Loading...

Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender

Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender

Microsoft Purview Insider Risk Management triage agent summaries will appear in Microsoft Defender alerts, providing AI-generated insights to streamline investigations. This feature rolls out from mid-August to December 2026, enabling easier alert review without changing existing configurations. No action is needed if prerequisites are met. What and why We’re introducing Insider Risk Management (IRM) triage agent summaries in Microsoft Defender. This enhancement helps investigators review key risk insights directly from the Defender alert queue, reducing the need to switch between security tools during alert triage. When the IRM triage agent is enabled and Insider Risk Management alerts are shared with Microsoft Defender, supported alerts will include AI-generated summaries such as alert categorization, investigation findings, observed risk patterns, and relevant user context. Investigators can continue to access the complete investigation experience in Microsoft Purview for deeper analysis. This message is associated with Microsoft 365 Roadmap ID 567472. Rollout schedule Public Preview: Beginning in mid-August 2026 and expected to complete in early September 2026 General Availability (Worldwide): Beginning in early December 2026 and expected to complete in late December 2026  Impact on your organization Who is affected Organizations that share Microsoft Purview Insider Risk Management alerts with Microsoft Defender Organizations that have the IRM triage agent enabled and active Security analysts and investigators who review Insider Risk Management alerts in Microsoft Defender Platforms and services Microsoft Defender Microsoft Purview Insider Risk Management Web What will happen Supported Insider Risk Management alerts in Microsoft Defender will display IRM triage agent summaries:  View image in new tab Summaries may include alert categorization, investigation findings, identified risk patterns, and relevant user context. The feature will be enabled automatically for organizations that meet the prerequisites. Existing alert-sharing configurations between Insider Risk Management and Microsoft Defender will be preserved. There is no impact to existing configurations or workflows. After rollout, investigators can: Review Insider Risk Management alerts in Microsoft Defender. Access the full investigation experience in Microsoft Purview when needed. Action required and recommendations: No action is required if your organization already meets the prerequisites. Review the following to ensure readiness: Confirm that Insider Risk Management alerts are […]

The post Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Microsoft Excel: Excel canvas

Excel canvas, a new Copilot feature in Microsoft Excel, creates dynamic reports with visualizations and insights that update automatically wit...

2 days ago

Dynamics 365 Contact Center – Use role-based enforcement for recording and transcription downloads

We are announcing the ability to use role-based enforcement for recording and transcription downloads in Dynamics 365 Contact Center. This fea...

2 days ago

Microsoft Outlook: Right-click to customize the classic ribbon

Microsoft Outlook now allows users to customize the classic ribbon by right-clicking on the Home or View tab to select commands and arrange th...

2 days ago

Microsoft Exchange Online: Exchange Web Services (EWS) enforcement update for EWSAllowedAppIDs

Starting October 10, 2026, Exchange Online tenants must configure EWSAllowedAppIDs to allow Exchange Web Services (EWS) access; EWSEnabled=Tru...

2 days ago

Microsoft Entra App Gallery: Self-service onboarding for new applications

Microsoft Entra App Gallery introduces self-service onboarding for new applications, allowing ISVs to validate SSO and provisioning integratio...

2 days ago

Upgraded call history in Teams Calls app

Teams Calls app call history is upgraded to consolidate missed calls and voicemails into single entries and expand history from 100 to 3,000 r...

2 days ago

Power Automate – Enable Process Intelligence Studio in object-centric process mining

We are announcing the availability of Process Intelligence Studio in object-centric process mining in Power Automate Process Mining. This feat...

2 days ago

Dynamics 365 Contact Center – Use after conversation presence status for wrap-up activities

We are announcing the ability to use after conversation presence status for wrap-up activities in Dynamics 365 Contact Center. This feature wi...

2 days ago

Dynamics 365 Finance and Operations cross-app: Migrate finance and operations environments from Lifecycle Services to Power Platform admin center

The self-service environment migration feature moves management of an existing finance and operations apps environment from Microsoft Dynamics...

2 days ago

Microsoft Teams: Start side conversations during meetings

Keep collaboration moving without disrupting the main discussion. Start and continue one-to-one or small-group conversations directly from a m...

2 days ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.