Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC937158

Microsoft Purview | Insider Risk Management: New scenario-based policy templates

Plan for Change

Message ID

MC937158
View in Admin Center

Roadmap ID

409966
View in Roadmap

Services

Microsoft Purview

Affected Platforms

Web

Summary

Microsoft Purview Insider Risk Management is introducing two new quick policy templates for Crown jewel protection and Email exfiltration, available from late November 2024 (Public Preview) and late February 2025 (General Availability). Existing quick policies for Data leak and Data theft will remain. No admin action is required before the rollout.

Details

Updated April 3, 2025: We have updated the rollout timeline below. Thank you for your patience.

Coming soon to Microsoft Purview | Insider Risk Management: Two new preconfigured quick policy templates for Crown jewel protection and Email exfiltration. These templates are for admins who want to deploy scenario-specific policy templates with less configuration, to get started faster. The existing quick policies for Data leak and Data theft will continue to be available. You can find all four scenario-based quick policies in Insider Risk Management at Policies > Create Policies. Admins can expect additional turning after deploying these policies to meet individual alert volume needs.

This message is associated with Microsoft 365 Roadmap ID 409966.

When this will happen:

Public Preview: We will begin rolling out late November 2024 and expect to complete by mid-December 2024.

General Availability (Worldwide, GCC, GCC High, DoD): We will begin rolling out late February 2025 (previously early February) and expect to complete by early April 2025 (previously late March).

How this will affect your organization:

  1. Sign in to Insider Risk Management with the admin role permissions
  2. Go to the Policies page at https://purview.microsoft.com/insiderriskmgmt/policiespage
  3. Select Create policy
  4. Select Quick policies
  5. Select either the Crown jewel protection policy or the Email exfiltration policy
  6. Configure policy as applicable (add users to scope, optional priority content, and so on)

admin controls

admin controls

The new policies will be on by default.

What you need to do to prepare:

This rollout will happen automatically by the specified date with no admin action required before the rollout. Review your current configuration to determine the impact for your organization. You may want to notify your users about this change and update any relevant documentation.

Learn more: The Quick Policies section in Create and manage insider risk management policies | Microsoft Learn

Timeline

📅
Published
Nov 19, 2024
Message published to Message Center
✏️
Updated
Apr 3, 2025
Message content updated
🏁
End Date
Jun 30, 2025
Message timeline ends

Tags

#Updated message#New feature#User impact#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC947048

Microsoft Purview | Insider Risk Management- Risky AI usage

Dec 2, 2024
MC937935

Microsoft Purview | Information Protection: SharePoint Online library permissions extend to downloaded files

Nov 19, 2024
MC921117

Microsoft Purview |Communication Compliance: Customize policies with language-specific trainable classifier conditions

Oct 29, 2024
MC920308

Microsoft Purview | Information Protection: Auto-labeling policies will support "Fingerprint based SIT"

Oct 28, 2024
MC911624

Microsoft Purview | Data Loss Prevention: ​Network share coverage and exclusion support on Mac endpoints​

Oct 15, 2024