In the previous Insider Risk Management (IRM) post, I covered the high-level steps and dashboards for reviewing alerts within IRM. In this post, we’ll take things a bit further by escalating an alert in insider risk management and following the process that allows analysts to gather and save the information necessary to review the larger picture the IRM alert brings to their attention.
As always, please be aware of my blog disclaimer
For more information in this series on Insider Risk Management, please see the other posts I have written on this topic (the links will be active as the pages become active):
- An Overview of Insider Risk Management
- Configuring Your Tenant for Insider Risk Management
- Creating a Data Leak Policy
- Reviewing Alerts In Insider Risk Management
- Escalating an Alert in Insider Risk Management (this post)
Escalating an Alert in Insider Risk Management
Creating a Case
In previous posts, I created a policy within my tenant to capture different triggering events that would trigger alerts when sensitive information was downloaded, exfiltrated, modified, etc. The policy has been triggered, and now we need to review it. Accessing the alerts in IRM we can see that there are two new items targeted at MacGruber MacGyver.
The two alerts were triggered on the same day. Notice one is higher than the other in severity. This is based purely on the thresholds set when the policy is created (or last modified). The policy “Test Data Leak” was purposely created with all of the thresholds set very low. This is raised the different activities much higher in severity, thus the higher score. The “Contoso Data Leak Policy” created during this blog series has the items set to a more common value, and while the severity is low, it still generated an alert for us to review.
Accessing the alert, it can be seen that there are not a lot of data points. This is simply because I am using test data for the purpose of this post:
In a typical production environment, the scatter plot graph will have more data points to review:
Having determined that we wish to dig into this alert further, the next step is to escalate the alert to a case and assign it to the analyst for review. To do this:
- Open the alert to review.
- At the top right-hand side of the dashboard, click on “Confirm all alerts & create case.”
- Provide the case with a meaningful name and click “Create case”
Note: This doesn’t create a case for just this alert; it will also add all the alerts the user has in place to the same case.
Once the case has been created open the case to view the information provided within, there are a few new tabs that didn’t exist in the alert that provide additional details and control of the investigation:
Alerts tab: This tab will display all of the alerts that are included in the case that is tied to the user in question. As new alerts occur, they will be added automatically to the case.
Content Explorer Tab: This is very similar to the content explorer view in Purview. It provides analysts with a list of the data that was involved in the alerts and now the case. It also allows the analysts to view the data directly if they have the necessary content explorer roles within Purview.
Case Notes Tab: The case notes tab allows the analysts and investigators involved in the review of the case to leave notes within the case itself. The notes allow multiple investigators to collaborate within the case itself or just for an analyst to leave a note for their own investigation.
Contributor Tab: The contributor tab allows the case owners to add additional analysts and investigators as necessary (assuming they will have the necessary access to IRM.
Creating an eDiscovery Case
The case system is really good for scanning the activities of a possible risky user, but it is limited to the actions that Purview tracks and the IRM policies set up to report on. The final level of escalation from the initial alert generated by a policy is an advanced eDiscovery case. By escalating the IRM case to an eDiscovery case, you are now able to review much more content than the IRM case provides and dig deeper into the user’s messages and content (if necessary). The eDiscovery case also allows analysts and investigators to place content on hold as may be necessary for investigative and possible litigation purposes.
An important note about escalating to eDiscovery: if your IRM environment is configured to anonymize the users in alerts and cases, eDiscovery will remove the obfuscation and inform investigators who the case is reviewing.
To escalate a case to eDiscovery:
- Access the case to escalate from within IRM’s case view
- Click on Case actions –> Escalate for investigation
- In the blade that slides out, provide a meaningful name and description for the eDiscovery case (both are required fields)
- Click Save
- The blade will update with a link to eDiscovery. Clicking on the “eDiscovery (Premium)” link will open eDiscovery within the context of IRM. This is the only way that eDiscovery will open this way. To access this later will be through the eDiscovery solution in Purview.
- Opening eDiscovery, the cases tab will list the active cases the logged-in user has access to including the newly created case.
When the case is created, the system will automatically add the user (who generated the alert) to the eDiscovery case and place their content on hold.
This concludes the steps for escalating the case. In future posts I’ll cover the advanced topics of Forensic Evidence and Adaptive Protection.
Thanks for reading!

















Leave a Reply