Exercise – Investigate potential data theft using Insider Risk Management

In this exercise, you investigate activity related to a departing employee who may have copied and archived sensitive content before their account was disabled. You’ll review the alert, evaluate the user’s actions, escalate the case, and examine the broader context in Microsoft Defender.

Tasks:

  1. Investigate alert details and user activity
  2. Create and escalate a case
  3. Correlate incident data in Microsoft Defender

ERP Software Demo Malaysia