Illustration of secure cloud data transfer from laptops through layered firewalls to a monitoring dashboard.
Microsoft Purview collection policies can now suppress data that Insider Risk Management would otherwise use to evaluate endpoint activity, creating a configuration dependency that Purview administrators need to audit before treating an Insider Risk policy as comprehensive. Microsoft’s Microsoft 365 Roadmap entry 501582 is marked Launched and says collection policies can scope sensitive-information-type classification and activities for selected users; Microsoft Learn’s accompanying product documentation establishes the operational consequence more precisely: a deployed device collection policy takes precedence over conflicting Insider Risk Management monitoring settings.

The result is not a new Insider Risk alert type or a broader set of automatic detections. It is a change in the evidence pipeline. If an Insider Risk Management policy is configured to watch a device action but a collection policy filters that action out, the event is not collected and cannot later appear for investigator review. That makes collection-policy design part of Insider Risk Management administration, rather than a separate data-governance task owned solely by DLP or information-protection teams.

Microsoft’s roadmap record, last updated on September 16, 2026, lists the feature for Microsoft Purview on the web and names GCC, GCC High, and DoD as supported cloud instances. Its general-availability field, however, says September 2025 despite the entry’s much later update date. Administrators should treat the roadmap’s current Launched status as confirmation that Microsoft considers the capability available, but should not infer that September 2025 was the date this Insider Risk Management interaction was first documented or surfaced to every tenant.

Device collection settings can remove IRM evidence​

Microsoft Learn draws a narrow but important boundary around the feature. The precedence rule applies to device indicators in Insider Risk Management policies, and only when a device collection policy has been deployed. It does not mean every collection policy automatically changes every cloud, Microsoft 365, or third-party signal available to Insider Risk Management.

For affected endpoint scenarios, though, the practical effect is direct. A collection policy can be configured around classifiers, file extensions, file size, selected user or group scopes, supported activities, and data sources. Microsoft documents endpoint activities including file access, creation, deletion, renaming, printing, archiving, upload to cloud services, copying to removable media, copying to network shares, Bluetooth transfer, and removable-media mount or unmount events.

An Insider Risk Management policy may be configured to consider a pattern that includes a file download or collection event, an archive operation, a rename intended to obscure a file, and later exfiltration. But the collection policy is upstream of that review process. If its device rules exclude one of those relevant activities, or exclude the user involved, the missing event does not become a low-priority signal. It disappears from the Insider Risk record available to analysts.

Microsoft says an event collected by a collection policy but not selected in an Insider Risk Management policy is simply ignored by Insider Risk Management. The reverse conflict is more consequential: when Insider Risk Management wants an event and the collection policy filters it out, collection wins.

That design is understandable from a data-minimization perspective. It also means a tightly scoped collection policy can quietly weaken an Insider Risk investigation without an administrator ever editing the Insider Risk policy itself.


Sensitive-information scoping changes what can be seen​

The roadmap announcement highlights Sensitive Information Types, or SITs, and activity scoping. Microsoft’s collection-policy reference shows that policy authors can choose all classifiers, all classifiers except selected ones, or specific classifiers. On devices, trainable classifiers are not supported; Microsoft says they are ignored if selected. That distinction matters for teams that have built Insider Risk detections around custom classification concepts and assume a similarly named collection-policy condition will preserve their endpoint coverage.

Collection policies can also limit detection by file extension and document size. In cloud and AI-connected data sources, they can target text or file uploads, text or file downloads, and other activities. For Windows devices onboarded to Microsoft 365, the activity catalog is much more endpoint-oriented: local file operations, removable media, remote desktop copy actions, cloud uploads, and other audit events.

The policy scope itself can be set to all users and groups, specific users and groups, or all users except named users and groups. Microsoft’s documentation says exclusions take precedence over inclusions. That means an exception added to reduce data collection for a privileged group, a pilot group, contractors, or executives can also eliminate applicable device evidence from Insider Risk Management if that group falls within an Insider Risk policy’s scope.

This is where separate Purview administration teams can create an avoidable blind spot. The collection-policy author may be pursuing a legitimate privacy, licensing, cost, or data-reduction objective. The Insider Risk administrator may be relying on a policy that still appears healthy in its own configuration pages. Neither setting is inherently wrong, but the effective detection scope is the intersection of the two policies, with collection rules serving as the gatekeeper.

Sequence detections are especially exposed to gaps​

Microsoft’s Insider Risk Management documentation describes sequence detection as the correlation of two or more potentially risky actions performed in order. Its four categories are collection, exfiltration, obfuscation, and clean-up. Examples include downloading files, moving content into a compressed folder, sending information externally, renaming files, and deleting files.

That correlation is useful precisely because a single action is often ambiguous. A file download can be ordinary work. An archive creation can be routine. A removable-media copy might be permitted for a field employee. The risk signal emerges when related events occur in sequence and around the same content or user behavior.

A collection-policy exclusion can break that chain. If a policy captures cloud uploads but not local archive creation, for example, the later upload may still be collected while the analyst loses a potentially meaningful preparatory action. If device file-read events are narrowed to particular classifiers or extensions, the organization may preserve evidence around labeled documents while losing context for ancillary files involved in the same incident.

Microsoft says Insider Risk Management can use filenames to map activities across a sequence. Missing events therefore affect more than event counts: they can reduce the chronology and context an investigator uses to decide whether conduct was routine, negligent, or malicious.

The product’s policy-health feature may identify incomplete policies, indicator issues, trigger failures, and approaching volume limits. Microsoft’s documentation does not say that policy health will independently diagnose every cross-solution conflict introduced by a collection policy. Administrators should not rely on a green or healthy Insider Risk policy status as proof that the endpoint telemetry they intended to evaluate is actually being retained.


Purview ownership now needs a shared change process​

The immediate administrative task is to identify every active device collection policy, who can modify it, and which Insider Risk Management policies use device indicators for overlapping users. Microsoft identifies several roles and groups that can be relevant to collection policies, including the DLP Compliance Management role and the Organization Management, Compliance Administrator, Insider Risk Management Admin, Information Protection Admins, and Data Security Viewers role groups.

That breadth is a warning sign for larger organizations. A change can originate outside the team reviewing Insider Risk alerts. Microsoft also documents that Data Security Posture Management and its AI-focused counterpart can create collection policies through one-click recommendations. An environment that allows multiple Purview solution owners to deploy policy changes needs change control that records the intended impact on Insider Risk telemetry.

A practical review should include the following:

  • Inventory deployed collection policies that include the Devices data source, rather than reviewing only policies created by the Insider Risk team.
  • Compare each policy’s included and excluded users, groups, classifiers, file extensions, and activities with the users and indicators configured in active Insider Risk Management policies.
  • Test representative endpoint actions with nonproduction users, including archive creation, removable-media copies, cloud upload, file rename, and file deletion where those actions matter to the organization’s risk scenarios.
  • Review Insider Risk policy health and actual user-activity records after the test, because a policy can remain enabled while required events are absent from the case timeline.
  • Require Purview policy owners to document whether a proposed collection-policy restriction intentionally limits Insider Risk Management evidence, and obtain approval from the Insider Risk program owner before deployment.

There is also a cost and governance reason to make this review deliberate. Microsoft says collection policies can use pay-as-you-go billing, per-user licensing, or both. Reducing collection can be a defensible way to control data volume and spend. But doing so without mapping the downstream investigative impact shifts the cost from collection to reduced evidentiary quality when an incident occurs.

The roadmap entry is a warning, not a new control plane​

Microsoft’s description could be read as a routine expansion of collection policies: use them to scope classifiers and activities for particular users. The detailed documentation shows the more consequential point. On Windows endpoints, collection policy is a control over what Insider Risk Management can later know.

Organizations using Purview for data-theft, data-leak, risky-AI-usage, or departing-user investigations should therefore treat their collection-policy inventory as part of their Insider Risk control set. A collection rule that excludes a device action may be an intentional privacy decision, but it is also a decision that the action will not be available when an investigator needs to reconstruct what happened.