Microsoft 365 Message Center item MC1438568
MC1438568 - Microsoft Purview | Insider Risk Management triage agent summaries available in Microsoft Defender
Microsoft Purview Insider Risk Management triage agent summaries will appear in Microsoft Defender alerts, providing AI-generated insights to streamline investigations. This feature rolls out from mid-August to December 2026, enabling easier alert review without changing existing configurations. No action is needed if prerequisites are met.
- Message Center ID
- MC1438568
- Category
- stay Informed
- Severity
- normal
- Services
- Microsoft Purview
- Tags
- New feature, User impact, Admin impact
- Roadmap ID
- 567472
- Platforms
- Web
- Published
- 2026-07-24
- Last updated
- 2026-07-24
- Expires
- 2027-01-31
[What and why]We're introducing Insider Risk Management (IRM) triage agent summaries in Microsoft Defender. This enhancement helps investigators review key risk insights directly from the Defender alert queue, reducing the need to switch between security tools during alert triage.When the IRM triage agent is enabled and Insider Risk Management alerts are shared with Microsoft Defender, supported alerts will include AI-generated summaries such as alert categorization, investigation findings, observed risk patterns, and relevant user context. Investigators can continue to access the complete investigation experience in Microsoft Purview for deeper analysis.This message is associated with Microsoft 365 Roadmap ID 567472.[Rollout schedule]Public Preview: Beginning in mid-August 2026 and expected to complete in early September 2026General Availability (Worldwide): Beginning in early December 2026 and expected to complete in late December 2026 [Impact on your organization]Who is affectedOrganizations that share Microsoft Purview Insider Risk Management alerts with Microsoft DefenderOrganizations that have the IRM triage agent enabled and activeSecurity analysts and investigators who review Insider Risk Management alerts in Microsoft DefenderPlatforms and servicesMicrosoft DefenderMicrosoft Purview Insider Risk ManagementWebWhat will happenSupported Insider Risk Management alerts in Microsoft Defender will display IRM triage agent summaries: Summaries may include alert categorization, investigation findings, identified risk patterns, and relevant user context.The feature will be enabled automatically for organizations that meet the prerequisites.Existing alert-sharing configurations between Insider Risk Management and Microsoft Defender will be preserved.There is no impact to existing configurations or workflows.After rollout, investigators can:Review Insider Risk Management alerts in Microsoft Defender.Access the full investigation experience in Microsoft Purview when needed.[Action required and recommendations:]No action is required if your organization already meets the prerequisites.Review the following to ensure readiness:Confirm that Insider Risk Management alerts are being shared with Microsoft Defender.Confirm that the IRM triage agent is deployed and active.Inform security operations and investigation teams about the new triage experience.Update any internal documentation that references Insider Risk Management alert investigations.[Compliance considerations]QuestionAnswerDoes the change introduce or significantly modify AI/ML or agent capabilities that interact with or provide access to customer data?Yes. IRM triage agent summaries are surfaced within Microsoft Defender and provide AI-generated investigation context derived from Insider Risk Management alert data.