Tools Used
- Microsoft Learn Sandbox
- Microsoft Purview Portal
- Microsoft 365 Compliance Center
Steps Taken
- Signed into Microsoft Purview portal as MOD Administrator.
- Navigated to Insider Risk Management → Settings.
- Enabled analytics and configured data sources for risk detection.
- Created a new Insider Risk policy targeting data leaks and exfiltration.
- Defined triggering conditions, thresholds, and user groups.
- Enabled policy and verified alert generation for simulated risky activity.
- Reviewed alerts and case details in the Insider Risk dashboard.
Outcome
Insider Risk Management successfully configured and validated. Microsoft 365 now monitors user behavior for potential data leaks and insider threats, supporting proactive risk mitigation.
Certification Alignment
SC-401 Domain 1.4 – Implement Insider Risk Management Solutions
Sandbox Link
Lab 7 – Configure Insider Risk Management