Texas A&M UniversityWork In Progress

Enable Insider Risk Management, Adaptive Protection, and eDiscovery for investigations.

Monitoring & Investigation

With oversharing remediated and access controls in place, this section establishes ongoing visibility into user activities and enables legal response capabilities.


Insider Risk & Audit {#insider-risk}

Objective

Deploy Insider Risk Management for behavioral analytics and leverage Audit (Premium) for forensic investigations.

Insider Risk Management Overview

IRM uses signals from across M365 to detect risky behaviors:

Signal SourceExamples
EmailUnusual attachment volume, external sends
FilesMass downloads, USB copies, cloud uploads
IdentitySign-ins from new locations, privilege escalation
HR EventsResignation dates, performance issues

Policy Templates

TemplateDetects
Data theft by departing usersExfiltration when employees resign
Data leaksUnusual sharing or downloading
Security policy violationsAccess to blocked sites
Step 1 – Enable Insider Risk Management

Click-Ops:

  1. Navigate to Microsoft Purview portalSolutionsInsider Risk Management
  2. Complete initial setup wizard
  3. Create policy from template:
    • Select Data theft by departing users
    • Configure HR connector for resignation signals
    • Enable pseudonymization for privacy
  4. Set alert thresholds
Step 2 – Configure Audit (Premium)

Goal: Ensure 1-year audit retention and capture forensic events.

Key Premium Events:

EventValue
MailItemsAccessedSee what emails were read (not just accessed)
SearchQueryInitiatedExchangeSee what users searched for
SearchQueryInitiatedSharePointSharePoint search queries

Adaptive Protection {#adaptive-protection}

Objective

Dynamically adjust DLP enforcement based on user risk level from Insider Risk Management.

How Adaptive Protection Works

User Risk LevelDLP Response
MinorStandard policy enforcement, policy tips shown
ModerateSharing blocked, requires business justification
ElevatedHard block on sensitive actions, security team notified
Enable Adaptive Protection

Click-Ops:

  1. Navigate to Microsoft Purview portalSolutionsInsider Risk ManagementAdaptive Protection
  2. Enable the feature
  3. Configure risk level thresholds
  4. Link to existing DLP policies

How It Works:

  • IRM calculates user risk based on behavioral signals
  • DLP policies automatically escalate enforcement for high-risk users
  • Reduces friction for trusted users while protecting against threats
Retention Moved to Prevention

Retention and records management is now covered in Prevention, as lifecycle policies are part of deeper protection after oversharing remediation.


eDiscovery Premium {#ediscovery}

Objective

Set up eDiscovery capabilities for legal investigations, FOIA requests, and compliance audits.

eDiscovery Workflow

PhaseAction
IdentificationDetermine custodians and data sources
PreservationPlace legal holds
CollectionSearch and gather content
ProcessingDeduplicate, extract text
ReviewAnalyze, tag, cull
ProductionExport for legal
Step 1 – Create an eDiscovery Case

Click-Ops:

  1. Navigate to Purview > eDiscovery > Premium
  2. Click + Create a case
  3. Add case members (legal team)
  4. Configure custodians and data sources
  5. Create searches and place holds
Step 2 – Configure Hold Policies

Goal: Preserve content for legal matters.

Hold Types:

TypeUse Case
Custodian-basedHold all content for specific users
Query-basedHold content matching search criteria
Site-basedHold entire SharePoint sites

Validation Checklist

#ItemSuccess Criteria
1IRM policiesAt least one policy active
2Audit Premium1-year retention configured
3Retention policiesDeployed to key locations
4eDiscoveryCan create cases and holds

Next Steps

With monitoring in place, proceed to Prevention to implement DLP, retention policies, and Communication Compliance.

Continue to Prevention →