Microsoft Purview Insider Risk Management Device Onboarding

Implement and manage Microsoft Purview Insider Risk Management
Answer Correct answer: B — Onboard the devices to Microsoft Purview to enable the collection of file activity telemetry required for the insider risk management policy.

You have a Microsoft 365 subscription. Users have devices that run Windows 11. You plan to create a Microsoft Purview insider risk management policy that will detect when a user performs the following actions: • Deletes files that contain a sensitive information type (SIT) from their device • Copies files that contain a SIT to a USB drive • Prints files that contain a SIT You need to prepare the environment to support the policy. What should you do?

  1. Configure the physical badging connector.
  2. Onboard the devices to Microsoft Purview. Correct Answer
  3. Configure the HR data connector.
  4. Create a Microsoft Purview communication compliance policy.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Insider risk management relies on endpoint telemetry; without onboarding devices to the compliance service, no file-level activity can be monitored.

To detect sensitive information type (SIT) activities like deletion, USB copying, and printing, you must onboard Windows devices to Microsoft Purview. This establishes the necessary telemetry for insider risk policies.

Candidates often select communication compliance (D), which monitors messages rather than local device file actions, or connectors that are not prerequisites for basic detection.

Community Discussion (4 comments)

belyo 👍 1 Selected: B
Onboard the devices to Microsoft Purview
TC1Labs 👍 2 Selected: B
Onboard the devices to Microsoft Purview
TC1Labs 👍 2 Selected: B
So, the correct answer is B. Onboard the devices to Microsoft Purview.
TC1Labs 👍 2
The correct answer is B. Onboard the devices to Microsoft Purview.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is B — Onboard the devices to Microsoft Purview. To implement an Insider Risk Management policy that detects specific file-based actions (deleting, copying to USB, printing), the solution requires data from the user's endpoint. Microsoft Purview Insider Risk Management uses the Unified Audit Log, but for file activities on the device, it specifically relies on the Microsoft Defender for Endpoint agent or the built-in telemetry collected when a device is onboarded to Microsoft Purview Compliance. Without this connection, the system cannot see what happens to files on the local machine.

Why the Other Options Are Wrong

Option A (Physical badging connector) is used to correlate physical location with digital activity, which is optional and not required for basic file detection. Option C (HR data connector) provides employee status data to help evaluate risk levels but does not provide the actual telemetry of file actions. Option D (Communication compliance) is designed for monitoring communications like emails and chats, not for detecting local file manipulation or peripheral usage like USB drives.

Community Comment Notes

Community consensus strongly supports option B. Users such as TC1Labs confirm that "Onboard the devices to Microsoft Purview" is the critical first step to enable the detection capabilities described in the scenario. The votes indicate 100% agreement among learners that this is the prerequisite action.

Exam Strategy

Always identify the data source first. If the policy involves 'file actions' on 'devices', think about endpoint onboarding or Defender integration. Communication compliance is for text/voice, not file operations.

Frequently Asked Questions

Why is HR data connector not the answer?

The HR connector provides employee context (like termination date) but does not provide the technical telemetry of file actions needed to detect the suspicious behavior.

Can I use Communication Compliance for file copies?

No, Communication Compliance monitors messages (email, chat). It cannot detect local file operations like copying to a USB drive or printing from a workstation.

Related Analysis

← Back to SC-400 Study Guide