HR connector for termination and resignation dates; optionally a Communication Compliance policy that detects inappropriate content in messages. Detection focuses on browsing to generative AI websites and on user prompts and AI responses that contain sensitive information in Microsoft 365 Copilot, Microsoft Copilot, and agents. This policy's detections also contribute to user risk scoring in Adaptive Protection (configured in a later chapter). You can also create it as a one-click policy from Microsoft Purview Data Security Posture Management (DSPM) for AI when you act on Detect risky interactions in AI apps.
Risky browser usage (preview). Trigger: user browsing activity related to security that matches at least one selected Browsing indicator. Microsoft points you to the browser signal detection article for the full prerequisite list (device onboarding plus the Edge or Chrome extension). Use this template for acceptable-use violations such as phishing sites or adult content—not for SharePoint exfiltration (that is Data leaks / data theft) and not for EMR snooping (that is Patient data misuse).
Risky Agents (preview). Triggers Microsoft lists: exposing an agent to risky prompts, an agent generating sensitive responses, accessing sensitive or priority SharePoint files, accessing risky websites, sharing SharePoint files with people outside the organization, and activity above the agent's usual activity for the day. Prerequisites: Copilot Studio agents and Microsoft Foundry agents. Microsoft states this policy template is applied by default for all organizations.
Exam decision table
| If the scenario emphasizes... | Select |
|---|---|
| Employee resigns, is terminated, or the Entra account is deleted and files leave via USB, print, or cloud | Data theft by departing users |
| Same employment end and Defender for Endpoint shows disabled antivirus or unwanted software | Security policy violations by departing users |
| High-severity DLP alert or selected exfiltration on the general population | Data leaks |
| Same leak pattern but the population is executives, privileged admins, or a watch list | Data leaks by priority users |
| Performance improvement plan, poor review, demotion, or toxic messages then data leaving | Data leaks by risky users |
| Same stressors then Defender for Endpoint security violations | Security policy violations by risky users |
| Defender for Endpoint defense evasion for ordinary users, including a history of violations | Security policy violations |
| EMR snooping, neighbor or family record access, or PHI export | Patient data misuse |
| Copilot or AI prompts and responses that contain secrets | Risky AI usage |
| Users browsing malware, adult, or violence categories | Risky browser usage |
| Copilot Studio or Foundry agents leaking via tools or SharePoint | Risky Agents |
Sequence detection (two or more risky activities in a defined order) is supported on Data leaks, Data leaks by priority users, Data leaks by risky users, Data theft by departing users, and Risky AI usage. Priority content selection is supported on those same templates plus the same data-leak family. You choose sequences and priority content when you create the policy, not when you merely pick the template—but knowing which templates support them prevents you from picking Patient data misuse or a security-violation template when the scenario is a sequenced SharePoint exfiltration.
A collection policy can still starve device indicators after you pick the right template: if collection filters out the device activity, IRM never sees it.
Exam traps for templates
- Departing plus files is not departing plus Defender. Two different templates.
- Priority templates fail without a priority user group (policy health: "No priority user groups are included in this policy").
- Risky-user templates fail without the HR connector and/or Communication Compliance integration.
- Patient data misuse needs both HR address matching and a Healthcare or Epic connector—not High-severity DLP.
- Data leaks needs High DLP severity, supported workloads, and overlapping user scope. Each Data leaks policy can bind at most 20 DLP policies.
- Customizable triggers exist only on Data leaks and Data leaks by priority users.
- Do not pick Forensic evidence or Adaptive Protection as the answer to "which template detects departing-user theft."
- If a triggering event is not configured, Microsoft's policy health warning is that risk scores will not be assigned until you select a triggering event.
HR reports a resignation date next Friday. The security team is worried the engineer will download SharePoint project folders and copy them to a personal cloud drive before the last day. Which policy template should you select?
You created a Confidential Project Users priority user group in Insider Risk Management settings and assigned two reviewers. Which pair of templates requires that group to be assigned on the policy?
A hospital wants Insider Risk Management to score clinicians who open electronic medical records of family members or neighbors. Which prerequisite set matches the Patient data misuse template?