Microsoft Ignite 2019: Insider Risk Management and the Microsoft Defender Rebrand
Retrospective: this article looks back at events from November 2019, written in 2026 with the benefit of hindsight.
At Microsoft Ignite in November 2019, Microsoft announced Insider Risk Management in preview as part of Microsoft 365 compliance, alongside updates across its security portfolio as it continued moving its products from "Windows Defender" branding to "Microsoft Defender."
What Insider Risk Management did
Insider Risk Management used signals from Microsoft 365 and HR systems to identify potentially risky user activity, such as:
- Data theft by departing employees (for example, mass downloads or copying files to USB after a resignation date is recorded).
- Data leaks of sensitive or confidential information.
- Policy violations, later expanding to security policy violations and risky browsing.
Policies combined indicators into risk scores, with alerts triaged by investigators. Crucially, it was built with privacy controls: user names could be pseudonymized by default, and role-based access limited who could see what.
Why it mattered
Insider threats — malicious or accidental — were hard to address with traditional security tools focused on external attackers. Bringing insider risk detection into the Microsoft 365 compliance suite made it accessible to organizations that already licensed E5.
The sensitivity
Insider risk programs raise legal, privacy and cultural questions. Monitoring employees requires HR, legal and works council involvement in many jurisdictions. Microsoft's design acknowledged that, but customers still had to do the governance work.
In hindsight
Insider Risk Management became part of Microsoft Purview and later integrated Adaptive Protection, automatically applying stricter data loss prevention to higher-risk users. It also became relevant to AI: Purview now uses insider risk signals to detect risky use of Copilot and other AI tools.
- How to Pilot Microsoft Purview Insider Risk Management How-To & Hardening
- Insider Risk Policy Checklist: Privacy, HR and Legal Sign-Off How-To & Hardening
- CIO Brief: Insider Risk Without Spying on Employees CIO Briefings