From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
Manage forensic evidence settings - Microsoft 365 Tutorial
From the course: Microsoft Information Security Administrator Associate (SC-401) Cert Prep by Microsoft Press
Manage forensic evidence settings
By this point, you should be getting very comfortable and familiar with creating policies within Purview. And creating an IRM policy is not an awful lot different. So let's just walk through and see how it differs, because there are some differences between an IRM policy and other policies in Purview. And of course, the reason we need policies, if If it wasn't obvious, was without policies, we're not going to be able to trigger alerts and investigations. So let's go. As you can see, fairly normal here. So we'll just call it data leak. We're gonna just put everybody in and now we can exclude users and groups, which I'm not going to do. And then you can see we can prioritize things. So I'm gonna leave it on the default. so we're going to prioritize SharePoint sensitivity label. It's going to use these indicators to prioritize. Then we can also look for a triggering event. We can actually give it a SharePoint site. We'll do the Zava Tiger Team there as a priority SharePoint site, and I…
Contents
-
-
-
-
-
-
-
-
-
(Locked)
Module introduction1m 30s
-
(Locked)
Learning objectives1m 23s
-
(Locked)
Implement roles and permissions for Insider Risk Management4m 49s
-
(Locked)
Plan and implement Insider Risk Management connectors9m 4s
-
(Locked)
Plan and implement integration with Microsoft Defender for Endpoint3m 3s
-
(Locked)
Configure and manage Insider Risk Management settings4m 4s
-
(Locked)
Configure policy indicators5m 55s
-
(Locked)
Select an appropriate policy template4m 13s
-
(Locked)
Create and manage Insider Risk Management policies6m 4s
-
(Locked)
Manage forensic evidence settings5m 17s
-
(Locked)
Enable and configure insider risk levels for Adaptive Protection4m 4s
-
(Locked)
Manage insider risk alerts and cases8m 52s
-
(Locked)
Manage Insider Risk Management workflow, including notice templates10m 1s
-
(Locked)
-
-
-