Share via

IRM policy alerts are not triggering

Nitin Jain 20 Reputation points
2026-05-13T06:12:00.4866667+00:00

I've created an IRM policy with below configuration:

3

4

5

6

7

8

9

11

12

13

We are facing an issue where alerts are not being triggered for priority content.

For example, I downgraded the sensitivity label on a file and then exfiltrated/shared the file externally via Exchange and OneDrive. Based on the configured policy, this activity should have triggered an alert, but no alert was generated.

Could someone please help investigate this issue?

Microsoft Security | Microsoft Purview
0 comments No comments

1 answer

Sort by: Most helpful
  1. SAI JAGADEESH KUDIPUDI 3,205 Reputation points Microsoft External Staff Moderator
    2026-05-14T00:00:11.7866667+00:00

    Hi Nitin Jain,

    Based on the screenshots, the Insider Risk Management policy configuration itself appears correct. Since no alerts were generated even after testing and waiting more than 24 hours, the issue is most likely related to IRM prerequisite configuration rather than the policy conditions.

    In many cases, this happens when the required Insider Risk Management permissions or role assignments are missing, or when the IRM onboarding steps were not fully completed.

    Please verify the following:

    Unified Audit Logging is enabled

    The test user is included within the policy scope

    The required Insider Risk Management roles are assigned

    Licensing requirements are satisfied

    Sufficient time has been allowed for backend policy propagation and telemetry ingestion (sometimes 24–48 hours)

    The required permissions and onboarding steps are documented here:

    Configure Insider Risk Management prerequisites

    After the permissions were configured correctly, this type of issue is typically resolved and alerts begin generating normally.

    Hope this helps. If you have any follow-up questions, please let me know. I would be happy to help.

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.