Microsoft Purview compliance portal: Insider Risk Management - IRM alerts in XDR

Microsoft 365 Roadmap ID: 422730
Launched
Microsoft Purview compliance portal
Worldwide (Standard Multi-Tenant)
General Availability Preview
Web
August 2025

Description

With this feature, IRM alerts and other supporting data will be available in the following Microsoft Defender XDR experiences: 1. IRM alerts will be surfaced in unified alert and Incident queue in Microsoft Defender XDR. 2. IRM alerts, Indicators, and enriched events will be available in Microsoft Defender XDR advanced hunting. Analysts can leverage KQL queries to identify potentially hidden risky patterns in data security related user activity. 3. IRM alert, Indicators, and enriched events will be exposed through Graph API. This feature can be enabled through “Share data with Microsoft Defender XDR” within Microsoft Insider Risk Management settings. To ensure privacy of the data, all IRM data in Microsoft Defender XDR can only be accessed by users with Insider risk analyst or Insider risk investigator permissions in Purview. Existing analysts accessing IRM data in purview will continue to access IRM data in Microsoft Defender XDR. IRM data in Microsoft Defender XDR does not honor anonymization. This is to enable effective correlation of IRM alerts with alerts from other solutions in Microsoft Defender XDR platform (such as Defender for Endpoint, Defender for Cloud apps, etc.). Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

Change History

December 3, 2025 at 2:00 AM Updated
Status
Previous
Rolling out
New
Launched
Cloud Instances
Previous
Worldwide (Standard Multi-Tenant), GCC, GCC High, DoD
New
Worldwide (Standard Multi-Tenant)
Modified Date
Previous
2025-09-23T23:15:02.000Z
New
2025-12-03T00:15:38.000Z
September 24, 2025 at 12:00 AM Updated
Status
Previous
In development
New
Rolling out
Modified Date
Previous
2025-07-01T23:15:03.000Z
New
2025-09-23T23:15:02.000Z
July 2, 2025 at 12:01 AM Updated
Release Date
Previous
June CY2025
New
August CY2025
Modified Date
Previous
2025-01-24T00:00:21.000Z
New
2025-07-01T23:15:03.000Z

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.