Understand data protection and governance tasks for Microsoft 365 and Copilot
Insider Risk and Communication Compliance
Differentiate risky user-behavior investigation from review of policy-relevant communications.
What you need to know
- Insider Risk Management correlates configured indicators and triggering events to surface potentially risky user activity.
- Communication Compliance detects and supports review of messages that might violate regulatory, business-conduct, or organizational communication policies.
- Both solutions use privacy-aware workflows, scoped roles, alerts, and human review.
Objects and administrative surfaces
- Policies, alerts, users, cases, and indicators — Microsoft Purview portal.
- Communication reviewers and Insider Risk investigators require distinct role assignments.
How it works
- Policy matches and risk indicators are signals for review rather than automatic conclusions about intent.
- Solutions can integrate signals, but each retains its own investigative purpose and permissions.
When to use it
- Use Insider Risk Management for patterns such as unusual exfiltration by a departing employee.
- Use Communication Compliance for harassing, threatening, regulated, or otherwise policy-relevant messages.
Security and governance implications
- Apply need-to-know roles, pseudonymization where available, and documented escalation.
- Avoid using either solution as unreviewed employee surveillance.
Troubleshooting signals
- Confirm policy scope, indicators/classifiers, trigger conditions, reviewer roles, and processing time.
- Open the alert evidence before escalating it to a case.
Exam traps
- DLP focuses on sensitive-data handling; Communication Compliance focuses on messages; Insider Risk combines user-risk indicators.
- An alert needs investigation and does not independently prove wrongdoing.
Key takeaways
- Risky user pattern → Insider Risk; risky message → Communication Compliance.
- Protect privacy and require human review.
Related objectives
- D2.1.a
- D2.3.c
- D2.3.e