Investigate and triage insider risk alerts in Microsoft Purview

The Alert dashboard in Microsoft Purview Insider Risk Management helps investigators and analysts view, prioritize, and take action on potentially risky user activity. Each alert is based on policy-defined conditions and provides a summary of the user’s actions, associated risks, and relevant context. Effective alert triage ensures that high-risk behavior is addressed quickly, while low-risk activity can be dismissed to reduce noise.

Overview of the Alert dashboard

The Alerts dashboard provides a centralized queue of all alerts generated by Insider Risk Management policies. Each row in the dashboard represents an individual alert and includes key fields to support triage and prioritization at a glance:

  • ID: A unique identifier for each alert.
  • Copilot icon: Indicates whether Copilot is available to summarize the alert.
  • Users: The individual associated with the potentially risky activity.
  • Policy: The Insider Risk Management policy that generated the alert.
  • Status: Shows if the alert is new, confirmed, dismissed, or resolved.
  • Spotlight: Highlights high-priority alerts that meet specific risk criteria.
  • Alert severity: Automatically calculated risk level—Low, Medium, or High.
  • Time detected: Indicates when the alert was generated.
  • Assigned to: Shows who, if anyone, is currently assigned to investigate the alert.
  • Case: Lists any case associated with the alert.

You can use filters, saved views, and column customization to focus on the alerts that matter most. Selecting an alert opens the Alert details page, where you can investigate activity, view user history, and take action such as dismissing or escalating the alert.

ERP Analytics Software