Roadmap › 567472

Microsoft Purview: Insider Risk Management - DS Triage Agent for IRM available in Defender

In development Microsoft Purview Web
General availability
2026-12
Preview
2026-08
Added
09 Jul 2026
Last modified
09 Jul 2026 23:00 UTC
First archived
25 Aug 2026
Release rings
General Availability, Preview
Clouds
Worldwide (Standard Multi-Tenant)

Description

We’re introducing support for Insider Risk Management (IRM) alert agent summaries within Microsoft Defender, enabling investigators to access key triage insights directly in the Defender alert queue. When the IRM Triage Agent is active, IRM alerts surfaced in Microsoft Defender will now include the agent summary—such as agent categorization, investigation summary, identified risk patterns, and relevant user details—helping analysts quickly assess alert severity without leaving their existing Defender workflows. For deeper analysis, investigators can access the full IRM investigation experience within the Microsoft Purview portal. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

View on microsoft.com