What's changed: Deepened SC-900 Chapter 4 to the AZ-900 baseline (Service Trust Portal vs Purview/Compliance Manager with shared-responsibility mapping & table; sensitivity labels/DLP/retention classify→protect→lifecycle flow & table; insider risk/eDiscovery/audit table & scenario; FAQ, traps). Localized 3 figures
4.3Insider Risk, eDiscovery, and Audit
Understand insider risk management for internal risks, eDiscovery for legal investigations, and audit for recording activity.
Compliance includes not only external threats but also internal risk management and legal/audit needs. Microsoft Purview provides these as well.
4.3.1Key capabilities
- Insider risk management: detect and manage risks of data leaks or malicious activity by insiders (employees, contractors) from behavioral signals, with privacy-conscious design.
- eDiscovery: search, preserve (hold), collect, and export relevant content for litigation or investigations.
- Audit: log who did what and when; offered as standard audit and advanced audit with longer retention.
All three are compliance capabilities to "stay accountable and traceable after the fact," but with different aims: insider risk management proactively detects internal threats; eDiscovery reliably preserves and collects evidence for legal proceedings; audit records activity for later tracing. For example, on suspicion of wrongdoing, you trace facts via audit logs, preserve evidence via eDiscovery, and keep monitoring similar signs via insider risk management—working together.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

