What's changed: Deepened SC-900 Chapter 4 to the AZ-900 baseline (Service Trust Portal vs Purview/Compliance Manager with shared-responsibility mapping & table; sensitivity labels/DLP/retention classify→protect→lifecycle flow & table; insider risk/eDiscovery/audit table & scenario; FAQ, traps). Localized 3 figures
4.3Insider Risk, eDiscovery, and Audit
Understand insider risk management for internal risks, eDiscovery for legal investigations, and audit for recording activity.
Compliance includes not only external threats but also internal risk management and legal/audit needs. Microsoft Purview provides these as well.
4.3.1Key capabilities
- Insider risk management: detect and manage risks of data leaks or malicious activity by insiders (employees, contractors) from behavioral signals, with privacy-conscious design.
- eDiscovery: search, preserve (hold), collect, and export relevant content for litigation or investigations.
- Audit: log who did what and when; offered as standard audit and advanced audit with longer retention.
All three are compliance capabilities to "stay accountable and traceable after the fact," but with different aims: insider risk management proactively detects internal threats; eDiscovery reliably preserves and collects evidence for legal proceedings; audit records activity for later tracing. For example, on suspicion of wrongdoing, you trace facts via audit logs, preserve evidence via eDiscovery, and keep monitoring similar signs via insider risk management—working together.
| Capability | Purpose | Keyword |
|---|---|---|
| Insider risk management | Detect internal threats | Internal, proactive |
| eDiscovery | Search/preserve/collect evidence | Legal, litigation |
| Audit | Record activity logs | Who/when/what |
Scenario: suspected data exfiltration by a departing employee. Insider risk management detects risky behavior (e.g., bulk downloads by someone about to leave) and alerts. The investigation traces "when, which files, what actions" via audit logs. In preparation for legal action, related emails/documents are preserved (held), collected, and exported via eDiscovery. The three capabilities divide the work to handle internal risk.
Watch the mix-ups: (1) Insider risk management (proactively detect internal threats) vs the previous chapter’s Defender (external threat detection/response)—internal vs external. (2) eDiscovery (preserve/collect legal evidence) vs audit (record activity logs)—eDiscovery "collects," audit "records." (3) These are Microsoft Purview compliance features.
Q. eDiscovery vs audit? Audit continuously records day-to-day activity; eDiscovery searches, preserves, and collects specific content (including audit data) for legal proceedings. Q. Is insider risk management employee surveillance? It detects risky "behavior patterns" with privacy-conscious design such as anonymization. Q. How do these differ from security (previous chapter)? The previous chapter mainly detects/defends external threats; this chapter is the compliance view—internal, legal, and evidentiary.
Common mappings: insider risks = insider risk management, content search/preservation/collection for legal cases = eDiscovery, activity logging = audit. Tell them apart by internal (insider), legal (eDiscovery), or recording (audit).
4.3.2Section summary
- Insider risk management (internal) / eDiscovery (legal) / audit (activity logs)
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. Which Microsoft Purview capability detects and manages risks of data leaks or malicious activity by insiders?
Q2. Which finds, preserves, and collects relevant content for litigation or investigations?
Q3. Which logs "who did what and when" so it can be investigated later?
Keep track of your progress
The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.

