First Step for Insider Risk Management Policy in Microsoft Purview
You have a Microsoft 365 E5 subscription. You plan to use Microsoft Purview insider risk management. You need to create an insider risk management policy that will detect data theft from Microsoft SharePoint Online by users that submitted their resignation or are near their employment termination date. What should you do first?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Insider risk policies rely on HR data connectors to identify high-risk user states like resignation or termination before analyzing content activities.
To detect data theft from SharePoint Online by users near termination, you must first configure an HR data connector to import resignation and termination events into Microsoft Purview.
Candidates often select configuring Office indicators or onboarding devices first, failing to realize that without HR data, the system cannot filter policies by employment status.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct first step is to configure an HR data connector. According to Microsoft documentation, "You can set up a data connector to import human resources (HR) data related to events such as a user's resignation." This data is essential because the insider risk management policy needs to know which users are at high risk (e.g., resigned or terminated) to apply specific detection rules against their activities.Why the Other Options Are Wrong
Configuring Office indicators (A) defines what sensitive information to look for but does not identify who is at risk based on employment status. Onboarding devices (D) is part of endpoint monitoring, which is separate from SharePoint content analysis. Physical badging (C) tracks physical access, not digital data exfiltration from cloud services.Community Comment Notes
Community consensus strongly supports option B, with users noting that importing HR data is the prerequisite for identifying "resignation" or "termination" statuses. As one commenter noted, the HR connector imports data related to events such as "a user's resignation," enabling the policy to target these specific groups.Official Reference
Exam Strategy
Always identify the prerequisite data source before selecting configuration options. For Insider Risk Management, HR data is the foundation for targeting high-risk employees; without it, you cannot filter by employment status.
Frequently Asked Questions
Why can't I just use Office indicators first?
Office indicators define what sensitive data to look for, but they do not identify which users are at risk. You need HR data to filter policies by employment status.
Does HR connector work for all M365 services?
Yes, the HR data connector provides a unified view of employee status across Microsoft 365 workloads, allowing insider risk policies to apply to SharePoint, Exchange, and Teams.