In the SC-900 exam, the insider risk and eDiscovery section asks "how threats originating inside the organization are detected, and how electronic evidence is collected when a legal investigation is required." When you consider that data leaks by internal employees are more frequent than attacks by external hackers, it becomes clear why these tools are necessary.
Insider Risk Management
What if a sales employee who has decided to resign secretly copies the company's customer database to a USB drive during their last week? Or a developer who has accepted a job at a competitor sends core source code to their personal email? These situations are hard for security cameras or firewalls to catch, because the person is an internal employee accessing data through legitimate permissions.
Microsoft Purview Insider Risk Management is designed specifically to detect these kinds of internal threats.
Types of Risks Detected
Intellectual property theft: An employee about to leave suddenly downloading or copying large quantities of files to a USB drive Intentional data leakage: Sending confidential documents to personal email or personal cloud storage Security policy violations: Accessing prohibited websites, installing unauthorized software, disabling security tools Insider threat signals: Unusual behavioral patterns from dissatisfied employees
Detecting Anomalous Behavior with AI and ML
Insider Risk Management operates on a machine learning (ML) foundation. Rather than simply noting "a file was downloaded," it compares behavior to the user's usual patterns and looks for anomalies. For example, if an employee who normally opens 10 files per day suddenly starts downloading 500 files a day, that activity is classified as a risk signal.
It also integrates with HR systems to analyze contextual information like resignation notification dates and performance review results. When the signal "this employee gave notice" is combined with "file downloads suddenly spiked," the risk score rises.
Balancing Privacy and Investigation
If internal monitoring becomes too broad, employee privacy concerns arise. Insider Risk Management was designed with this in mind. Until an investigator opens a case, the name of the user who generated the risk signal is displayed anonymously. Only approved investigators can see the actual identity.
Communication Compliance
What if a trader at a large financial firm whispers to a colleague in an internal chat: "We should buy stock in Company A tomorrow, there's going to be an announcement today"? That's insider trading and a serious financial crime. But it's impossible for people to manually review the millions of messages thousands of employees send and receive every day.
Microsoft Purview Communication Compliance automatically analyzes communication channels like Teams, Exchange email, and Yammer to detect problematic content.
What It Detects
Workplace harassment, threats, and offensive language Discriminatory speech (related to race, gender, religion) Sharing of insider trading information Sharing of sensitive information or confidential data Conflict of interest situations
An AI-based classifier automatically analyzes message content and flags messages suspected of policy violations to reviewers. Reviewers then examine the flagged messages and take the necessary action.
Information Barriers
At an investment bank, if the M&A advisory team and the stock trading team share information, it leads to serious conflicts of interest and insider trading. Legally, a "Chinese Wall" must exist between these two teams.
Information Barriers technically block communication and collaboration between specific groups in Microsoft Teams, SharePoint, and OneDrive. This is not merely a policy document — it is a technical control that actually blocks chat, file sharing, and meeting invitations.
For example, if you configure "the research team and the sales team cannot Teams chat with each other," then when a research team member tries to message a sales team member, it is automatically blocked.
eDiscovery — Collecting Electronic Evidence for Legal Investigations
A company is drawn into a lawsuit. The court demands: "Submit all emails and documents related to this project during a specific period three years ago." You need to find relevant materials from among the millions of emails exchanged by thousands of employees. What do you do?
eDiscovery (Electronic Discovery) is a tool for systematically collecting and managing electronic evidence required for legal proceedings or internal investigations.
eDiscovery Processing Stages
Stage 1 — Hold: The very first thing to do is protect relevant data from being deleted. When a hold is applied to a specific user's mailbox or SharePoint site, even if the user attempts to delete content, it is actually preserved.
Stage 2 — Search: Search for relevant content using a variety of criteria such as keywords, date ranges, involved parties, and file types. Exchange email, Teams messages, SharePoint documents, and OneDrive files can all be searched at once.
Stage 3 — Review: Review the search results to select which items are actually legally relevant.
Stage 4 — Export: Export the selected items in a standard format for legal review. Make them available for lawyers or external reviewers to analyze.
Stage 5 — Analysis: Reduce the number of documents to review through duplicate removal, email thread grouping, and relevance analysis.
Standard vs. Premium
| Category | eDiscovery (Standard) | eDiscovery (Premium) | |----------|-----------------------|----------------------| | Key Features | Hold, search, export | Standard + advanced analytics, review sets | | Target | General investigations | Large-scale legal proceedings | | Included License | Microsoft 365 E3 or higher | Microsoft 365 E5 or higher |
Audit — Recording Who Did What
If a security incident occurs and you cannot determine "when did someone access this file, and who was it?", root cause analysis becomes impossible. The Audit feature automatically records all major activities by users and administrators.
Audit (Standard)
The basic auditing feature, included with most Microsoft 365 subscriptions. It records thousands of event types including user logins, file access, email sending, and permission changes. Logs are retained for up to 180 days.
Audit (Premium)
An advanced auditing capability available with Microsoft 365 E5 subscriptions. It records far more events than Standard auditing, and the retention period extends to up to one year (or up to 10 years with additional configuration). It also records specialized events to support security investigations — for example, what search terms were used to access a specific item.
!Audit Standard versus Premium
Exam Key Points
"Detect large-scale file downloads by an employee about to resign" -- Insider Risk Management
"Detect inappropriate content in Teams/email" -- Communication Compliance
"Block communication between specific departments" -- Information Barriers
"Search electronic data for legal proceedings" -- eDiscovery
"Prevent deletion of relevant data" -- eDiscovery Hold
"Record user/admin activity" -- Audit
"180-day default retention" -- Audit (Standard)
"Up to 1-year retention, advanced investigation support" -- Audit (Premium)
Insider Risk = detect internal threats, eDiscovery = support legal investigations