Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Purview complianceMedium

A healthcare provider needs to implement a system to monitor and detect potential data exfiltration attempts by employees who have access to patient health information (PHI). Specifically, they are concerned about unusual downloading of large volumes of PHI, sharing PHI with unauthorized external parties, and emailing PHI to personal accounts. The solution must provide alerts and allow for investigation. Which Microsoft Purview solution is best suited for this scenario?

  1. AInsider Risk Management (IRM)
  2. BInformation Barriers (IB)
  3. CCommunication Compliance policies
  4. DData Loss Prevention (DLP) policies
Show answer & explanation

Correct answer: A. Insider Risk Management (IRM)

Insider Risk Management (IRM) is designed to detect, investigate, and act on malicious or inadvertent insider activities that pose a risk to sensitive data, such as large downloads, unauthorized sharing, and emailing to personal accounts, by leveraging activity signals.

Why the other options are wrong

  • B. Information Barriers restrict communication between user groups, not detect data exfiltration.
  • C. Communication Compliance monitors communications for policy violations, not broader data exfiltration behaviors.
  • D. DLP policies prevent specific sensitive data from leaving the organization, but IRM provides broader detection of risky user behaviors.

Insider Risk Management (IRM)

Microsoft Purview Insider Risk Management helps organizations detect, investigate, and act on malicious and inadvertent insider activities that pose a risk to sensitive data and assets.

  • Identifies risky user behaviors (e.g., large downloads, data sharing).
  • Uses signals from Microsoft 365 services.
  • Provides alerts and investigation tools.

Memory trick: Insider risks are caught, before data is naught.

More Implement and manage Microsoft Purview compliance questions