What to Create First for Insider Risk Management Project Policy?
You plan to implement inside 365 E5 subscription. You plan to implement insider risk management for users that manage sensitive data associated with a project. You need to create a protection policy for the users. The solution must meet the following requirements: • Minimize the impact on users who are NOT part of the project. • Minimize administrative effort. What should you do first?
Community Votes
63% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether you know priority user groups are the scoping mechanism for project-specific insider risk policies; the trap is jumping straight to policy creation and over-scoping to all users.
In Microsoft Purview Insider Risk Management, a priority user group scopes policies to users handling sensitive project data. This page confirms the first step is to create a priority user group before building the protection policy to minimize impact and administrative effort.
Many candidates choose B (create the insider risk management policy) because it sounds like the direct action, but selecting all users or manually adding users inside the policy increases impact and admin overhead compared with a reusable priority user group.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
C is correct because priority user groups in Microsoft Purview Insider Risk Management are designed to scope policies to a specific set of users who handle sensitive data, such as a confidential project team. Creating the priority user group first lets you later select it in the insider risk management policy wizard, so only project members are monitored. This directly satisfies the requirement to minimize impact on users outside the project. It also minimizes administrative effort because the group can be reused across multiple insider risk policies instead of manually maintaining user lists in each policy. EM1234 cited Microsoft Learn guidance about creating a "Confidential Project Users priority user group". The question asks what to do first, and the priority user group is the prerequisite scoping object.Why the Other Options Are Wrong
A is wrong because a Microsoft Entra security group is not the native scoping mechanism for Insider Risk Management and would add unnecessary administrative steps. B is wrong as a first step because creating the policy before defining the priority user group can lead to broader targeting or extra manual user selection, which conflicts with minimizing impact and effort. D is wrong because a risky users policy in Entra is unrelated to insider risk management protection policies. Some commenters, such as TomBoy25 and riccardo, argued for A or B, but their reasoning overlooks the dedicated priority user group feature.Community Comment Notes
The majority vote and several comments align with C. BewiseExams noted "There's a whole menu hidden behind the gear icon in IRM menu". EM1234 quoted Microsoft Learn about creating a "Confidential Project Users priority user group" for a highly confidential project. Dools and Amin4799 preferred B after lab testing, but their observation that you can select users or groups during policy creation actually supports the need to prepare the priority group first for minimal impact. TomBoy25 preferred A to reduce administrative effort, yet a priority user group remains the more targeted IRM-native solution.Official Reference
Exam Strategy
When an SC-400 question asks for the first step to minimize impact and administrative effort, look for the native scoping object rather than the policy itself. Priority user groups are created under Insider Risk Management settings before you configure a policy. Read the requirement words 'first' and 'not part of project' as clues to prepare the target group.
Frequently Asked Questions
Why is a priority user group preferred over a security group for insider risk management?
Priority user groups are native to Insider Risk Management and can be selected directly in policy scoping, whereas Entra security groups would add administrative steps and may not support the same risk indicators.
Can I select users directly in the insider risk management policy instead of creating a priority user group first?
Yes, but selecting users manually in each policy increases admin effort and risk of over-scoping. A priority user group centralizes the project team for reuse and minimizes impact.