Insider risk management not working analitics

Danissimode 40 Reputation points
2023-11-03T15:57:24.98+00:00

Hello.

i'm turn on Insider riskanalitics 5 days ago but it still doesn't work. it is CDX tenant Microsoft 365 Enterprise Demo Content with Microsoft Defender for Endpoint Licenses - no pre-hydrated threat content. I did onboarding devices by adding the code DeviceCompliance.onboarding to the intune, I set the reaction time from 1 day, but the analysis did not appear.User's image

User's image

Microsoft 365 and Office | Install, redeem, activate | For business | Windows
Microsoft Security | Microsoft Purview
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 2,090 Reputation points Microsoft Employee
    2024-04-09T18:49:02.7266667+00:00

    In order to troubleshoot your issue, we need to consider a few factors:

    1. Data sources: For Insider Risk Management to work correctly, you need to have the right data sources in place. These include the Microsoft 365 audit log, Microsoft Defender for Endpoint, and HR connector. Make sure these are correctly set up.
    2. Policies: You need to have correctly configured Insider Risk Management policies in place. Make sure you have set up these policies properly and they are active.
    3. Licenses: You need to have the right licenses for the users you are trying to monitor. You mentioned that you have Microsoft Defender for Endpoint Licenses, but you also need Microsoft 365 E5 or Microsoft 365 E5 Compliance for Insider Risk Management.
    4. Processing time: It takes time for the system to process events and generate alerts. While you have set the reaction time to 1 day, it might take more time for the system to start generating alerts, especially if there are lots of events to process.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.