Insider Risk Management policies and alerts tools
Add CRUD coverage for Purview Insider Risk Management policies and alerts, to the same standard as Conditional Access and Safe Links (list, get, create, update, delete, each with its own safety flags). Use case: pull open alerts for a tenant during an incident review.
Log in to comment and vote
Comments1
Christopher Scaminaci
Oct 5
All six shipped in one release. Every CIPP tool here needs CIPP 10.5.0 or later.
Sensitivity labels and label policies: list, deploy (create or update), edit and remove labels. Label policies are read and deployed with the label. CIPP has no label policy delete.
DLP: list, deploy with rules, edit and remove policies; read rules. CIPP has no standalone rule delete; disable a rule through the deploy.
Retention: every read you asked for (the rule and scope detail on the retention policy list needs CIPP 10.10.0 or later), plus retention policy deploy, edit and remove on CIPP. Retention label create, update and delete are on Microsoft Graph (graph_create_retention_label, graph_update_retention_label, graph_delete_retention_label).
Insider Risk Management: alerts ship as graph_list_insider_risk_alerts. IRM policies have no Microsoft API or PowerShell cmdlet.
Communication Compliance: policy and rule reads ship. Microsoft does not support creating or managing these policies from PowerShell or any API.
Custom sensitive information types: list, rule package read, deploy from a regex or a rule pack, remove. These need CIPP 10.6.0 or later.
The Graph label tools use two new Microsoft permissions. Each Microsoft connection picks them up on its next sign-in; in a tenant where users cannot approve admin permissions, an admin approves once.