|
| 1 | +Cases in Microsoft Purview Insider Risk Management allow investigators to track user risk over time, review associated alerts, and take action based on the severity and context of the activity. Each case focuses on a single user and can include one or more alerts. Cases are created manually when an alert requires deeper review or coordination with other teams. |
| 2 | + |
| 3 | +Use the **Cases** dashboard to view all active and closed cases, assign ownership, and manage follow-up actions such as escalation, communication, and resolution. |
| 4 | + |
| 5 | +## Respond to alerts |
| 6 | + |
| 7 | +Not all alerts require a case. You can take action directly from the **Alerts** queue by confirming or dismissing alerts as part of your triage process: |
| 8 | + |
| 9 | +- **Dismiss** an alert if it's a false positive or doesn't require further review. |
| 10 | +- **Confirm** an alert to indicate a policy violation and optionally create a case for deeper investigation. |
| 11 | + |
| 12 | +Creating a case is recommended when an alert involves serious risk, multiple incidents, or needs collaboration across teams. Once a case is created, you can take further action such as sending notices, escalating, or resolving with a classification. |
| 13 | + |
| 14 | +## Create and manage cases |
| 15 | + |
| 16 | +Cases are created from alerts when an incident needs further review or response. Once created, cases can be updated with new alerts and managed through their lifecycle. You can: |
| 17 | + |
| 18 | +- Assign or reassign ownership |
| 19 | +- Send an email notice to the user |
| 20 | +- Escalate to Microsoft Purview eDiscovery (Premium) |
| 21 | +- Run Power Automate flows |
| 22 | +- Create or view a connected Microsoft Teams team |
| 23 | +- Resolve the case with a classification of Benign or Confirmed policy violation |
| 24 | + |
| 25 | +You can assign a case to any user with one of these roles: **Insider Risk Management**, **Analyst**, or **Investigator**. |
| 26 | + |
| 27 | +:::image type="content" source="../media/insider-risk-case-details.png" alt-text="Screenshot showing how to create a case in Insider Risk Management." lightbox="../media/insider-risk-case-details.png"::: |
| 28 | + |
| 29 | +## Use the Cases dashboard |
| 30 | + |
| 31 | +The Cases dashboard lists each case and includes key details: |
| 32 | + |
| 33 | +- Case name and ID |
| 34 | +- Assigned user (anonymized if enabled) |
| 35 | +- Status: **Active** or **Closed** |
| 36 | +- Number of alerts |
| 37 | +- Time opened and last updated |
| 38 | +- Last updated by |
| 39 | + |
| 40 | +You can search by case ID or keywords, and use filters to narrow by status, date opened, or last updated. |
| 41 | + |
| 42 | +To customize the view, select **Customize columns**. To save filters for future use, apply filters and select **Save this view**. |
| 43 | + |
| 44 | +:::image type="content" source="../media/insider-risk-case-details.png" alt-text="Screenshot showing the Cases dashboard in Insider Risk Management." lightbox="../media/insider-risk-case-details.png"::: |
| 45 | + |
| 46 | +## Investigate a case |
| 47 | + |
| 48 | +Selecting a case opens a detailed investigation view with multiple tabs: |
| 49 | + |
| 50 | +- **Case overview**: User identity, department, risk score, associated alerts |
| 51 | +- **Alerts**: Status, severity, and alert ID for each included alert |
| 52 | +- **User activity**: Timeline of scored risk activity from the alert or broader user history |
| 53 | +- **Activity explorer (preview)**: Detailed timeline and metadata for each associated event |
| 54 | + |
| 55 | + **User activity** shows the overall timeline of user risk behavior, while **Activity explorer** focuses on event-level details within the case scope. |
| 56 | + |
| 57 | +- **Forensic evidence**: Screen captures from activity that triggered the alert |
| 58 | +- **Content explorer**: Copies of files and email messages associated with risk alerts |
| 59 | +- **Case notes:** Permanent, timestamped notes added by analysts |
| 60 | +- **Contributors**: Users added to the case for collaboration |
| 61 | + |
| 62 | + :::image type="content" source="../media/insider-risk-case-details.png" alt-text="Screenshot showing details of a case investigation." lightbox="../media/insider-risk-case-details.png"::: |
| 63 | + |
| 64 | +> [!NOTE] |
| 65 | +> Contributors can view the case and add notes, but they can't edit contributor lists or confirm/dismiss alerts. |
| 66 | +
|
| 67 | +## Take action on a case |
| 68 | + |
| 69 | +The case toolbar includes actions for responding to the alert: |
| 70 | + |
| 71 | +### Send email notice |
| 72 | + |
| 73 | +Send a message to the user to reinforce policies or training. Notices are based on templates and are recorded in the **Case notes** tab. |
| 74 | + |
| 75 | +> [!TIP] |
| 76 | +> Sending a notice doesn't close the case. To resolve it, you must select **Resolve case** separately. |
| 77 | +
|
| 78 | +### Escalate for investigation |
| 79 | + |
| 80 | +Use this option to escalate the case to a Microsoft Purview eDiscovery (Premium) case for deeper investigation and legal hold workflows. |
| 81 | + |
| 82 | +### Run Power Automate flows |
| 83 | + |
| 84 | +Trigger flows for common tasks such as: |
| 85 | + |
| 86 | +- Notifying a manager |
| 87 | +- Creating a record in ServiceNow |
| 88 | +- Requesting details from HR |
| 89 | + |
| 90 | +### Create or view Teams team |
| 91 | + |
| 92 | +If Teams integration is enabled in Insider Risk Management settings, a team is created automatically when a case is opened. Teams are archived when a case is resolved. To enable Teams integration: |
| 93 | + |
| 94 | +1. Go to the [Microsoft Purview portal](https://purview.microsoft.com/?azure-portal=true). |
| 95 | +1. Select **Settings** > **Insider Risk Management** > **Microsoft Teams**. |
| 96 | +1. Select the toggle to enable integration with Microsoft Teams. |
| 97 | + |
| 98 | + :::image type="content" source="../media/insider-risk-teams-integration.png" alt-text="Screenshot showing where to enable Teams integration in Microsoft Purview Insider Risk Management." lightbox=" ../media/insider-risk-teams-integration.png"::: |
| 99 | + |
| 100 | +## Resolve a case |
| 101 | + |
| 102 | +When investigation is complete, resolve the case as: |
| 103 | + |
| 104 | +- **Benign**: Behavior is low-risk, accidental, or false positive |
| 105 | +- **Confirmed policy violation**: Behavior is intentional or a serious violation |
| 106 | + |
| 107 | +Enter a reason for the resolution. Resolution actions are recorded in Case notes, and the case status is updated to Closed. |
0 commit comments