GregLab | Exam Prep

Understand data protection and governance tasks for Microsoft 365 and Copilot

Insider Risk and Communication Compliance

Important

Separate user-risk patterns from risky communications and apply privacy-aware human investigation to both.

Aligned to the current AB-900 guide, verified July 22, 2026.

Why this matters

AB-900 expects you to route behavioral risk and message-policy concerns to the right Purview workflow while preserving privacy and human review.

Must Know

  • Insider Risk Management correlates user activity and contextual signals to identify possible insider-risk patterns.
  • Communication Compliance detects messages that may violate conduct, regulatory, or organizational communication policy.
  • DLP controls sensitive-data activity; Insider Risk correlates broader behavior; Communication Compliance reviews message content and conduct.
  • An alert is a signal for triage, not proof of intent or guilt; reviewers examine evidence before escalation.
  • Role separation, limited scope, privacy protections, and documented review processes reduce misuse of employee-related signals.
  • A case is a structured investigation built from selected evidence; it is more than the original alert.

Compare and Distinguish

  • Insider Risk vs Communication Compliance: cross-activity user-risk pattern vs message-policy violation.
  • DLP vs Communication Compliance: sensitive-data handling control vs communication content/conduct review.
  • DLP vs Insider Risk: rule applied to a data activity vs correlation of broader behavior and risk indicators.
  • Alert vs case: initial signal for triage vs a structured investigation with selected evidence.
  • Risk signal vs guilt: evidence requiring review vs a conclusion about intent.

Scenario examples

  • Scenario: A departing employee downloads and shares an unusual volume of files. Think: Insider Risk can correlate the departure trigger and activity indicators; DLP may separately control a sensitive transfer.
  • Scenario: Messages may contain harassment. Think: Communication Compliance supports scoped detection and human review.
  • Scenario: One DLP alert shows a permitted finance transfer. Think: Do not infer insider intent; review context and related behavior before escalation.
  • Scenario: A reviewer cannot open message evidence. Think: Check the specific Communication Compliance reviewer/content permissions, not an unrelated SharePoint role.

Exam traps

  • Insider Risk does not automatically prove a user is malicious.
  • Communication Compliance is not DLP: it reviews policy-relevant messages rather than governing every sensitive-data movement.
  • An alert and a case are different stages of investigation.
  • Broad employee surveillance is not the goal; privacy-aware scoped review is essential.

Key takeaways

  • User behavior pattern → Insider Risk; policy-relevant message → Communication Compliance.
  • Sensitive-data action → DLP; related tools can contribute evidence without becoming interchangeable.
  • Signals require authorized, privacy-aware human review.
How it works
  • Insider Risk policies begin with a triggering event or scoped condition, then evaluate indicators over a time window and assign risk signals for review. A trigger starts or scopes evaluation; an indicator is observable activity such as an unusual download or sharing action. Neither is a conclusion by itself.
  • Communication Compliance policies evaluate in-scope messages against configured conditions/classifiers and route matches to reviewers, who can remediate, escalate, or resolve according to policy.
  • Role groups separate policy configuration, alert review, investigation, and content access so one person does not automatically see every sensitive detail.
Objects and administrative surfaces
  • Insider Risk policies, indicators, alerts, users, and cases — Insider Risk Management in Microsoft Purview.
  • Communication Compliance policies, alerts, reviewers, message evidence, remediation, and escalation — Communication Compliance in Microsoft Purview.
  • DLP and Activity explorer can provide adjacent evidence but retain their own roles and permissions.
When to use it
  • Use Insider Risk for patterns such as unusual data movement around departure or repeated risky activities across time.
  • Use Communication Compliance for messages that may involve harassment, threats, regulatory language, conflicts of interest, or another defined communication policy.
  • Use DLP when the immediate need is to warn or block sensitive-data movement.
Security and governance implications
  • Use need-to-know role groups, privacy counsel and documented policies, pseudonymization where appropriate, and controlled escalation.
  • Define legitimate business contexts and review standards so ordinary behavior is not automatically treated as misconduct.
  • Audit reviewer and investigator access to sensitive employee evidence.
Troubleshooting signals
  • Confirm policy scope, trigger, indicators/classifiers, time window, supported location, role assignment, and processing delay.
  • Open the underlying evidence and distinguish a policy match from a validated case before escalating.
  • If two tools report the same activity, compare their questions and evidence instead of assuming duplicate or contradictory results.
More detail
  • Insider Risk Management asks “Which user behavior pattern might represent insider risk?” Policies combine scoped users, triggering events, and indicators such as unusual downloads, sharing, or data movement. Alerts can be reviewed and escalated to cases.
  • Communication Compliance asks “Which messages might violate a communication policy?” Policies can use classifiers, keywords, conditions, and scoped communication channels to identify messages for reviewer workflows.
  • The same organization can use DLP, Insider Risk, and Communication Compliance together. DLP controls a sensitive-data action, Insider Risk correlates broader user behavior, and Communication Compliance reviews message content and conduct.
  • Privacy protections matter because these tools inspect employee-related signals. Role separation, pseudonymization where available, limited scope, documented escalation, and human review reduce misuse and premature conclusions.
  • A policy alert is a signal. Reviewers inspect context and evidence, determine whether behavior is expected or policy-relevant, and follow an approved investigation/remediation process.

Ready for the quiz?

  • When should you choose Insider Risk instead of Communication Compliance?
  • How can DLP and Insider Risk address the same event differently?
  • Why is an alert not proof of malicious intent?
  • What governance safeguards matter when reviewing employee-related signals?

Related objectives

  • D2.1.a — Understand features and capabilities of Microsoft Purview Information Protection, Microsoft Purview Data Loss Prevention (DLP), Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance, Microsoft Purview Data Security Posture Management (DSPM) for AI, and Microsoft Purview Data Lifecycle Management
  • D2.3.c — Identify risks by using Insider Risk Management
  • D2.3.e — Identify policy violations generated by Communication Compliance

Learn more

Free Microsoft 365 Copilot and Agent Administration Fundamentals prep

Build focused AB-900 quizzes from skill areas, topics, and product references.

Practice with exam-style multiple-choice and multiple-response questions, score breakdowns, explanations, and a compact reference for this lane's official exam domains.

Read Topics Build a quiz

Exam Weights

Quiz builder

Choose your practice set

Mode

Exam fidelity: Microsoft does not identify the specific item types that will appear on an individual exam before delivery. This lane counts multiple-choice and multiple-response items as exam-style practice. Ordering and matching are supplemental learning exercises and do not count toward exam-style accuracy. Difficulty labels are calibrated to AB-900 Fundamentals, not a Microsoft-published question rating.

Reference

AB-900 topics and reference map

Study links

AB-900 resources