Study workspace

Prepare for SC-200 with a reference that remembers your progress.

All nine learning paths now run in the new architecture. Select one to reveal its brief and modules.

09 / 09

Choose a learning path

0/404 units
09Mitigate threats using Microsoft Purview4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows0/42 units complete
Learning path 09 · Mitigate threats using Microsoft Purview

4 modules · 42 units · DLP alerts, insider risk, Audit, eDiscovery, Defender XDR, and investigation workflows

0%

Study focus

Data risk response

Investigate DLP and insider-risk alerts, correlate evidence, remediate activity, and manage cases.

Evidence discovery

Search, validate, retain, and export evidence with Microsoft Purview Audit and eDiscovery.

4 modules · 42 units

Select one or more modules

Each click adds or removes a module from your workspace. Units remain closed until you open them.

02

Module 2

Investigate insider risk alerts and related activity

Focus: alert prioritization, policy tuning, risk factors, activity timelines, Defender correlation, and case management.
0/13
01 / 13Introduction

Insider Risk Management correlates signals that may indicate accidental or intentional harm by people with legitimate access. Investigation must balance security, privacy, legal requirements, and need-to-know access.

Official lessonInsider risk objectives
02 / 13Understand insider risk alerts and investigations

Policies combine triggering events, risk indicators, user scope, time windows, and thresholds. Alerts represent risk-scored activity patterns, not proof of wrongdoing. Triage should test business context and corroborating evidence while preserving user privacy.

Official lessonSignals, policies, and alerts
03 / 13Manage alert volume in insider risk management

Control volume through user scope, indicators, thresholds, trigger conditions, time windows, exclusions, and policy health recommendations. Tune from observed false-positive patterns and missed-risk scenarios rather than simply suppressing high-volume sources.

Official lessonPolicy thresholds and queue quality
04 / 13Investigate and triage insider risk alerts in Microsoft Purview

Use the Alerts dashboard to prioritize by severity, risk score, policy, detected time, and status. Open the alert to inspect indicators, triggering events, user context, chronology, and content. Dismiss benign alerts or create a case when deeper investigation is warranted.

Official lessonAlert dashboard and triage
05 / 13Investigate insider risk alerts with Security Copilot and AI agents

Copilot can summarize alerts, activity patterns, and risk factors; AI agents can accelerate repeatable analysis. Confirm all AI output against underlying records, follow organizational privacy rules, and keep a human accountable for case decisions.

Official lessonAI-assisted insider risk investigation
06 / 13Analyze alert context with the All risk factors tab

The All risk factors tab aggregates contributing indicators and risk events so the analyst can understand why the score increased, compare activity categories, and identify the highest-value pivots. Separate a single unusual event from a sustained, multi-signal pattern.

Official lessonRisk-factor context
07 / 13Investigate activity details with the Activity explorer tab

Activity explorer shows event-level details with filters for date, activity type, application, device, domain, and other attributes. Use it to validate the exact operations behind an alert and identify files, destinations, volume, and sequences.

Official lessonEvent-level activity analysis
08 / 13Review patterns over time with the User activity tab

The User activity view places alerts, risk indicators, and events on a timeline. Look for changes from baseline, bursts before a departure event, movement across channels, and repeated actions that are individually low risk but collectively significant.

Official lessonUser behavior timeline
09 / 13Investigate insider risk alerts in Microsoft Defender XDR

Pivot to Defender XDR when activity may connect to compromised identity, endpoint malware, cloud app misuse, or another security incident. Correlate the user, devices, alerts, files, network activity, and incident timeline before attributing intent.

Official lessonInsider risk and XDR correlation
10 / 13Manage and take action on insider risk cases

Create a case for deeper review, assign contributors, add alerts and evidence, document notes, and coordinate permitted actions such as user notification, escalation, HR or legal referral, or security response. Resolve with an accurate classification and audit trail.

Use role groups and privacy settings to restrict access and pseudonymize user identity where organizational policy requires it.

Official lessonCase lifecycle and actions
11 / 13Exercise - Investigate potential data theft using Insider Risk Management

Triage a potential data-theft alert, inspect risk factors and detailed activity, review the user timeline, correlate relevant context, create or update a case, and document a proportionate outcome.

Official exercisePotential data theft investigation
12 / 13Module assessment

Review policy triggers and indicators, alert scoring and thresholds, queue tuning, risk-factor and activity tabs, Copilot validation, Defender XDR pivots, privacy controls, and case actions.

Official assessmentInsider risk knowledge check
13 / 13Summary

Insider risk investigations require contextual evidence, careful attribution, privacy-aware access, cross-team governance, proportionate action, and policy tuning based on outcomes.

Official lessonModule summary
End of learning pathMitigate threats using Microsoft Purview