Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1246005

Microsoft Purview | Insider Risk Management – Enhancements to the Data Security Triage Agent

Informational

Message ID

MC1246005
View in Admin Center

Roadmap ID

557683
View in Roadmap

Services

Microsoft Purview

Affected Platforms

Web

Summary

Microsoft Purview Insider Risk Management is enhancing the Data Security Triage Agent to prioritize alerts, summarize behavioral risks, and expand user context for more efficient investigations. The update rolls out from March to July 2026, requires admin activation, and includes Security Copilot for Microsoft 365 E5 users.

Details

Introduction

We’re enhancing the Data Security Triage Agent in Microsoft Purview Insider Risk Management to help analysts triage alerts more efficiently and focus investigations on the activities and users that matter most. These updates respond to customer feedback for clearer risk context, streamlined alert review, and improved investigation accuracy.

This message is associated with Microsoft 365 Roadmap ID 557683.

When this will happen

  • Public Preview: We will begin rolling out in early March 2026 and expect to complete by early April 2026.
  • General Availability (Worldwide): We will begin rolling out in late June 2026 and expect to complete by late July 2026.

How this affects your organization

Who is affected

  • Admins and security analysts who use Microsoft Purview Insider Risk Management.
  • Organizations with Insider Risk Management enabled and analysts using alert triage workflows.

What will happen

The newly enhanced Data Security Triage Agent acts as the front door to investigations, helping teams immediately understand who and what matters most. Instead of manually reviewing raw alerts, the Data Security Triage Agent provides:

  • Prioritized alerts based on user risk and activity patterns.
  • Behavioral risk patterns summarized into investigative themes, helping analysts move more quickly from alert to insight.
  • Expanded user context, including role, employment status (such as last working date), and prior alert history.
  • Access to the enhanced experience in:
    • Purview portal → Insider Risk Management → Agent tab
    • Alerts tab → Triage Agent toggle
  • The enhancement is not enabled by default; admins must turn on the Data Security Triage Agent.
  • Organizations using Microsoft 365 E5 will also receive Security Copilot to support investigations; rollout is ongoing and customers will receive advance notice.

Screenshot 1 - View of alerts

 user settings

Screenshot 2 - How to access the enhanced Triage Agent in Microsoft Purview Insider Risk Management (IRM):

 user settings

What you can do to prepare

No immediate action is required. However, to make use of the new capabilities, consider the following steps:

  • Enable the Data Security Triage Agent in the Purview portal (Agent tab).
  • Train analysts to access the enhanced view using the Triage Agent toggle in the Alerts tab.
  • Review your internal documentation for Insider Risk investigation processes and update it as needed.

Learn more: Agents built into your workflow: Get Security Copilot with Microsoft 365 E5

Compliance considerations

No compliance considerations identified. Review as appropriate for your organization.

Timeline

Published
Mar 6, 2026
Message published to Message Center
Updated
Mar 6, 2026
Message content updated
End Date
Aug 31, 2026
Message timeline ends

Tags

#New feature#User impact#Admin impact

Category

Stay Informed

Related Messages

Similar updates

MC1249429

Microsoft Purview compliance portal: Data Security Investigations introduces new soft purge mitigation action

Mar 12, 2026
MC1247881

Microsoft Purview DLP: New policy configuration options available for inline network and Edge for Business

Mar 9, 2026
MC1246003

Endpoint Data Loss Prevention: Always-on diagnostics for Windows endpoints (Phase 2)

Mar 6, 2026
MC1244281

Microsoft Purview | Insider Risk Management - Ability to preview content in Insider Risk Management Alerts

Mar 4, 2026
MC1238434

Microsoft Purview | Data Lifecycle Management - Separate Retention policies for Copilots and AI Apps

Feb 25, 2026