Insider Risk Signals for AI Activity
Uses Microsoft Purview Insider Risk Management to identify users with potentially risky AI-related behavior, such as sharing sensitive content with AI apps or interacting with unsanctioned AI services, by correlating configured activity signals from Microsoft Purview, Microsoft 365, browser, endpoint, and network controls. These insights are integrated into Microsoft Defender XDR, where IRM alerts correlate per user into a single incident for unified investigation.