Enable Insider Risk Analytics in Microsoft Purview – Part 6

Reading Time: 4 minutes


If you missed the previous parts, here they are:

Part 1: Introduction to Microsoft Purview
Part 2: Microsoft Purview Portal

Part 3: Microsoft Purview Roles and Scopes
Part 4: Turn on audit logs in Microsoft Purview
Part 5: Microsoft Purview Device Onboarding

In this blog post, I’ll walk you through step by step instructions on how to enable Microsoft Purview Insider Risk Analytics and configure data sharing to help your organisation proactively manage insider threats.

What is Microsoft Purview Insider Risk

Before diving into the steps to enable analytics and data sharing, it’s important to first provide a brief overview of Microsoft Purview Insider Risk. I’ll be exploring Microsoft Purview Insider Risk in more detail later in this blog series.

Organisations are facing growing challenges not only from external threats but increasingly from within the organisation. Microsoft Purview Insider Risk Management is a powerful solution designed to help organisations detect, investigate, and mitigate insider risks, whether those actions are accidental or intentional.

Microsoft Purview Insider Risk Management correlates various signals to identify insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized (where user identities are hidden or replaced with fake names) by default.

Why It Matters:

According to Microsoft’s Data Security Index 2024, insider threats are a major concern:

  • 63% of all data breaches originate from insider activity.
  • 93% of organisations report being concerned about insider risks.

These statistics show why it’s so important for organisation’s to take a proactive approach to insider risk management. Microsoft Purview Insider Risk Management can play a key role in helping to detect and respond to these risks early.

Common Use Cases:

Microsoft Purview Insider Risk Management helps organisations spot and respond to risky activities before they become serious issues. Here are some everyday examples:

  • Employees leaving the company: A staff member downloads sensitive files or sends them to personal email just before resigning.
  • Disgruntled or upset employees: Someone unhappy with their role starts accessing confidential data and uploading large amounts of data to personal cloud storage.
  • Data theft: An employee tries to copy files to a USB drive without permission.
  • Cross-team investigations: HR, legal, and security teams can work together to understand and respond to suspicious behaviour.

I’ll go into more detail about Microsoft Purview Insider Risk later in this blog series, but first, let’s look at how to enable Insider Risk analytics and data sharing.

This is a crucial first step as it enables organisations to conduct an evaluation of potential insider risks in your organisation without configuring any insider risk policies. Once enabled, analytics can highlight risky user activity, generate severity scores, and share insights with tools like Data Loss Prevention (DLP), Communication Compliance, and Microsoft Defender (More on these features later in the series). These insights help build a strong foundation for managing insider risks effectively.

  1. Access purview.microsoft.com

  2. Click solutions from the left pane and then Insider Risk Management

Image 1



3. Click Data sharing from the left pane

4. Turn on share user risk details with other security solutions and click save

When turned on, admins with the correct permissions will be able to review user risk details from Insider Risk Management within other solutions such as Data Loss Prevention (DLP), Communication Compliance, and Microsoft Defender. The data shared is based on user activities detected by Insider Risk Management policies and user-level analytics. I’ll enable user-level analytics in the next step, as it’s a required configuration for sharing user risk details with other security solutions.

Export alert details to SIEM services: I will leave this option off. This option allows the export of alert details to third party SIEM solutions.

Image 3


5. Click analytics from the left pane and turn on both settings to get a complete coverage of insights across the tenant and from different security solutions.

– Show insights at tenant level
When enabled, this setting aggregates data across the organisation and displays it in analytics reports. It doesn’t provide detailed user-level insights or integrate with other security tools like DLP (Data Loss Prevention) or Microsoft Defender. Microsoft recently introduced user-level insights to address this gap.

Note: User-level insights cannot be enabled on their own, tenant-level insights must be turned on first. Disabling tenant-level insights will also disable user-level insights.


Show insights at user level
This works with the data sharing option I enabled in the previous step. User-level analytics provide insights for all eligible users in your organisation, including those not covered by any Insider Risk Management policy. When investigating alerts in Microsoft Defender, DLP, or Communication Compliance, analysts with the right permissions automatically gain access to user-level data, helping improve risk assessments. I’ll explore Insider Risk policies later in this blog series.

Image 2



A close-up of the options is shown below. To gain the most complete insights, I’ll be enabling both tenant-level and user-level analytics.

Note: Tenant-level analytics must be turned on before enabling user-level analytics. If tenant-level analytics is disabled, user-level analytics will also be turned off.

Additionally, data sharing must be enabled alongside user-level analytics. I enabled data sharing in the previous step.

6. Enable both and click save

Note: To enable insider risk user-level analytics, you must be a member of the Insider Risk Management, Insider Risk Management Admins, or Microsoft 365 Global admin role group.

Image 4


That’s it for this part of the blog series. I’ll explore Insider Risk policies in more detail later in the series.

In the next post, I’ll begin exploring Information Protection in Microsoft Purview, starting with Sensitive Information Types (SITs), a key component for identifying and classifying sensitive data.

Join me at the following link: Part 7 Microsoft Purview Information Protection

Microsoft Purview Device Onboarding – Part 5

Reading Time: 3 minutes



If you missed the previous parts, here they are:

Part 1: Introduction to Microsoft Purview
Part 2: Microsoft Purview Portal

Part 3: Microsoft Purview Roles and Scopes
Part 4: Turn on audit logs in Microsoft Purview

In this blog post, I’ll walk you through the step by step process of onboarding devices into Microsoft Purview. This may be a key action for organisations that want to extend data protection, compliance, and visibility beyond cloud services such as to user endpoints like laptops and desktops. By onboarding devices, you can use Microsoft Purview to apply policies such as Data Loss Prevention (DLP), monitor sensitive data activity, and ensure consistent governance across your digital estate.

Services such as Endpoint data loss prevention (Endpoint DLP) and insider risk management (covered later) require that devices be onboarded so that they can send monitoring data to Microsoft Purview.

I’ve been exploring how Endpoint DLP works on devices, and it’s been eye opening to see how it helps track when sensitive items are accessed or shared. It gives me a clearer picture of how data is being used and lets me put guardrails in place to help prevent risky behavior. I’ll explore these features later in this blog post series.

If Windows 10/11 devices are already onboarded to Microsoft Defender for Endpoint (MDE), they’ll show up in the managed list automatically, no extra steps needed. Onboarding through the Microsoft Purview portal also brings them into Defender for Endpoint, which is handy. At the time of writing this post, it’s also possible to onboard Windows Server 2019 and 2022.

However, if Defender for Endpoint isn’t the antivirus you’re using, the application is rolled out as part of the onboarding process and configured in passive mode, meaning it doesn’t actively block threats or interfere with the existing protection. Instead, it quietly collects telemetry and shares threat insights, allowing Defender for Endpoint to monitor behavior without causing conflicts or performance issues.

Let’s go through the steps to enable onboarding of devices in Microsoft Purview

  1. Access the Microsoft Purview portal at purview.microsoft.com

  2. Click Settings from the left pane
Image1

3. Expand Device onboarding and click Devices

Image2


4. Click Turn on device onboarding

Image3

5. Click ok

Turn on device onboarding
When you turn this on, any devices that already onboarded to Microsoft Defender for Endpoint (MDE) will appear in the device list here. Regardless of whether you already have onboarded devices, you’ll be able to onboard new ones from the “Onboarding” page.

Image4


6. Click ok again

Image5


7. After a brief period, devices with Microsoft Defender for Endpoint installed start showing up in the Purview portal.

Image7


If you’re not using Microsoft Defender for Endpoint (MDE), you can still onboard your Windows and macOS devices by selecting Onboarding from the left pane. There are a several deployment methods available.

As mentioned earlier in this post, Defender for Endpoint will be installed alongside your existing antivirus or anti-malware product, but it will remain in passive mode.

Image6



Join me in part 6 of this blog post series where I enable Insider Risk Analytics and data sharing.

Link: Part 6 Enable Insider Risk Analytics in Microsoft Purview

Turn on audit logs in Microsoft Purview – Part 4

Reading Time: 2 minutes

In this blog post I’ll go through a step by step guide to enabling auditing in Microsoft Purview.

If missed the previous parts, here they are:

Part 1: Introduction to Microsoft Purview
Part 2: Microsoft Purview Portal

Part 3 – Microsoft Purview Roles and Scopes

Auditing is important in Microsoft Purview because many of its features, like Data Loss Prevention (DLP), Insider Risk Management, and Information Protection, rely on audit logs to function effectively. For example, if a user removes a sensitivity label from a document or shares a file externally, that action is recorded in the audit log. These logs then feed into alerts, reports, and risk scoring systems that help security and compliance teams respond quickly and appropriately when there is an issue.

Enabling auditing early ensures that historical data is captured from the start, which is essential for building a complete picture of user behavior and data movement. It also helps organisations meet regulatory requirements, which often require detailed activity tracking and audit trails. In short, auditing lays the groundwork for a secure, compliant, and well governed environment, making it a must do step before diving into the full capabilities of Microsoft Purview.

When auditing is enabled via the Microsoft Purview portal, user and administrator activities across your organisation are captured in the audit log and automatically retained for 180 days. The retention period begins as soon as the data is logged and is governed by your organisation’s audit log retention policies and the user license type. (Refer to the comparison table below for details.)

Image 6

Source: Microsoft Learn

If auditing is currently disabled, you can activate it either through the Microsoft Purview portal or via Exchange Online PowerShell. Please note: once enabled, it may take several hours before audit log search results become available.

  1. Access the Microsoft Purview portal at purview.microsoft.com
Image 1



2. Click the Start recording user and admin activity banner. If this is not visible, you have most likely already enabled auditing.

Image 2



3. Click yes when promoted with the message below

Complete organizational setup
To complete this task, we’ll need to complete the setup process for your organization. ​Would you like to do this now?​

Image 5

Note: It could take up to 60 minutes for the change to take effect once enabled.

Continue to part 5 where I enable device onboarding in Microsoft Purview

Link: Part 5: Microsoft Purview Device Onboarding

How to Configure Conditional Access Reauthentication in Azure PIM

Reading Time: 5 minutes


In this blog post, I’ll provide a step by step guide on how to enforce admin reauthentication when elevating a role in Azure Privileged Identity Management (PIM) using a Conditional Access policy.

But why would you want an admin to reauthenticate?

Once an admin signs in to the Azure portal, they typically don’t need to authenticate again during that session. Sounds convenient, right? But here’s the problem. If an admin needs to access PIM to elevate their role, they can do so without reauthenticating, because they’re already signed in. This creates a potential security risk. If a bad actor gains access to an authenticated session, they could elevate the admin’s role and cause serious damage to your environment.

By enforcing reauthentication through Conditional Access, you add an extra layer of protection. The admin will be required to verify their identity again before they can elevate to a privileged role, helping to prevent unauthorised access and safeguard your platform.

In this blog post I will:

  • create an Authentication Context.
  • create a Conditional Access policy (including the Authentication Context), that prompts for reauthentication when an admin attempts to elevate a role in PIM.
  • associate the Authentication Context with a PIM role
  • test the configuration

Task 1: Create an Authentication Context


Authentication Context can be used to enhance the security of data and actions within applications. These applications might include your own custom apps, line of business (LOB) solutions, SharePoint, or services protected by Microsoft Defender for Cloud Apps.

For example, an organisation may store files in SharePoint sites, ranging from something simple like a lunch menu to something more sensitive like a secret BBQ sauce recipe. While everyone might have access to the lunch menu site, access to the secret BBQ sauce recipe site could require users to be on a managed device, use a FIDO2 security key, and accept specific terms of use. Authentication Context can help enforce these policies.

Authentication Context can also be applied in Privileged Identity Management (PIM). For instance, you might require administrators requesting high privilege roles, such as Global Administrator, to authenticate using a FIDO2 key, only allow access from a trusted location, a compliant device and so on.

In this blog post, we’ll focus on a specific use case, prompting administrators to reauthenticate before an admin role is assigned to them via PIM.

Let’s go through the steps

  1. Access Entra ID via the Azure Portal portal.azure.com or Entra portal at entra.microsoft.com

  2. In the search bar, type Conditional Access and click Microsoft Entra Conditional Access
Image2



3. From the left pane, click Authentication Contexts

Image4


4. Enter a name, description and click save

Image5

Image6

Task 2: Create a Conditional Access policy and associate it with the newly created Authentication Context

  1. Click Policies from the left pane and + New policy
Image7

  • Give your policy a suitable name
  • Target the users/groups
  • Click target resources. From the drop down (Select what this policy applies to) click Authentication Context.
  • The Authentication Context I created earlier is visible for me to select.
  • Don’t save changes just yet

    Continue to step 2 below
Image8



2. Scroll down and click sessions

Image9

  • Click Sign-in frequency
  • Click Every time
  • Click the select button
Image10


3. Switch the toggle to on and click create

Image11


Note: You may wish to leave the toggle on report only mode which will ensure the policy does not apply but will provide you with audit logs. Once convinced all is working as it should do, you can enforce the policy by turning it on. Ensure you test with a group of pilot users.


Task 3: Assign the Conditional Access policy to PIM

  1. Search for and access PIM (Microsoft Entra Privileged Identity Management)
Image12


2. In this example, I’ll be assigning the Authentication Context I created earlier to the User Administrator role. I have a demo user name Darren who has been assigned the User Administrator Role in PIM. Darren is able to elevate/request for the role and the role is automatically removed after a number of hours.

3. From the left pane, click roles. Search and click User Administrator

Image13

4. From the left pane, click Role settings

Image14

5. Click Edit to access the default settings.

Image15

6. Click the option Microsoft Entra Conditional Access Authentication Context. The Authentication Context I created earlier is visible, which is attached to the Conditional Access Policy which forces the admin to reauthenticate every time.

Image16


7. Click update

Image20


Task 4: Test the Reauthentication Policy


I’ll be logging in to Azure Portal with a demo user named Darren. I have already assigned Darren’s account to the User Administrator through PIM. Therefore, Darren is eligible to activate this role when needed. Darren is also included within the Conditional Access Policy scope.

  1. I login as Darren and go through MFA

    Note: we’ll see the Authentication Context and policy trigger later
Image17

2. Whilst logged in as Darren, I search for PIM and click my roles from the left pane.

Image18

Click activate

Image19

3. Darren is presented with a message requesting for additional verification.

Image21

4. Click the message: A Conditional Access policy is enabled and may require additional verification. Click to continue

5. Darren is prompted to login again (reauthenticate)

Image22

Image23


6. and after reauthenticating, Darren can continue to active the role.

Image24


I hope you found this post useful

Thanks for reading and see you at the next one.

Free Microsoft Courses on YouTube

Reading Time: 3 minutes


In case you weren’t aware, there are FREE Microsoft courses now available on the official Microsoft Learn YouTube channel.

I’ve compiled a list of these courses below to make it easier for anyone looking to learn something new, prepare for certifications, or just explore what Microsoft has to offer.

Check them out and enjoy! 👇

⚫ Free AB-100 Course on YouTube – Architecting agentic AI business solutions

⚫ Free AI-103 course on YouTube – Develop AI apps and agents on Azure

⚫ Free AI-300 Course on YouTube – Operationalizing Machine Learning and Generative AI Solutions

⚫ Free AI-3016 Course on YouTube – Develop generative AI apps in Azure

⚫ Free AI-3017 Course on YouTube – AI for business leaders

⚫ Free AI-900 Course on YouTube – Azure AI Fundamentals

⚫ Free AI-901 course on YouTube – Introduction to AI in Azure

⚫ Free AZ-900 course on YouTube – Azure Fundamentals

⚫ Free AZ-104 Course on YouTube– Azure Administrator

⚫ Free AZ-204 Course on YouTube – Azure Developer

⚫ Free AZ-400 Course on YouTube – Design and Implement Microsoft DevOps Solutions

⚫ Free AZ-700 Course on YouTube – Designing and Implementing Microsoft Azure Networking Solutions

⚫ Free AZ-800 Course on YouTube – Administering Windows Server Hybrid Core Infrastructure

⚫ Free AZ-801 Course on YouTube – Configuring Windows Server Hybrid Advanced Services

⚫ Free SC-900 Course on YouTube – Security, Compliance, and Identity Fundamentals

⚫ Free SC-100 Course on YouTube – Cyber Security Architect

⚫ Free SC-200 Course on YouTube – Microsoft Security Operations Analyst

⚫ Free SC-300 Course on YouTube – Identity and Access Administrator

⚫ Free SC-401 Course on YouTube – Administering Information Security

⚫ Free SC-5002 Course on YouTube – Secure Azure services and workloads with Microsoft Defender for Cloud regulatory compliance controls

⚫ Free SC-5006 Course on YouTube – Enhance security operations by using Microsoft Security Copilot

⚫ Free MS-4023 Course on YouTube – Explore Microsoft 365 Copilot Chat

⚫ Free AZ-500 Course on YouTube – Azure Security Engineer Associate

⚫ Free AZ-305 Course on YouTube – Designing Microsoft Azure Infrastructure Solutions

⚫ Free AZ-2008 Course on YouTube – DevOps foundations: The core principles and practices

⚫ Free MS-4019 Course on YouTube – Transform your everyday business processes with agents

⚫ Free MS-4018 Course on YouTube – Draft, analyze, and present with Microsoft 365 Copilot

⚫ Free MS-4017 Course on YouTube – Manage and extend Microsoft 365 Copilot

⚫ Free MS-4007 Course on YouTube – Microsoft 365 Copilot User Enablement Specialist

⚫ Free DP-3001 Course on YouTube – Migrate SQL Server workloads to Azure SQL

⚫ Free DP-300 Course on YouTube – Administering Microsoft Azure SQL solutions

⚫ Free AI-3026 Course on YouTube – Develop AI agents on Azure

⚫ Free DP-605 Course on YouTube – Prepare and visualize data with Microsoft Power BI

⚫ Free DP-700 Course on YouTube – Microsoft Fabric Data Engineer

⚫ Free MS-4017 Course on YouTube – Manage and extend Microsoft 365 Copilot

⚫ Free DP-3011 Course on YouTube – Implement a data lakehouse analytics solution with Azure Databricks

⚫ Free PL-300 Course on YouTube – Power BI Data Analyst

⚫ Free DP-600 Course on YouTube – Fabric Analytics Engineer

⚫ Free PL-900 Course on YouTube – Power Platform Fundamentals

⚫ Free PL-7008 Course on YouTube – Create agents in Microsoft Copilot Studio

⚫ Free DP-900 Course on YouTube – Azure Data Fundamentals

⚫ Free MS-4010 Course on YouTube – Extend Microsoft 365 Copilot with declarative agents by using Visual Studio Code

⚫ Free MS-4004 Course on YouTube – Empower your workforce with Microsoft 365 Copilot Use Cases

⚫ Free MD-4011 Course on YouTube – Enhance endpoint security with Microsoft Intune and Microsoft Copilot for Security

⚫ Free MS-4014 Course on YouTube – Build a foundation to extend Microsoft 365 Copilot

⚫ Free AZ-2007 Course on YouTube – Accelerate app development by using GitHub Copilot

⚫ Free DP-100 Course on YouTube – Designing and Implementing a Data Science Solution on Azure

⚫ Free GH-200 Course on YouTube – GitHub actions

⚫ Free GH-500 Course on YouTube – GitHub Advanced Security

⚫ Free GH-100 course on YouTube – GitHub Fundamentals