Microsoft Purview Insider Risk Management Device Onboarding
You have a Microsoft 365 subscription. Users have devices that run Windows 11. You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the following actions: • Deletes files that contain a sensitive information type (SIT) from their device • Copies files that contain a SIT to a USB drive • Prints files that contain a SIT You need to prepare the environment to support the policy. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Insider risk management relies on endpoint telemetry; without onboarding devices to the compliance service, no file-level activity can be monitored.
To detect sensitive information type (SIT) activities like deletion, USB copying, and printing, you must onboard Windows devices to Microsoft Purview. This establishes the necessary telemetry for insider risk policies.
Candidates often select communication compliance (D), which monitors messages rather than local device file actions, or connectors that are not prerequisites for basic detection.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is B — Onboard the devices to Microsoft Purview. To implement an Insider Risk Management policy that detects specific file-based actions (deleting, copying to USB, printing), the solution requires data from the user's endpoint. Microsoft Purview Insider Risk Management uses the Unified Audit Log, but for file activities on the device, it specifically relies on the Microsoft Defender for Endpoint agent or the built-in telemetry collected when a device is onboarded to Microsoft Purview Compliance. Without this connection, the system cannot see what happens to files on the local machine.
Why the Other Options Are Wrong
Option A (Physical badging connector) is used to correlate physical location with digital activity, which is optional and not required for basic file detection. Option C (HR data connector) provides employee status data to help evaluate risk levels but does not provide the actual telemetry of file actions. Option D (Communication compliance) is designed for monitoring communications like emails and chats, not for detecting local file manipulation or peripheral usage like USB drives.
Community Comment Notes
Community consensus strongly supports option B. Users such as TC1Labs confirm that "Onboard the devices to Microsoft Purview" is the critical first step to enable the detection capabilities described in the scenario. The votes indicate 100% agreement among learners that this is the prerequisite action.
Exam Strategy
Always identify the data source first. If the policy involves 'file actions' on 'devices', think about endpoint onboarding or Defender integration. Communication compliance is for text/voice, not file operations.
Frequently Asked Questions
Why is HR data connector not the answer?
The HR connector provides employee context (like termination date) but does not provide the technical telemetry of file actions needed to detect the suspicious behavior.
Can I use Communication Compliance for file copies?
No, Communication Compliance monitors messages (email, chat). It cannot detect local file operations like copying to a USB drive or printing from a workstation.