Investigate insider risk alerts in Microsoft Defender XDR
Microsoft Defender Extended Detection and Response (XDR) helps expand investigation capabilities for insider risk by integrating alerts from Microsoft Purview Insider Risk Management with other Microsoft security data. This combined view gives security operations center (SOC) analysts the context they need to assess user behavior, correlate risk signals, and take action across Microsoft 365 workloads.
Use this view to correlate insider risk alerts with data from other services like Microsoft Defender for Endpoint, Microsoft Entra ID, and Microsoft Purview Data Loss Prevention.
Access insider risk alerts in Defender XDR
To review alerts in the Microsoft Defender portal:
- Go to Investigation & response > Incidents & alerts > Incidents.
- Use the Service source filter to select Microsoft Purview Insider Risk Management
This filter shows alerts from Insider Risk Management and highlights when those alerts are grouped into incidents with alerts from other Microsoft tools.