Microsoft Purview: Insider Risk Management - Unified alert queue Beta
Data as of 1 hour ago (9 September 2026)
Description
We’re introducing a new unified alert triage experience in Insider Risk Management that brings agent‑driven insights directly into the standard Alerts queue. With this update, analysts can view agent categorizations alongside traditional alert filters and columns in a single, consolidated workflow. The updated alert details panel, enables faster investigation and action from the alerts list page by embedding agent insights directly into the alert experience. To support customer transition, the existing alert and agent triage experience will remain available for 60 days and can be accessed via the Alerts tabs under Users in the left navigation. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.
Change history
Added to the roadmap 27 May 2026. Tracked here since 1 September 2026. Earliest target we recorded: October 2026 (since tracked — Microsoft may have moved it before we started watching).
Nothing has changed on this item since tracking began on 1 September 2026. Changes appear here as Microsoft updates the feed.