Accelerating the quantum-safe timeline
July 1, 2026[Launched] Generally Available: Toolboxes in Microsoft Foundry
July 1, 2026Modern insider risk investigations succeed or fail based on how quickly analysts can move from signal to decision with more context. Too often, investigations within Microsoft Purview require high switching costs while analysts struggle with disconnected alert views and scattered case notes across workflows. Every switch slows triage pulling focus away from the risk itself, decreasing the speed and confidence of investigations.
That’s why we’re unifying the Microsoft Purview Insider Risk Management investigation experience with three connected improvements — a unified alert queue, expanded user profile details, and notes across alerts and cases. Analysts can now triage, understand context, and capture their work in a streamlined investigation flow to help enable faster investigations and increase confidence. Here’s what’s coming to public preview in July 2026:
1. One unified alert queue integrating classic and agent workflows together
The most disruptive part of triage happens before analysts dig into any single alert: understanding what alerts require the most attention. Today, that means toggling between the classic alert queue and the Data Security Triage Agent’s insights. We’re now bringing them together into a single, unified alerts list.
Instead of switching between two experiences, analysts get one page where they can:
- Preview agent summaries, alert details, and user details directly from the alerts list, reducing the need to open each alert individually.
- Filter all classic and agent attributes on one page, including a new agent categorization column and the ability to surface agent-triaged alerts that need attention.
- View and manage the agent directly from the alerts list.
- Open or act on an alert with the ability to stay within the queue.
As part of this unification, alert spotlighting is being retired, and the toggle between agent and classic alerts is going away in favor of the single view. To give teams time to adjust, both the classic and new experiences will remain available for at least 60 days, with support for both currently planned through August 31, 2026. Explore the unified alert queue here → New IRM Alert Experience.
Launch details: Public preview: July 2026 | Roadmap ID: 564621
2. Expanded user profile details to better understand user risk
Once an alert has been raised, the next question is about the person behind it: Who are they, and how much risk does this really represent? Answering that used to mean piecing context together from multiple places.
The expanded user profile brings context into one unified view by:
- Adding new signals from the user’s Entra profile including office location, employee type, department, and last working date.
- Aggregating key insider risk signals in one place including Entra profile details, past alert and case history, priority user group status, and policy inclusion.
The result is a fuller, more detailed picture of users’ risk, to provide investigators with more context for decisions without leaving the alert. See expanded user profile details here → New IRM Alert Experience
Where to find it: On the new Alerts (preview) tab — click Alerts (preview) in the left navigation, open an alert, scroll to User details, and select View user details. Note: when pseudo-anonymization is enabled, user profile details will not appear, preserving privacy by design.
Launch details: Public preview: July 2026 | Roadmap ID: 564619
3. Notes across alerts and cases keep context with the work
Investigation context shouldn’t live in someone’s memory or a side document. Analysts and investigators can now add and view notes directly in alerts and cases within the Purview portal, ensuring the story of an investigation stays with the investigation.
Notes come in two forms:
- System-generated notes are applied automatically on key changes including alert or case status, assigned user, alert or case closure, and case escalations.
- Analyst notes let investigators capture their own observations as they work
This gives teams continuity and a clearer record of investigation activity history without breaking stride.
Where to find it: In the Notes tab within the alert details panel, and within the Cases tab within a case. Start capturing notes across alerts and cases here→ New IRM Alert Experience
Launch details: Public preview: July 2026 | Roadmap ID: 564620
Ready to get started? Try the unified Insider Risk Management experience today: Click here to get started
Privacy Statement:
Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.