Tools/IRM Policy Planner

IRM Policy Planner

Plan your Insider Risk Management deployment. Choose policy templates, map prerequisites, configure indicators, and simulate scenarios before touching your tenant.

Check off the prerequisites your organization has configured. These determine which policy templates are available and will flag warnings if a policy requires something you have not set up.

Required for all policies

Microsoft 365 E5 or IRM add-on

Insider Risk Management requires M365 E5, E5 Compliance, or the Insider Risk Management add-on license.

Microsoft docs
Microsoft 365 audit log enabled

Audit logging must be turned on for Insider Risk Management to capture user and admin activities.

Microsoft docs

Required by specific templates

HR connector configured

The Microsoft 365 HR connector imports resignation dates, termination dates, performance reviews, and job level changes from your HR system.

Required by:Data theft by departing usersData leaks by risky usersSecurity policy violations by departing usersSecurity policy violations by risky users
Microsoft docs
DLP policies active

Data Loss Prevention policies with High severity alerts configured. Required as a triggering event for data leak templates.

Microsoft docs
Defender for Endpoint integrated

Microsoft Defender for Endpoint must be configured and sharing alerts with the Purview portal for security violation templates.

Required by:Security policy violationsSecurity policy violations by departing usersSecurity policy violations by risky usersSecurity policy violations by priority users
Microsoft docs
Healthcare connector configured

The Microsoft Healthcare connector imports activity data from your EMR system for patient data misuse detection.

Required by:Patient data misuse
Microsoft docs
Browser extensions deployed

The Microsoft Compliance Extension for Edge and/or Chrome must be deployed to detect browser-based exfiltration signals.

Required by:Risky browser usage
Microsoft docs

Optional

Physical badging connectorOPTIONAL

The Physical badging connector imports access data from your physical control and access platforms (badge readers, door logs).

Microsoft docs