Microsoft Purview compliance center: Insider Risk Management - Policy scoping enhancements Beta
Data as of 2 hours ago (9 September 2026)
Description
After further review, we continue rolling this out. We apologize for any inconvenience. With this release, Insider Risk Management administrators can include or exclude specific users, groups, and adaptive scopes within policies. We are also adding support for non-mail enabled Security Groups within IRM policies. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.
Change history
Added to the roadmap 10 March 2025. Tracked here since 1 September 2026. Earliest target we recorded: June 2025 (since tracked — Microsoft may have moved it before we started watching).
Nothing has changed on this item since tracking began on 1 September 2026. Changes appear here as Microsoft updates the feed.