WWL Tenants - Terms of use
If you are being provided with a tenant as part of an instructor-led training delivery, please note that the tenant is made available for the purpose of supporting the hands-on labs in the instructor-led training.
Tenants should not be shared or used for purposes outside of hands-on labs. The tenant used in this course is a trial tenant and cannot be used or accessed after the class is over and is not eligible for extension.
Tenants must not be converted to a paid subscription. Tenants obtained as part of this course remain the property of Microsoft Corporation and we reserve the right to obtain access and repossess at any time.
Lab 4 - Exercise 1 - Implement Insider Risk Management
You are Joni Sherman, the Information Security Administrator for Contoso Ltd. Your role involves ensuring regulatory compliance and protecting sensitive information within the organization. Recently, Contoso Ltd. has noticed unusual browsing activities that could potentially expose sensitive data. To proactively address this insider risk, you will implement Microsoft Purview Insider Risk Management, focusing on identifying, analyzing, and responding to potential insider threats effectively.
Tasks:
- Assign insider risk management permissions
- Configure policy indicators
- Create a data leaks policy
- Enable Microsoft Defender for Endpoint integration with Insider Risk Management
- Enable Defender indicators and configure priority users
- Create a policy for security policy violations by priority users
- Create a notice template
Estimated time: 90-120 minutes
Task 1 – Assign insider risk management permissions
In this task, you’ll assign Joni Sherman the Insider Risk Management role so she can access and manage insider risk features in Microsoft Purview.
-
Sign into the Client 1 VM (SC-401-CL1) as the SC-401-CL1\admin account.
-
Open Microsoft Edge in an InPrivate window by right-clicking Microsoft Edge from the task bar and selecting New InPrivate window.
-
Navigate to
https://purview.microsoft.comand sign into the Microsoft Purview portal as MOD Administrator,admin@WWLxZZZZZZ.onmicrosoft.com(where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). Admin’s password should be provided by your lab hosting provider. -
Select Settings > Roles and Scopes > Role groups.
-
On the Role groups for Microsoft Purview solutions page, select Insider Risk Management.
-
On the Insider Risk Management flyout panel, select the Members tab. Select + Add member, then select Choose users.
-
On the Choose users flyout panel, search for
Joni, then select the checkbox for Joni Sherman. -
Select Select at the bottom of the panel.
-
Back on the Insider Risk Management flyout panel, verify Joni Sherman appears as a member.
-
Select Done, then select Confirm to update the role group.
-
Close the InPrivate window.
You’ve assigned Joni the necessary permissions to work with Insider Risk Management in the Microsoft Purview portal.
Task 2 – Configure policy indicators
Before you create insider risk policies, you need to enable the indicators that define which user activities the system monitors. Enabling them upfront ensures your policies can use sequence detection and built-in thresholds without additional configuration.
-
In Microsoft Edge, navigate to
https://purview.microsoft.comand sign in asJoniS@WWLxZZZZZZ.onmicrosoft.com(where ZZZZZZ is your unique tenant prefix provided by your lab hosting provider). User account passwords are provided by your lab hosting provider. -
Select Settings > Insider risk management.
-
Select the tab on the left for Policy indicators.
-
On the Policy indicators page, expand each of the following categories and select Select all to enable all indicators:
- Office indicators
- Device indicators
- Cumulative exfiltration detection
Note: Greyed-out categories
Some categories, such as Microsoft Defender for Endpoint indicators, require additional integration before they can be enabled. You’ll configure that integration and enable those indicators in a later task. -
Select Save at the bottom of the page.
You’ve enabled the core policy indicators for insider risk detection. Office indicators track file activity in Microsoft 365 apps, device indicators cover USB and print operations, and cumulative exfiltration detection identifies activity that exceeds normal baselines.
Task 3 – Create a data leaks policy
In this task, you’ll create a policy from the Data leaks template to detect risky data exfiltration. This policy uses the Office, device, and exfiltration indicators you enabled in Task 2 to identify patterns like file downloads followed by USB copies or cloud uploads.
-
In Microsoft Purview, select Solutions > Insider Risk Management > Policies.
-
On the Policies page, select + Create policy, then select Custom policy.
-
On the Choose a policy template page, select Data leaks, then select Next.
-
On the Name your policy page, enter:
- Name:
Data leaks policy - Description:
Detects risky data exfiltration activity using Office, device, and cumulative exfiltration indicators.
- Name:
-
Select Next.
-
On the Choose users, groups, & adaptive scopes page, select Next.
-
On the Exclude users and groups (optional) (preview) page, select Next.
-
On the Decide whether to prioritize content page, select I don’t want to prioritize content right now, then select Next.
-
On the Choose triggering event for this policy page, review the available sequences. The sequences listed here rely on the indicators you enabled in Task 2 — each one combines multiple signals to detect coordinated data movement.
-
Select Next.
-
On the Choose thresholds for triggering events page, select Next.
-
On the Indicators page, select Next.
-
On the Detection options page, select Next.
-
On the Choose threshold type for indicators page, select Next.
-
On the Review settings and finish page, select Submit.
-
On the Your policy was created page, select Done.
-
Back on the Policies page, verify your data leaks policy has a Healthy status.
You’ve created a data leaks policy that uses sequence-based triggers and the indicators configured in Task 2 to detect risky data exfiltration patterns.
Task 4 – Enable Microsoft Defender for Endpoint integration with Insider Risk Management
In this task, you’ll enable integration between Microsoft Defender for Endpoint and Microsoft Purview so security alerts can be used in insider risk policies.
-
In Microsoft Edge, navigate to Microsoft Defender by going to
https://security.microsoft.com. -
In the left navigation pane, select System > Settings > Endpoints > Optional features.
-
Scroll down and select the toggle to On to Share endpoint alerts with Microsoft Compliance Center.

-
Select Save preferences at the bottom of the screen.
You’ve successfully enabled Defender for Endpoint to share alerts with Microsoft Purview.
Task 5 – Enable Defender indicators and configure priority users
With Defender for Endpoint integration active, you can now enable the security-specific indicators that feed security policy violations policies. You’ll also create a priority user group to target monitoring for high-risk roles.
Note: Defender for Endpoint indicator availability
Microsoft Defender for Endpoint indicators might appear greyed out and unselectable if the integration from the previous task hasn’t finished processing. If that happens, wait a few minutes and refresh the page before continuing.
-
In Microsoft Edge, navigate to
https://purview.microsoft.com. -
Select Settings > Insider risk management.
-
Select the tab on the left for Policy indicators.
-
On the Policy indicators page, expand and select Select all to enable all indicators in these categories:
- Microsoft Defender for Endpoint indicators
- Risky browsing indicators (preview)
-
Select Save at the bottom of the page.
-
Select the Priority user groups tab, then select + Create priority user group.
-
On the Name and describe the priority user group page, enter:
- Name:
Finance team - Description:
Team members who manage financial operations, budgeting, and payroll systems.
- Name:
-
Select Next.
-
On the Members page, select + Members.
-
In the Members flyout, search for and select:
Lynne RobbinsDebra BergerMegan Bowen
-
Select Add to add the three members to the Finance team priority group.
-
Select Next.
-
On the Choose who can view data involving users in this priority group, select + Choose users and role groups.
-
In the flyout, select the Insider Risk Management role group. This allows members of the role group, including Joni, to view data involving users in this priority group. Select Add.
-
Select Next.
-
Review and Submit your settings, then select Done once your priority user group has been created.
You’ve enabled Defender-based indicators for detecting security policy violations and created a priority user group for targeted monitoring.
Task 6 – Create a policy for security policy violations by priority users
In this task, you’ll create an insider risk policy that uses the Defender for Endpoint indicators you enabled in Task 5 to detect security-related events — such as disabled protections or malware — for priority users.
-
In Microsoft Purview, select Solutions > Insider Risk Management > Policies.
-
On the Policies page, select + Create policy, then select Custom policy.
-
On the Choose a policy template page, select Security policy violations by priority users, then select Next.
-
On the Name your policy page, enter:
- Name:
Security policy violations - Priority users - Description:
Detects Defender for Endpoint alerts for risky activity by priority users, such as malware or disabled protections.
- Name:
-
Select Next.
-
On the Choose users, groups, & adaptive scopes page, select Add or edit priority user groups.
-
On the Choose priority user groups flyout, select the checkbox for the Finance team group, then select Add.
-
Select Next.
-
On the Decide whether to prioritize content page, select Next.
-
On the Choose triggering event for this policy page, select Next.
-
On the Indicators page, select Next.
-
On the Choose threshold type for indicators page, leave the default Apply thresholds provided by Microsoft option selected, then select Next.
-
On the Review settings and finish page, select Submit.
-
On the Your policy was created page, select Done.
-
Back on the Policies page, select Security policy violations - Priority users and confirm the policy status is Healthy.
You’ve created a custom insider risk policy that uses Defender for Endpoint signals to detect risky activity from priority users. When an alert from this policy is triaged, an investigator can use a notice template to communicate with the user. In the next task, you’ll create that reusable response asset.
Task 7 – Create a notice template
Notice templates are created separately from insider risk policies and selected when an investigator communicates with a user about a triaged alert. In this task, you’ll create a reusable template for security policy violation alerts generated by the priority-user policy.
-
In Microsoft Purview, select Solutions > Insider Risk Management > Users > Notice templates.
-
On the Notice templates page, select + Create notice template.
-
Fill out the necessary information in the Create a new notice template flyout panel on the right.
- Template name:
Security Violation Alert - Send from:
Joni Sherman - Subject:
Unusual activity detected - please review -
Message body:
<!DOCTYPE html> <html> <body> <h2>Security Alert</h2> <p>We've detected activity from your account that might violate our organization's security policies. This could be due to malware, disabled protections, or other risky behavior.</p> <p>Please review your recent actions and ensure your device security settings are up to date. If you believe this alert was generated in error, contact the IT Security team for assistance.</p> <p>To avoid future issues, refer to the <a href="https://contoso.com/security-guidelines">Contoso Security Guidelines</a>.</p> <p>Thank you,</p> <p><em>Compliance and Security Team</em></p> </body> </html>
- Template name:
-
Select Create.
-
Back on the Notice templates page, you’ll see the Security Violation Alert template you just created.
You’ve created the Security Violation Alert notice template. It is now available for an investigator to select when communicating with a user about a relevant insider risk alert.