Microsoft 365Platform ChangesRetrospectives

Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.

At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across its security portfolio as it continued moving its products from "Windows Defender" branding to "Microsoft Defender."

What Insider Risk Management did

Insider Risk Management used signals from Microsoft 365 and HR systems to identify potentially risky user activity, such as:

  • Data theft by departing employees (for example, mass downloads or copying files to USB after a resignation date is recorded).
  • Data leaks of sensitive or confidential information.
  • Policy violations, later expanding to security policy violations and risky browsing.

Policies combined indicators into risk scores, with alerts triaged by investigators. Crucially, it was built with privacy controls: user names could be pseudonymized by default, and role-based access limited who could see what.

Why it mattered

Insider threats — malicious or accidental — were hard to address with traditional security tools focused on external attackers. Bringing insider risk detection into the Microsoft 365 compliance suite made it accessible to organizations that already licensed E5.

The sensitivity

Insider risk programs raise legal, privacy and cultural questions. Monitoring employees requires HR, legal and works council involvement in many jurisdictions. Microsoft's design acknowledged that, but customers still had to do the governance work.

In hindsight

Insider Risk Management became part of Microsoft Purview and later integrated Adaptive Protection, automatically applying stricter data loss prevention to higher-risk users. It also became relevant to AI: Purview now uses insider risk signals to detect risky use of Copilot and other AI tools.

microsoft insider risk managementIgnite 20192019

More on this story