https://store-images.s-microsoft.com/image/apps.8664.ab1c073d-4878-4e72-8d00-c8a8916024c5.987bb684-4b29-4819-bd47-a2403c5f66e7.a8869fb8-5514-4044-a41c-e061e80178ef

Insider Risk Management triage agent

Microsoft Security

Insider Risk Management triage agent

Microsoft Security

The Purview Insider Risk Management triage agent uses AI to prioritize high-risk insider activities

The Microsoft Purview Insider Risk Management triage agent is an AI-powered tool designed to help security teams efficiently manage insider risk alerts. It provides a managed alert queue that highlights the most critical activities by evaluating both the content and potential intent behind them, based on the organization’s configured risk parameters. By offering a clear explanation of its prioritization logic, the agent reduces the time and complexity involved in manual triage, enabling teams to respond faster and more effectively to potential insider threats.
Agent tasks: Alert triage, risk scoring, threat prioritization, contextual analysis, incident classification
  • Agent workflow
  • Inputs: User activity signals, alert metadata, organizational risk tolerance settings
  • Outputs: Prioritized insider risk alert queue with rationale for categorization and recommended response
  • https://store-images.s-microsoft.com/image/apps.43798.ab1c073d-4878-4e72-8d00-c8a8916024c5.987bb684-4b29-4819-bd47-a2403c5f66e7.705432f3-581d-40b5-9bde-93639ecb2da7
    https://store-images.s-microsoft.com/image/apps.43798.ab1c073d-4878-4e72-8d00-c8a8916024c5.987bb684-4b29-4819-bd47-a2403c5f66e7.705432f3-581d-40b5-9bde-93639ecb2da7