Microsoft Purview compliance portal: Insider Risk Management - IRM alerts in XDR
Summary
With this feature, IRM alerts and other supporting data will be available in the following Microsoft Defender XDR experiences: 1. IRM alerts will be surfaced in unified alert and Incident queue in Microsoft Defender XDR. 2. IRM alerts, Indicators, and enriched events will be available in Microsoft Defender XDR advanced hunting. Analysts can leverage KQL queries to identify potentially hidden risky patterns in data security related user activity. 3. IRM alert, Indicators, and enriched events will be exposed through Graph API. This feature can be enabled through “Share data with Microsoft Defender XDR” within Microsoft Insider Risk Management settings. To ensure privacy of the data, all IRM data in Microsoft Defender XDR can only be accessed by users with Insider risk analyst or Insider risk investigator permissions in Purview. Existing analysts accessing IRM data in purview will continue to access IRM data in Microsoft Defender XDR. IRM data in Microsoft Defender XDR does not honor anonymization. This is to enable effective correlation of IRM alerts with alerts from other solutions in Microsoft Defender XDR platform (such as Defender for Endpoint, Defender for Cloud apps, etc.). Mi…
- Status
- Launched
- General availability target
- Aug 2025
- Preview target
- Jan 2025
- Products
- Microsoft Purview
- Clouds
- Worldwide (Standard Multi-Tenant)
- Release phases
- General Availability, Preview
- Platforms
- Web
- Added to the roadmap
- 5 Nov 2024
- Last changed
- 3 Dec 2025 · 10mo ago