Skip to content

Commit a8de3a6

Browse files
committed
investigate module
1 parent b9d9ca9 commit a8de3a6

18 files changed

+256
-9
lines changed
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-insider-risk-investigate-alerts.activity-explorer-tab
3+
title: Investigate activity details with the Activity explorer tab
4+
metadata:
5+
title: Investigate activity details with the Activity explorer tab
6+
description: "Investigate activity details with the Activity explorer tab."
7+
ms.date: 04/15/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 6
14+
content: |
15+
[!include[](includes/activity-explorer-tab.md)]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
### YamlMime:ModuleUnit
2+
uid: learn.wwl.purview-insider-risk-investigate-alerts.all-risk-factors
3+
title: Analyze alert context with the All risk factors tab
4+
metadata:
5+
title: Analyze alert context with the All risk factors tab
6+
description: "Analyze alert context with the All risk factors tab."
7+
ms.date: 04/15/2025
8+
author: wwlpublish
9+
ms.author: riswinto
10+
ms.topic: unit
11+
azureSandbox: false
12+
labModal: false
13+
durationInMinutes: 5
14+
content: |
15+
[!include[](includes/all-risk-factors.md)]
Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
The **Activity explorer** tab in Microsoft Purview Insider Risk Management helps analysts investigate the full context of potentially risky behavior. This tab shows a timeline of user activity that contributes to the alert, with detailed metadata to support investigation, filtering, and review.
2+
3+
Use this tab to confirm what triggered the alert and identify patterns or supporting evidence that indicate whether further action is needed.
4+
5+
:::image type="content" source="../media/activity-explorer-tab.png" alt-text="Screenshot showing the Activity explorer tab in Microsoft Purview Insider Risk Management." lightbox="../media/activity-explorer-tab.png":::
6+
7+
## Review activity details
8+
9+
Each row in the Activity explorer represents an event associated with the alert or broader user activity. Columns show details such as:
10+
11+
- Date and time of the event
12+
- Activity type (for example, file download or risky prompt)
13+
- File name and location
14+
- Associated sensitivity label, if present
15+
- Risk score and related risk factors
16+
17+
You can select an item to open the activity details pane and review:
18+
19+
- Event metadata, such as file path or recipient
20+
- Assigned risk score
21+
- Indicators that contributed to the risk level
22+
23+
This level of detail supports deeper investigation of user behavior.
24+
25+
## Filter activity for investigation
26+
27+
To help focus your review, use filters at the top of the page to narrow the activity list. You can filter by:
28+
29+
- **Activity scope**: Show all scored activity for the user or only activity associated with this specific alert
30+
- **Risk factor**: Focus on specific indicators like sequences, cumulative exfiltration, unallowed domains, or priority content
31+
- **Review status**: Hide previously reviewed items to focus on new activity
32+
33+
Filtering helps streamline triage and identify which events require the most attention.
34+
35+
## Customize the view
36+
37+
Customizing the view helps you focus on relevant attributes during triage. To match your investigation workflow, you can:
38+
39+
- Select or remove columns using **Customize columns**
40+
- Sort the view by date or risk score
41+
- Save custom filter and column views for reuse
42+
43+
These options help personalize the workspace so investigators can focus on what matters most.
44+
45+
## Understand activity count discrepancies
46+
47+
The number of activities shown in Activity explorer might not always match the number of raw event logs. Common reasons include:
48+
49+
- **Cumulative exfiltration detection**: Similar activities are deduplicated and scored as a single risk event
50+
- **Policy changes**: If policy settings change after events occur, prior events might be excluded
51+
- **Excluded items in sequences**: Files excluded from risk scoring might still appear if they're part of a larger sequence
52+
53+
These factors explain why sequences or exfiltration activity counts might differ between views.
54+
55+
## Investigate excluded items in sequences
56+
57+
Even when a file type is excluded from scoring, it might still show up in a sequence if it contributes to broader risk. For example, a .png file normally excluded from policy might appear in a sequence if it was used during an obfuscation attempt.
58+
59+
In these cases:
60+
61+
- A score of 0 appears for the excluded event
62+
- Excluded events are marked as **Excluded** in the activity details
63+
- A link is available to filter and view all excluded events
64+
65+
This helps you understand the full context of a user's behavior, even when individual events aren't scored directly.
66+
67+
## Save views for future use
68+
69+
If you create a useful filter and column setup, you can select **Save this view** to reuse it later. Saved views include both filters and column selections, allowing consistent triage workflows across analysts or alert types.
70+
71+
Select **Views** to load saved views at any time. Views can be personal or shared depending on how your team manages investigations.
Lines changed: 38 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
The **All risk factors** tab in Microsoft Purview Insider Risk Management provides a summary of potentially risky activity associated with an alert. This view helps investigators understand why an alert might be significant by showing which risk signals are present, even if those signals weren’t the direct cause of the alert.
2+
3+
Use this tab to evaluate the broader context of a user's behavior and decide whether to investigate further, dismiss the alert, or take action.
4+
5+
:::image type="content" source="../media/all-risk-factors-tab.png" alt-text="Screenshot showing the All risk factors tab in Microsoft Purview Insider Risk Management." lightbox="../media/all-risk-factors-tab.png":::
6+
7+
## Risk factors shown in this tab
8+
9+
The All risk factors tab surfaces several types of behavior that might increase a user's overall risk level:
10+
11+
- **Top exfiltration activities**: Lists the most frequent exfiltration actions, such as archiving or uploading files.
12+
- **Cumulative exfiltration**: Shows whether repeated actions build over time to indicate rising risk.
13+
- **Sequences of activities**: Highlights related activities that form a recognizable risk sequence.
14+
- **Priority content**: Indicates whether the user interacted with files marked as sensitive or business-critical.
15+
- **Unallowed domains**: Flags any file or data transfers to domains that aren't permitted by policy.
16+
- **Unusual behavior or high-impact user status**: Detects abnormal patterns or identifies users whose role or access level contributes to elevated risk.
17+
18+
Not all alerts are directly caused by these factors, but the tab helps you assess what else might be happening that could influence the user’s risk level.
19+
20+
> [!TIP]
21+
> Risk signals shown on this tab might not be the reason the alert was triggered. Always check the activity listed in the alert summary before deciding how to respond.
22+
23+
## Use the Content detected section
24+
25+
The **Content detected** section on this tab shows specific items involved in each risk activity. Selecting a listed item allows you to:
26+
27+
- View metadata such as file name, type, location, and sensitivity label if present
28+
- Open the **Activity explorer** to see how that item fits into a broader timeline of activity
29+
30+
:::image type="content" source="../media/all-risk-factors-content-detected.png" alt-text="Screenshot showing the Content detected section of the All risk factors tab in Microsoft Purview Insider Risk Management." lightbox="../media/all-risk-factors-content-detected.png":::
31+
32+
This view helps you validate whether the behavior was risky and supports more informed decisions.
33+
34+
## Important behavior to understand
35+
36+
- **Risk factor summaries don't always match the trigger.** An alert might be triggered by access to priority content, but the tab could instead highlight unrelated risky browsing activity or sequences that increase concern.
37+
- **Sequences can include excluded events.** Even if a file type is excluded from scoring, it can still appear in a sequence if it contributes to broader risky behavior. For example, a .png file might normally be excluded but still appears if used during an obfuscation attempt.
38+
- **Use the Content detected section to investigate further.** This section links to Activity explorer, where you can view detailed events and associated content. It serves as a key entry point for deeper review.

learn-pr/wwl-sci/purview-insider-risk-investigate-alerts/includes/introduction.md

Whitespace-only changes.

learn-pr/wwl-sci/purview-insider-risk-investigate-alerts/includes/investigate-triage-alerts.md

Lines changed: 40 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,24 @@ The Alert dashboard in Microsoft Purview Insider Risk Management helps investiga
22

33
## Overview of the Alert dashboard
44

5-
The Alert dashboard provides a centralized view of all alerts generated by insider risk policies. Each alert is tied to a single user and includes:
5+
The Alerts dashboard provides a centralized queue of all alerts generated by Insider Risk Management policies. Each row in the dashboard represents an individual alert and includes key fields to support triage and prioritization at a glance:
66

7-
- **Alert summary**: Displays the risk severity level, alert score, activity that triggered the alert, and triggering event.
8-
- **User details and history**: Shows general user information and past alerts, including unresolved or repeated risk patterns.
9-
- **Tabs for deeper analysis**: Includes tabs for **All risk factors**, **User activity**, and **Activity explorer** to review specific behavior in detail.
7+
- **ID**: A unique identifier for each alert.
8+
- **Copilot icon**: Indicates whether Copilot is available to summarize the alert.
9+
- **Users**: The individual associated with the potentially risky activity.
10+
- **Policy**: The Insider Risk Management policy that generated the alert.
11+
- **Status**: Shows if the alert is new, confirmed, dismissed, or resolved.
12+
- **Spotlight**: Highlights high-priority alerts that meet specific risk criteria.
13+
- **Alert severity**: Automatically calculated risk level—Low, Medium, or High.
14+
- **Time detected**: Indicates when the alert was generated.
15+
- **Assigned to**: Shows who, if anyone, is currently assigned to investigate the alert.
16+
- **Case**: Lists any case associated with the alert.
1017

11-
Alerts are automatically categorized by severity (low, medium, high) and can be filtered by status, policy, risk factor, or other criteria. Each new insight related to a user is added to their existing alert instead of generating a new one.
18+
:::image type="content" source="../media/insider-risk-alerts-dashboard.png" alt-text="Screenshot showing the Alerts dashboard in Insider Risk Management." lightbox=" ../media/insider-risk-alerts-dashboard.png":::
1219

13-
> [!NOTE]
14-
> Only unrestricted administrators or users with proper role assignments can view alerts, depending on how administrative units are scoped.
20+
You can use filters, saved views, and column customization to focus on the alerts that matter most. Selecting an alert opens the Alert details page, where you can investigate activity, view user history, and take action such as dismissing or escalating the alert.
1521

16-
## Filtering and customizing views
22+
### Filtering and customizing views
1723

1824
When working with a high volume of alerts, filtering and customizing your view can improve efficiency:
1925

@@ -22,8 +28,32 @@ When working with a high volume of alerts, filtering and customizing your view c
2228
- **Customize columns** to show or hide fields like policy name, time detected, or alert status.
2329
- **Search by keyword** such as user principal name (UPN), alert ID, or assigned admin.
2430

31+
:::image type="content" source="../media/insider-risk-filter-alerts.png" alt-text="Screenshot highlighting the filters on the Alerts dashboard." lightbox=" ../media/insider-risk-filter-alerts.png":::
32+
33+
### Spotlight high-priority alerts
34+
35+
Insider Risk Management includes a **Spotlight** feature that automatically highlights high-priority alerts in the alert queue. This helps analysts focus on the most critical cases first. Spotlight uses rule-based logic to evaluate alerts based on activity type, tags, and risk scoring patterns observed across organizations. Spotlighted alerts appear visually distinct in the alert list and support faster triage decisions.
36+
37+
> [!TIP]
38+
> Spotlight is especially useful in environments with high alert volume. It brings attention to alerts that might require immediate review.
39+
2540
These tools help reduce investigation time and support consistency across teams.
2641

42+
## Review individual alerts
43+
44+
After identifying an alert of interest in the dashboard, you can select it to open the Alert details page. This view provides a deeper investigation workspace with information about the triggering activity, user context, and risk factors. From here, analysts and investigators can assess whether the alert warrants further action.
45+
46+
- **Alert summary**: Displays the risk severity level, alert score, activity that triggered the alert, and triggering event.
47+
- **User details and history**: Shows general user information and past alerts, including unresolved or repeated risk patterns.
48+
- **Tabs for deeper analysis**: Includes tabs for **All risk factors**, **User activity**, and **Activity explorer** to review specific behavior in detail.
49+
50+
:::image type="content" source="../media/insider-risk-alert-details.png" alt-text="Screenshot showing alert details in Insider Risk Management." lightbox=" ../media/insider-risk-alert-details.png":::
51+
52+
Alerts are automatically categorized by severity (low, medium, high) and can be filtered by status, policy, risk factor, or other criteria. Each new insight related to a user is added to their existing alert instead of generating a new one.
53+
54+
> [!NOTE]
55+
> Only unrestricted administrators or users with proper role assignments can view alerts, depending on how administrative units are scoped.
56+
2757
## Triage and take action on alerts
2858

2959
Once you've identified an alert that needs review, you can triage and take action directly from the Alert details page:
@@ -52,6 +82,8 @@ Copilot can also suggest questions to help refine your summary, such as:
5282
- List all sequential activities involving this user.
5383
- Did the user engage in any unusual behavior?
5484

85+
:::image type="content" source="../media/insider-risk-security-copilot.png" alt-text="Screenshot showing embedded Security Copilot in Insider Risk Management." lightbox=" ../media/insider-risk-security-copilot.png":::
86+
5587
These insights make it easier to prioritize the most important alerts and dismiss those that don't require follow-up.
5688

5789
## Retention and alert limits
Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
## Investigate ongoing risk with the User activity tab
2+
3+
The **User activity** tab in Microsoft Purview Insider Risk Management shows a visual timeline of potentially risky behavior over time. This view helps investigators assess whether a user’s activity is ongoing, escalating, or part of a broader pattern.
4+
5+
Use this tab to evaluate risk across multiple alerts and understand how individual actions fit into a larger risk profile.
6+
7+
:::image type="content" source="../media/user-activity-tab.png" alt-text="Screenshot showing the User activity tab in Microsoft Purview Insider Risk Management." lightbox="../media/user-activity-tab.png":::
8+
9+
## Identify patterns over time
10+
11+
This view uses colored bubbles to show activity categories and risk scores across a timeline. Bubbles represent distinct risk events. Select any bubble to open a details pane that includes:
12+
13+
- Date of the event
14+
- Risk category (for example, Exfiltration or Obfuscation)
15+
- Risk score
16+
- Number of associated files or emails, with links for review
17+
18+
This visual layout makes it easier to spot repeated behaviors or concerning trends.
19+
20+
## Understand risk sequences
21+
22+
Sequences are shown with connecting lines between bubbles. These indicate related events that are part of a broader risk pattern. When a sequence is selected, the details pane includes:
23+
24+
- Name and date range of the sequence
25+
- Combined risk score
26+
- Total number of events and links to associated content
27+
28+
This view helps connect the dots between activities that might seem low-risk individually but are more significant together.
29+
30+
## Use the scatter plot to visualize risk patterns
31+
32+
The User activity tab includes a **color-coded scatter plot** that shows potentially risky activity over time. Each bubble represents a scored event. The vertical position indicates the risk score, and the horizontal position shows when the event occurred.
33+
34+
Use this visual timeline to:
35+
36+
- See when risk activity happened and how it changed over time
37+
- Spot clusters or gaps in activity
38+
- Identify risk sequences, shown with connecting lines and icons
39+
40+
## Filter and sort user activity
41+
42+
To focus your analysis, use the filters and sorting options at the top of the page:
43+
44+
- **Risk category**: Filter for sequences or high-risk events
45+
- **Activity type**: Narrow to specific behaviors, such as AI usage or deletion
46+
- **Date range**: View activity over 1, 3, or 6 months
47+
- **Sort by**: Organize the timeline by risk score or event date
48+
- **Review status**: Filter out activity that has already been reviewed
49+
50+
These filters make it easier to review large amounts of user activity.
51+
52+
## Interpret the full user timeline
53+
54+
The User activity tab provides a complete view of risk-assigned behavior:
55+
56+
- Shows events that span multiple alerts
57+
- Displays cumulative exfiltration risk as a visual trend line
58+
- Highlights sequences that include excluded file types if relevant to the risk pattern
59+
- Uses a color-coded legend to categorize risk events
60+
61+
This comprehensive view supports better decision-making during investigations and case reviews.

learn-pr/wwl-sci/purview-insider-risk-investigate-alerts/introduction.yml

Whitespace-only changes.

learn-pr/wwl-sci/purview-insider-risk-investigate-alerts/investigate-triage-alerts.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,6 +10,6 @@ metadata:
1010
ms.topic: unit
1111
azureSandbox: false
1212
labModal: false
13-
durationInMinutes: 6
13+
durationInMinutes: 10
1414
content: |
1515
[!include[](includes/investigate-triage-alerts.md)]
91.1 KB
Loading

0 commit comments

Comments
 (0)