A woman reviews a dark-blue employee profile and security dashboard on a large monitor in an office.
Microsoft Purview Insider Risk Management (IRM) now shows investigators more of the user's profile inside the alert itself. Roadmap item 564619, "Enhanced user profile in IRM alerts," is marked Launched. It lists general availability in October 2026 after a July 2026 preview, and it covers Worldwide (Standard Multi-Tenant), GCC, GCC High and DoD tenants on the web.

The change is simple, and it matters. When an alert fires, the analyst's first question is usually who the person is and how worried they should be. Answering that used to mean opening other pages. Now a lot of the answer sits in the alert workflow.

What's changing in IRM alerts​

The roadmap entry says Microsoft is expanding the User section of IRM alerts. Investigators get more user profile and risk details without leaving the alert. The fields it names are:

  • Employee type
  • Office location
  • Start date
  • Policy inclusion
  • Priority user group status
  • Last working day

The roadmap says the feature belongs to the new alert workflow and appears in the Alert Details panel. It also says Microsoft will add more user attributes over time, with pseudo‑anonymization honored to support privacy‑by‑design investigation practices.

Microsoft's Learn documentation describes the feature this way: In the unified alert experience, you can view expanded user profile details directly from an alert. The expanded user profile aggregates all Insider Risk Management user signals into a unified view, making it easier to understand complete user risk at a glance.

Section summary: The profile panel moves context that investigators already needed into the alert view, so they spend less time switching pages.

Which fields are documented, and one mismatch​

Microsoft's Users-dashboard documentation lists the extra profile signals available in the unified alert experience:

FieldWhere it comes from / what it shows
Office locationThe user's Entra profile
Employee typeThe user's Entra profile
DepartmentThe user's Entra profile
Last working dateThe user's last scheduled day of work, if available
Past alert and case historyA summary of the user's previous alerts and cases across Insider Risk Management.
Priority user group statusShows whether the user belongs to any priority user groups.
Policy inclusionLists the policies in which the user is currently in scope.

Microsoft's launch post on its Tech Community security blog gives the same structure. The expanded profile adds new signals from the user's Entra profile including office location, employee type, department, and last working date. It also gathers past alert and case history, priority user group status and policy inclusion in one place.

The two sources don't match exactly. The roadmap lists start date, but the current Learn field list and Microsoft's launch blog do not. Department shows up in Learn and the blog but not in the roadmap text. The roadmap's promise of more attributes over time may explain it. Until start date appears in the documentation or in your own tenant, treat it as planned rather than confirmed.

Section summary: The confirmed core is four Entra fields plus three IRM signals. Start date is in the roadmap only for now.

How to find it​

Microsoft documents the steps:

  1. In the Insider Risk Management solution, select Alerts (preview) in the left navigation.
  2. Select an alert.
  3. Scroll down to User details.
  4. Select View user details.

What success looks like: The expanded panel shows Entra profile fields such as office location and department next to the user's alert and case history, priority group membership and in-scope policies.

If you can't see it, check these first:

  • You're in the classic dashboard. The feature is tied to the unified Alerts (preview) experience. Microsoft's Message Center notice (MC1429017) says the affected audience is tenants using the Alerts (Preview) experience.
  • Pseudo-anonymization is on. Microsoft is direct about this: When pseudo-anonymization is enabled, the expanded user profile details aren't visible. This is by design, not a bug. Don't turn anonymization off just to see the panel. That's a governance decision, often involving HR, legal or works councils, not a quick troubleshooting step.
  • Rollout timing. A third-party archive of the Message Center notice gives the schedule: General Availability (Worldwide, GCC, GCC High, DoD): Beginning early October 2026; expected to complete by mid-October 2026. Some tenants may not have it yet.
  • Empty Entra fields. The Entra-sourced fields come from the user's directory profile. If office location or employee type was never filled in, the alert can't show it. (This last point is our inference from the documented data source, not a statement from Microsoft.)

Where it fits: the unified alert experience​

This is one of three related changes. Redmondmag described the release as three connected improvements including a unified alert queue, expanded user profile details and notes across alerts and cases. Petri reported that Microsoft is combining traditional Insider Risk Management alerts and Data Security Triage Agent alerts into a single alert queue.

The unified queue has its own roadmap ID (564621), separate from this profile feature (564619), according to Microsoft's blog. It also changes some existing habits. Learn notes that Alert Spotlight is no longer available in the unified experience. To prioritize agent-triaged alerts, use the Needs Attention filter instead.

The bigger point for administrators is Microsoft's stated schedule: The classic and new alert experiences will both be available for at least 60 days. After August 31, only the unified experience will be supported. That date has passed, so features like this enhanced profile now land in the alert view Microsoft actually supports. They aren't an optional extra on the side anymore.

Section summary: The profile panel is one part of Microsoft's move to a single alert queue. That queue is the only supported IRM alert view after August 31.

Why investigators should care, and what it doesn't do​

Here's the practical case. A spike in file downloads looks very different coming from a contractor with a last working date next Friday than from a long-serving employee in the middle of a project migration. Employee type, last working date and priority group membership help an analyst read the same activity in very different ways. Having them in the alert saves real time when the queue is long.

Some limits are worth stating plainly:

  • It's context, not a verdict. A departing employee or priority-group member hasn't done anything wrong because of that label. IRM still relies on policies, indicators and human triage. Analysts confirm an alert and open or add to a case, or they dismiss it.
  • Nothing in Microsoft's documentation says these fields change detection, risk scoring or policy scope. They are display context. Read them that way unless Microsoft says otherwise.
  • Privacy controls stay in place. Microsoft's notice says the change keeps privacy-by-design protections such as pseudonymization, role-based access controls, and audit logging. Showing more personal data in one view still deserves a look from whoever owns your IRM governance.
  • Your directory data has to be right. If Entra attributes are stale, investigators get stale context faster.

Microsoft's own notice says the rollout needs no immediate action, but review and communication are recommended. That's sensible. Brief your analysts on the new panel, confirm your Entra attributes are filled in correctly, and make sure privacy stakeholders know what investigators can now see when anonymization is off.

Bottom line​

This isn't a headline Purview feature, but it removes a common annoyance. Investigators get the "who is this person?" context inside the alert they're already working. The confirmed fields are office location, employee type, department, last working date, alert and case history, priority group status and policy inclusion. The roadmap also promises start date and more. The profile only appears in the unified Alerts (preview) experience, and it stays hidden when pseudo-anonymization is on. If your security team uses Insider Risk Management, check the Alerts (preview) tab this month.

 

References

  1. Microsoft Purview: Insider Risk Management - Enhanced user profile in IRM alerts Microsoft 365 Roadmap 2026-10-06T22:56:31.053213Z
  2. Microsoft Unifies Insider Risk Alerts Across Purview Insider Risk Management -- Redmondmag.com redmondmag.com
  3. Microsoft Purview Insider Risk Management Gets Unified Alert Experience petri.com