Insider Risk Management Feature

Microsoft Purview Insider Risk Management – Escalating an Alert in Insider Risk Management

In the previous Insider Risk Management (IRM) post, I covered the high-level steps and dashboards for reviewing alerts within IRM. In this post, we’ll take things a bit further by escalating an alert in insider risk management and following the process that allows analysts to gather and save the information necessary to review the larger picture the IRM alert brings to their attention.

As always, please be aware of my blog disclaimer

For more information in this series on Insider Risk Management, please see the other posts I have written on this topic (the links will be active as the pages become active):

Escalating an Alert in Insider Risk Management

Creating a Case

In previous posts, I created a policy within my tenant to capture different triggering events that would trigger alerts when sensitive information was downloaded, exfiltrated, modified, etc. The policy has been triggered, and now we need to review it.  Accessing the alerts in IRM we can see that there are two new items targeted at MacGruber MacGyver.

Reviewing Alerts - Escalating an Alert in Insider Risk Management

The two alerts were triggered on the same day.  Notice one is higher than the other in severity.  This is based purely on the thresholds set when the policy is created (or last modified).  The policy “Test Data Leak” was purposely created with all of the thresholds set very low.  This is raised the different activities much higher in severity, thus the higher score.  The “Contoso Data Leak Policy” created during this blog series has the items set to a more common value, and while the severity is low, it still generated an alert for us to review.

Accessing the alert, it can be seen that there are not a lot of data points.  This is simply because I am using test data for the purpose of this post:

Reviewed Alert - Escalating an Alert in Insider Risk Management

In a typical production environment, the scatter plot graph will have more data points to review:

More Populated Graph - Reviewed Alert - Escalating an Alert in Insider Risk Management

Having determined that we wish to dig into this alert further, the next step is to escalate the alert to a case and assign it to the analyst for review.  To do this:

  1. Open the alert to review.
  2. At the top right-hand side of the dashboard, click on “Confirm all alerts & create case.”

Confirm and Create Case - Escalating an Alert in Insider Risk Management

  1. Provide the case with a meaningful name and click “Create case”

Save Case Details - Escalating an Alert in Insider Risk Management

Note: This doesn’t create a case for just this alert; it will also add all the alerts the user has in place to the same case.

Multiple Alerts Added to Case - Escalating an Alert in Insider Risk Management

Once the case has been created open the case to view the information provided within, there are a few new tabs that didn’t exist in the alert that provide additional details and control of the investigation:

Alerts tab: This tab will display all of the alerts that are included in the case that is tied to the user in question.  As new alerts occur, they will be added automatically to the case.

Case Alert View - Escalating an Alert in Insider Risk Management

Content Explorer Tab: This is very similar to the content explorer view in Purview.  It provides analysts with a list of the data that was involved in the alerts and now the case.  It also allows the analysts to view the data directly if they have the necessary content explorer roles within Purview.

Content Explorer View - Escalating an Alert in Insider Risk Management

Case Notes Tab: The case notes tab allows the analysts and investigators involved in the review of the case to leave notes within the case itself.  The notes allow multiple investigators to collaborate within the case itself or just for an analyst to leave a note for their own investigation.

Case Notes View - Escalating an Alert in Insider Risk Management

Contributor Tab: The contributor tab allows the case owners to add additional analysts and investigators as necessary (assuming they will have the necessary access to IRM.

Contributor View - Escalating an Alert in Insider Risk Management

Creating an eDiscovery Case

The case system is really good for scanning the activities of a possible risky user, but it is limited to the actions that Purview tracks and the IRM policies set up to report on.  The final level of escalation from the initial alert generated by a policy is an advanced eDiscovery case.  By escalating the IRM case to an eDiscovery case, you are now able to review much more content than the IRM case provides and dig deeper into the user’s messages and content (if necessary).  The eDiscovery case also allows analysts and investigators to place content on hold as may be necessary for investigative and possible litigation purposes.

An important note about escalating to eDiscovery: if your IRM environment is configured to anonymize the users in alerts and cases, eDiscovery will remove the obfuscation and inform investigators who the case is reviewing.

To escalate a case to eDiscovery:

  1. Access the case to escalate from within IRM’s case view

Select Case to Escalate

  1. Click on Case actions –> Escalate for investigation

Escalate for investigation

  1. In the blade that slides out, provide a meaningful name and description for the eDiscovery case (both are required fields)

Case Name and Description

  1. Click Save
  2. The blade will update with a link to eDiscovery.  Clicking on the “eDiscovery (Premium)” link will open eDiscovery within the context of IRM.  This is the only way that eDiscovery will open this way.  To access this later will be through the eDiscovery solution in Purview.

Click on eDiscovery Case

  1. Opening eDiscovery, the cases tab will list the active cases the logged-in user has access to including the newly created case.

Review eDiscovery Cases

When the case is created, the system will automatically add the user (who generated the alert) to the eDiscovery case and place their content on hold.

Custodian Added

This concludes the steps for escalating the case.  In future posts I’ll cover the advanced topics of Forensic Evidence and Adaptive Protection.

Thanks for reading!


I’d love to share regularly with you!

Subscribe to get the latest posts sent to your email.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *