DeltaPulse now has a public MCP server. Add / integrate this tool with your Copilot Agent(s).

MCP Documentation

Microsoft Purview compliance portal: New email indicators to Insider Risk Management

Message ID
MC1051101
View in Message Center
Service
Microsoft Purview
Tags
New featureAdmin impact
Rollout
March 2025April 2025June 2025
Roadmap ID
483520
View in M365 Roadmap
Platform
Web

Summary

We are adding two new email indicators to Microsoft Purview Insider Risk Management: Sending email with attachments to free public domains: This alerts when business-sensitive data is potentially leaked from a work email account to a free public domain email, potentially leading to a data security incident. Sending email with attachments to self: This alerts when business-sensitive data is potentially leaked from a work email account to a user's personal email account or emailing self, potential...

Details

We are adding two new email indicators to Microsoft Purview Insider Risk Management:

  1. Sending email with attachments to free public domains: This alerts when business-sensitive data is potentially leaked from a work email account to a free public domain email, potentially leading to a data security incident.
  2. Sending email with attachments to self: This alerts when business-sensitive data is potentially leaked from a work email account to a user's personal email account or emailing self, potentially leading to a data security incident.

Admins with Insider Risk Management permissions can enable these indicators from the Settings page and use these new indicators in the Data Leaks or Data Theft policy template. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

This message is associated with Microsoft 365 Roadmap ID 483520.

[When this will happen:]

Public Preview (Worldwide): We began rolling out in late March 2025 and expect to complete by mid-April 2025.

General Availability (Worldwide): We will begin rolling out in mid-June 2025 and expect to complete by late June 2025.

[How this will affect your organization:]

This feature helps customers to detect sensitive content being exfiltrated via emails to self or free public domains.

[What you need to do to prepare:]

Admins need to enable the indicators from policy indicators in Insider Risk Management (IRM) settings. These indicators can be added to any existing policy or admins can create a new policy with these indicators. 

Change History

Show
No change history available

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.