
In order to troubleshoot your issue, we need to consider a few factors:
- Data sources: For Insider Risk Management to work correctly, you need to have the right data sources in place. These include the Microsoft 365 audit log, Microsoft Defender for Endpoint, and HR connector. Make sure these are correctly set up.
- Policies: You need to have correctly configured Insider Risk Management policies in place. Make sure you have set up these policies properly and they are active.
- Licenses: You need to have the right licenses for the users you are trying to monitor. You mentioned that you have Microsoft Defender for Endpoint Licenses, but you also need Microsoft 365 E5 or Microsoft 365 E5 Compliance for Insider Risk Management.
- Processing time: It takes time for the system to process events and generate alerts. While you have set the reaction time to 1 day, it might take more time for the system to start generating alerts, especially if there are lots of events to process.