Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderM365 ReportPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderM365 ReportPortfolio

Connect

© 2026 M365 Message Center. Created with ❤ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC781588

Purview | Insider Risk Management: Exfiltration of business sensitive data to free public domain emails

Informational

Message ID

MC781588
View in Admin Center

Roadmap ID

393334
View in Roadmap

Services

Microsoft 365 suite

Affected Platforms

Web

Summary

Microsoft Purview Insider Risk Management is introducing a feature to detect exfiltration of sensitive data to free public domain emails, with a public preview in mid-May 2024 and general availability in late June 2024. The update enhances email insight alerts and adds new domain detection for better security incident prevention.

Details

Updated August 9, 2024: We have updated the content below with additional information. Thank you for your patience.

Coming soon, Microsoft Purview Insider Risk Management will roll out exfiltration of business sensitive data to free public domain emails.

This message is associated with Microsoft 365 Roadmap ID 393334.

When this will happen:

Public Preview: We will begin rolling out mid-May 2024 and expect to complete by late May 2024.

General Availability: We will begin rolling out late June 2024 and expect to complete by early July 2024.

How this will affect your organization:

We are enhancing the existing email insight alerts to provide additional information when business sensitive data is potentially leaked from a work email account to a free public domain email, potentially leading to a data security incident. The new domain detection group "Free public domains" will list the common domains used for personal email accounts. Admins with appropriate permissions can choose to select these domains in their indicator variants.

You can also modify the "Free public domains" detection group. Administrators with the necessary permissions now have the flexibility to tailor the default domain list in the "Free public domains" by adding new domains or removing existing ones. Should there be a need to revert to the original domain list provided by Microsoft, the "Reset" function can be utilized. The maximum number of domains allowed per detection group remains capped at 200, and this includes the "Free public domains" group. Any changes made to this group will be taken into account when analyzing potential data exfiltration to personal email accounts.

Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy. 

Any email going to free public domains (including email sent to self) will be automatically highlighted in email insights.

Updated email insight:

admin settings

Free public domains:

admin settings

New column and filters for email activities:

admin settings

What you need to do to prepare:

This rollout will happen automatically by the specified date with no admin action required before the rollout.

You may want to update any relevant documentation as appropriate. We will update this comm before rollout with revised documentation.

Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies based on their own internal policies, governance, and organizational requirements. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy. 

You can access the Insider Risk Management solution in the Microsoft Purview compliance portal.

Timeline

Published
Apr 19, 2024
Message published to Message Center
Updated
Aug 9, 2024
Message content updated
End Date
Sep 30, 2024
Message timeline ends

Tags

#Updated message#New feature#Admin impact

Category

Stay Informed

Related Messages

Similar updates

MC790716

Microsoft Purview | Information Protection - Sensitivity label protection policy for Azure SQL, Storage, and Amazon S3

May 6, 2024
MC789312

Microsoft Purview | Audit search: New filters will be available

Apr 30, 2024
MC788980

Microsoft Purview | Insider Risk Management: Granular trigger throttling

Apr 29, 2024
MC786326

Microsoft Purview | Insider Risk Management: Policy tuning analysis for priority content only policies

Apr 26, 2024
MC779849

Microsoft Purview | Data Loss Prevention: Oversharing popups enhancements on Microsoft Outlook Win32

Apr 18, 2024