17.3 Select an Appropriate Policy Template

Key Takeaways

  • Every IRM policy must be assigned a template; Microsoft supports up to 100 policies per template type.
  • Match the triggering event to the template: HR resignation/termination or Entra deletion for departing-user templates; High-severity DLP or custom exfiltration for Data leaks; Defender for Endpoint defense evasion for security-violation templates.
  • Data leaks by priority users and Security policy violations by priority users require priority user groups created in IRM settings.
  • Patient data misuse requires healthcare access indicators, an HR connector for address matching, and a Microsoft Healthcare or Epic connector—not a High-severity DLP trigger.
  • Departing-user data theft and departing-user security violations are different templates: files leaving versus Defender for Endpoint malware or disabled security controls.
Last updated: August 2026

Templates are scoring models, not finished policies

An Insider Risk Management policy template is a predefined package of which triggering events matter and which risk scoring model to use. Every policy must have an assigned template in the creation workflow before the policy is created. Microsoft supports up to 100 policies for each policy template. This section is selection: match the business event to the template. Wizard steps, forensic evidence settings, Adaptive Protection insider-risk levels, and case workflow are later chapters.

Triggering events are the prerequisites that determine whether a user is active for a policy. If you add a user but no triggering event occurs, the policy does not evaluate that user's activity unless you manually add the user on the Users dashboard. Policy prerequisites are the connectors, indicators, and integrations the template needs in order to receive signals.

Microsoft publishes in-scope user limits per template type. You may add any number of users to a policy; the limit applies to users brought in scope after a triggering event. If you near or exceed the limit, policy performance reduces. Check Policies and the Users in scope column. These maximums apply across all policies that use a given template type.

TemplatePublished in-scope user limit
Data leaks by priority users1,000
Security policy violations by priority users1,000
Security policy violations1,000
Patient data misuse (preview)5,000
Risky browser usage (preview)7,000
Data leaks by risky users7,500
Security policy violations by risky users7,500
Risky AI usage10,000
Data leaks15,000
Security policy violations by departing users15,000
Data theft by departing users20,000
Forensic evidenceUnlimited

Microsoft's published in-scope table does not list a number for Risky Agents (preview)—do not invent one. Forensic evidence appears in that limits table; configuring forensic evidence is a later chapter, not a substitute for a data-theft template.

Microsoft also publishes other policy caps used when you later build a policy (not when you merely pick a template): 50 priority file extensions, 50 priority sensitive info types, 50 priority sensitivity labels, 50 priority sites, and 5 priority trainable classifiers.

Match the triggering event to the template

This is the SC-401 skill: Select an appropriate policy template. Start from the event that should bring a user into scope, then pick the template whose trigger matches.

Data theft by departing users. Trigger: resignation or termination date from the HR connector or Microsoft Entra account deletion. The HR connector is optional if you use Entra deletion. The template scores exfiltration near leave dates: SharePoint Online downloads, printing, and copies to personal cloud messaging and storage. Cloud indicators can include Box, Dropbox, Google Drive, Amazon S3, and Azure.

Data leaks. Trigger: DLP policy activity that creates a High severity alert or built-in exfiltration event triggers you customize. Prerequisites: a DLP policy configured for High severity alerts on Exchange Online, SharePoint Online, or OneDrive for Business or customized triggering indicators. Low or Medium DLP Incident reports severity will not trigger IRM. Each IRM Data leaks policy can assign up to 20 DLP policies. Scope trap: only users included in both the DLP rule and the IRM policy are processed. Over-assigning High to non-exfiltration DLP rules (for example access-denied events) floods IRM with noise. Prefer a dedicated DLP policy that combines the exfiltration events you actually want as triggers.

Data leaks by priority users. Same trigger options as Data leaks, plus you must assign priority user groups from Settings. Scoring is more sensitive; alerts are more likely and tend to be higher severity.

Data leaks by risky users. Trigger: HR performance improvement, poor performance, or job level change and/or Communication Compliance messages with potentially threatening, harassing, or discriminatory language. You must configure the HR connector, Communication Compliance integration, or both. Associated Communication Compliance alerts do not need to be triaged, remediated, or changed in status before they feed IRM.

Patient data misuse (preview). Trigger: defense evasion of security controls from EMR systems and user and patient address matching indicators from HR systems. Prerequisites: healthcare access indicators selected in the policy or insider risk settings; HR connector configured for address matching; Microsoft Healthcare or Epic connector configured. Use this template for unauthorized access, viewing, modification, or export of patient data in EMR systems in support of HIPAA and HITECH safeguarding of protected health information.

Security policy violations. Trigger: defense evasion of security controls or unwanted software detected by Microsoft Defender for Endpoint. Requires an active Defender for Endpoint subscription and integration with the Microsoft Purview portal.

Security policy violations by departing users. Trigger: HR resignation/termination or Entra account deletion (HR optional if using Entra). Still requires Defender for Endpoint. Use this when the concern is malware or disabled security features, not file theft. File theft on the way out is Data theft by departing users.

Security policy violations by priority users. Trigger: Defender for Endpoint defense evasion or unwanted software. Requires Defender for Endpoint and priority user groups.

Security policy violations by risky users. Trigger: the same HR/Communication Compliance stressors as Data leaks by risky users. Requires those connectors and Defender for Endpoint.

Loading diagram...
Choose an IRM template from the triggering event

AI, browser, and agent templates

Risky AI usage. Microsoft's trigger-and-prerequisite table leaves the triggering-events cell blank for this template—do not invent a fake trigger name. Prerequisites Microsoft does publish: the Microsoft Insider risk extension (Microsoft Edge) or Microsoft Purview extension (Chrome) must be installed; at least one browsing indicator selected in the policy; optionally an HR connector for termination and resignation dates; optionally a Communication Compliance policy that detects inappropriate content in messages. Detection focuses on browsing to generative AI websites and on user prompts and AI responses that contain sensitive information in Microsoft 365 Copilot, Microsoft Copilot, and agents. This policy's detections also contribute to user risk scoring in Adaptive Protection (configured in a later chapter). You can also create it as a one-click policy from Microsoft Purview Data Security Posture Management (DSPM) for AI when you act on Detect risky interactions in AI apps.

Risky browser usage (preview). Trigger: user browsing activity related to security that matches at least one selected Browsing indicator. Microsoft points you to the browser signal detection article for the full prerequisite list (device onboarding plus the Edge or Chrome extension). Use this template for acceptable-use violations such as phishing sites or adult content—not for SharePoint exfiltration (that is Data leaks / data theft) and not for EMR snooping (that is Patient data misuse).

Risky Agents (preview). Triggers Microsoft lists: exposing an agent to risky prompts, an agent generating sensitive responses, accessing sensitive or priority SharePoint files, accessing risky websites, sharing SharePoint files with people outside the organization, and activity above the agent's usual activity for the day. Prerequisites: Copilot Studio agents and Microsoft Foundry agents. Microsoft states this policy template is applied by default for all organizations.

Exam decision table

If the scenario emphasizes...Select
Employee resigns, is terminated, or the Entra account is deleted and files leave via USB, print, or cloudData theft by departing users
Same employment end and Defender for Endpoint shows disabled antivirus or unwanted softwareSecurity policy violations by departing users
High-severity DLP alert or selected exfiltration on the general populationData leaks
Same leak pattern but the population is executives, privileged admins, or a watch listData leaks by priority users
Performance improvement plan, poor review, demotion, or toxic messages then data leavingData leaks by risky users
Same stressors then Defender for Endpoint security violationsSecurity policy violations by risky users
Defender for Endpoint defense evasion for ordinary users, including a history of violationsSecurity policy violations
EMR snooping, neighbor or family record access, or PHI exportPatient data misuse
Copilot or AI prompts and responses that contain secretsRisky AI usage
Users browsing malware, adult, or violence categoriesRisky browser usage
Copilot Studio or Foundry agents leaking via tools or SharePointRisky Agents

Sequence detection (two or more risky activities in a defined order) is supported on Data leaks, Data leaks by priority users, Data leaks by risky users, Data theft by departing users, and Risky AI usage. Priority content selection is supported on those same templates plus the same data-leak family. You choose sequences and priority content when you create the policy, not when you merely pick the template—but knowing which templates support them prevents you from picking Patient data misuse or a security-violation template when the scenario is a sequenced SharePoint exfiltration.

A collection policy can still starve device indicators after you pick the right template: if collection filters out the device activity, IRM never sees it.

Exam traps for templates

  • Departing plus files is not departing plus Defender. Two different templates.
  • Priority templates fail without a priority user group (policy health: "No priority user groups are included in this policy").
  • Risky-user templates fail without the HR connector and/or Communication Compliance integration.
  • Patient data misuse needs both HR address matching and a Healthcare or Epic connector—not High-severity DLP.
  • Data leaks needs High DLP severity, supported workloads, and overlapping user scope. Each Data leaks policy can bind at most 20 DLP policies.
  • Customizable triggers exist only on Data leaks and Data leaks by priority users.
  • Do not pick Forensic evidence or Adaptive Protection as the answer to "which template detects departing-user theft."
  • If a triggering event is not configured, Microsoft's policy health warning is that risk scores will not be assigned until you select a triggering event.
Test Your Knowledge

HR reports a resignation date next Friday. The security team is worried the engineer will download SharePoint project folders and copy them to a personal cloud drive before the last day. Which policy template should you select?

A
B
C
D
Test Your Knowledge

You created a Confidential Project Users priority user group in Insider Risk Management settings and assigned two reviewers. Which pair of templates requires that group to be assigned on the policy?

A
B
C
D
Test Your Knowledge

A hospital wants Insider Risk Management to score clinicians who open electronic medical records of family members or neighbors. Which prerequisite set matches the Patient data misuse template?

A
B
C
D