Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1051101

Microsoft Purview compliance portal: New email indicators to Insider Risk Management

Informational

Message ID

MC1051101
View in Admin Center

Roadmap ID

483520
View in Roadmap

Services

Microsoft Purview

Affected Platforms

Web

Details

We are adding two new email indicators to Microsoft Purview Insider Risk Management:

  1. Sending email with attachments to free public domains: This alerts when business-sensitive data is potentially leaked from a work email account to a free public domain email, potentially leading to a data security incident.
  2. Sending email with attachments to self: This alerts when business-sensitive data is potentially leaked from a work email account to a user's personal email account or emailing self, potentially leading to a data security incident.

Admins with Insider Risk Management permissions can enable these indicators from the Settings page and use these new indicators in the Data Leaks or Data Theft policy template. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.

This message is associated with Microsoft 365 Roadmap ID 483520.

When this will happen:

Public Preview (Worldwide): We began rolling out in late March 2025 and expect to complete by mid-April 2025.

General Availability (Worldwide): We will begin rolling out in mid-June 2025 and expect to complete by late June 2025.

How this will affect your organization:

This feature helps customers to detect sensitive content being exfiltrated via emails to self or free public domains.

What you need to do to prepare:

Admins need to enable the indicators from policy indicators in Insider Risk Management (IRM) settings. These indicators can be added to any existing policy or admins can create a new policy with these indicators. 

For more information, see Configure policy indicators in insider risk management.

Timeline

📅
Published
Apr 8, 2025
Message published to Message Center
✏️
Updated
Apr 8, 2025
Message content updated
🏁
End Date
Aug 4, 2025
Message timeline ends

Tags

#New feature#Admin impact

Category

📖Stay Informed

Related Messages

Similar updates

MC1061103

Microsoft Purview | Data Loss Prevention: Ability to rename policy and rules

Apr 24, 2025
MC1059679

Microsoft Purview | Insider Risk Management: Policy tuning analysis for priority content only policies

Apr 21, 2025
MC1058262

Microsoft Purview | Insider Risk Management: Enhancements to global exclusions in IRM settings

Apr 18, 2025
MC1056265

Microsoft Purview: New data security controls for detecting sensitive data shared over the network

Apr 15, 2025
MC1052914

Microsoft Purview | Endpoint Data Loss Prevention: App or app group restriction support for Microsoft Edge browser

Apr 10, 2025