Adaptive Protection: making a DLP policy risk-aware
Verdict: Add the "User's insider risk level for Adaptive Protection is" condition and set the levels to enforce. Custom setup needs an Insider Risk Management policy first as the signal source. Typical pattern: audit Moderate/Minor, block Elevated.
A DLP policy only reacts to insider risk once the risk-level condition names which levels trigger it.
- Create (or reuse) an Insider Risk Management policy - this supplies the signals Adaptive Protection scores users against.
- On the Insider risk levels tab, select that IRM policy as the source, then accept or customise the built-in Elevated, Moderate and Minor definitions.
- In the DLP rule, add the 'User's insider risk level for Adaptive Protection is' condition - this is the one condition required for the policy to participate in Adaptive Protection at all.
- Set the condition to the specific levels (Elevated, Moderate, Minor) the rule should enforce against - the policy only fires dynamically for the levels you list.
- Tune actions per level: a common pattern is audit-only for Moderate/Minor and block for Elevated.
Rules
- The 'User's insider risk level for Adaptive Protection is' condition is the one that makes a DLP policy participate in Adaptive Protection; without it the policy is a normal static rule.
- 'Insider risk level for Adaptive Protection is' is a supported Endpoint (Devices) DLP condition, alongside 'Content is not labeled' and 'File type is'.
- Custom setup requires an Insider Risk Management policy to exist first; select it on the Insider risk levels tab before accepting or customising the built-in Elevated/Moderate/Minor definitions.
- Elevated (built-in default) means one or more confirmed high-severity alerts, or at least three sequence insights each carrying a high-severity alert for specific risk activities.
- The risk-level condition enforces dynamically: set it to the levels the rule should act on, leaving other levels unaffected by that rule.
Traps
- Adding the risk-level condition is not enough on its own - it must be set to specific levels (Elevated/Moderate/Minor), or the policy has nothing to enforce against.
- Custom setup's Insider risk levels tab needs an existing IRM policy as its signal source before the built-in level definitions can be accepted or customised - a DLP policy with the condition already in it is not the prerequisite.
- Elevated by default is confirmed high-severity alerts or 3+ high-severity sequence insights - not medium-severity alerts or low-severity exfiltration activity, which describe Moderate/Minor instead.