Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender
Microsoft Purview Insider Risk Management triage agent summaries will appear in Microsoft Defender alerts, providing AI-generated insights to streamline investigations. This feature rolls out from mid-August to December 2026, enabling easier alert review without changing existing configurations. No action is needed if prerequisites are met. What and why We’re introducing Insider Risk Management (IRM) triage agent summaries in Microsoft Defender. This enhancement helps investigators review key risk insights directly from the Defender alert queue, reducing the need to switch between security tools during alert triage. When the IRM triage agent is enabled and Insider Risk Management alerts are shared with Microsoft Defender, supported alerts will include AI-generated summaries such as alert categorization, investigation findings, observed risk patterns, and relevant user context. Investigators can continue to access the complete investigation experience in Microsoft Purview for deeper analysis. This message is associated with Microsoft 365 Roadmap ID 567472. Rollout schedule Public Preview: Beginning in mid-August 2026 and expected to complete in early September 2026 General Availability (Worldwide): Beginning in early December 2026 and expected to complete in late December 2026 Impact on your organization Who is affected Organizations that share Microsoft Purview Insider Risk Management alerts with Microsoft Defender Organizations that have the IRM triage agent enabled and active Security analysts and investigators who review Insider Risk Management alerts in Microsoft Defender Platforms and services Microsoft Defender Microsoft Purview Insider Risk Management Web What will happen Supported Insider Risk Management alerts in Microsoft Defender will display IRM triage agent summaries: View image in new tab Summaries may include alert categorization, investigation findings, identified risk patterns, and relevant user context. The feature will be enabled automatically for organizations that meet the prerequisites. Existing alert-sharing configurations between Insider Risk Management and Microsoft Defender will be preserved. There is no impact to existing configurations or workflows. After rollout, investigators can: Review Insider Risk Management alerts in Microsoft Defender. Access the full investigation experience in Microsoft Purview when needed. Action required and recommendations: No action is required if your organization already meets the prerequisites. Review the following to ensure readiness: Confirm that Insider Risk Management alerts are […]
The post Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender appeared first on M365 Admin.
Published on:
Learn moreWe can help you with Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender
If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.
Related posts
Microsoft Teams: Enhanced real-time alerting rule management in the Teams admin center
Microsoft Teams will enhance Real-Time Alerting rule management in the Teams admin center by enabling rule duplication, bulk user uploads, and...
Copilot Studio – Use MCP-compliant tools in agent workflows
We are announcing the ability to use MCP (model context protocol) – compliant tools in agent workflows in Microsoft Copilot Studio. This...
Microsoft Teams: Personal message reminders for chat and channels
Microsoft Teams will introduce personal message reminders for chat and channel messages in October 2026. Users can set, manage, and receive no...
M365 Copilot: Tell Copilot what you need directly from the Copilot button in Word, Excel, and PowerPoint
Microsoft 365 Copilot adds a new prompt input directly on the Copilot button in Word, Excel, and PowerPoint for faster, contextual content cre...
Microsoft Outlook for iPad: Minimize email drafts and return to them later
Outlook for iPad will allow users to compose emails in a separate window and minimize drafts to return later, enhancing multitasking. This fea...
Microsoft Purview eDiscovery: Select user-owned SharePoint Embedded containers as a data source
Microsoft Purview eDiscovery will support selecting user-owned SharePoint Embedded containers as data sources for cases, searches, and holds s...
Microsoft Purview: Removing pay-as-you-go requirements for Edge for Business DLP unmanaged app protections
Starting mid-October 2026, Microsoft Purview will remove the pay-as-you-go billing requirement for inline collection and DLP policies protecti...
Data Privacy: Microsoft Online Services Subprocessor Disclosure
This notice provides an update to the Microsoft Online Services Subprocessors List. Microsoft may engage non-Microsoft organizations to help p...
Microsoft Graph: User.ReadBasic.All will no longer allow reading user app role assignments and license details
User.ReadBasic.All will no longer provide access to user app role assignments and license details starting mid-September 2026 to fix a securit...
30-Day Reminder: Windows Server 2022 will reach end of mainstream support on October 13, 2026
On October 13, 2026, Windows Server 2022 will reach end of mainstream support. The October 2026 security update will be the last mainstream su...