First Step for Insider Risk Management Policy in Microsoft Purview

Implement and manage Microsoft Purview Insider Risk Management
Answer Correct answer: B — Configure an HR data connector to import resignation and termination events, enabling the policy to identify high-risk users.

You have a Microsoft 365 E5 subscription. You plan to use Microsoft Purview insider risk management. You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date. What should you do first?

  1. Configure Office indicators.
  2. Configure an HR data connector. Correct Answer
  3. Configure a Physical badging connector.
  4. Onboard devices to Microsoft Defender for Endpoint.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Insider risk policies rely on HR data connectors to identify high-risk user states like resignation or termination before analyzing content activities.

To detect data theft from SharePoint Online by users near termination, you must first configure an HR data connector to import resignation and termination events into Microsoft Purview.

Candidates often select configuring Office indicators or onboarding devices first, failing to realize that without HR data, the system cannot filter policies by employment status.

Community Discussion (3 comments)

Kuteron 👍 1
https://learn.microsoft.com/en-us/purview/import-hr-data?tabs=microsoft-purview-portal
Kuteron 👍 1
Learn Microsoft Purview Set up a connector to import HR data Article 06/17/2024 In this article Before you begin Step 1: Prepare a CSV file with your HR data Step 2: Create an app in Microsoft Entra ID Step 3: Create the HR connector You can set up a data connector to import human resources (HR) data related to events such as a user's resignation or a change in a user's job level. The HR data is used by the insider risk management solution to generate risk indicators that can help you identity possible malicious activity or data theft by users inside your organization.
Dools 👍 1 Selected: B
Looks correct https://learn.microsoft.com/en-us/purview/import-hr-data?tabs=microsoft-purview-portal

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct first step is to configure an HR data connector. According to Microsoft documentation, "You can set up a data connector to import human resources (HR) data related to events such as a user's resignation." This data is essential because the insider risk management policy needs to know which users are at high risk (e.g., resigned or terminated) to apply specific detection rules against their activities.

Why the Other Options Are Wrong

Configuring Office indicators (A) defines what sensitive information to look for but does not identify who is at risk based on employment status. Onboarding devices (D) is part of endpoint monitoring, which is separate from SharePoint content analysis. Physical badging (C) tracks physical access, not digital data exfiltration from cloud services.

Community Comment Notes

Community consensus strongly supports option B, with users noting that importing HR data is the prerequisite for identifying "resignation" or "termination" statuses. As one commenter noted, the HR connector imports data related to events such as "a user's resignation," enabling the policy to target these specific groups.

Official Reference

Exam Strategy

Always identify the prerequisite data source before selecting configuration options. For Insider Risk Management, HR data is the foundation for targeting high-risk employees; without it, you cannot filter by employment status.

Frequently Asked Questions

Why can't I just use Office indicators first?

Office indicators define what sensitive data to look for, but they do not identify which users are at risk. You need HR data to filter policies by employment status.

Does HR connector work for all M365 services?

Yes, the HR data connector provides a unified view of employee status across Microsoft 365 workloads, allowing insider risk policies to apply to SharePoint, Exchange, and Teams.

Related Analysis

← Back to SC-400 Study Guide