Adaptive Protection: making a DLP policy risk-aware

Verdict: Add the "User's insider risk level for Adaptive Protection is" condition and set the levels to enforce. Custom setup needs an Insider Risk Management policy first as the signal source. Typical pattern: audit Moderate/Minor, block Elevated.

A DLP policy only reacts to insider risk once the risk-level condition names which levels trigger it.

  1. Create (or reuse) an Insider Risk Management policy - this supplies the signals Adaptive Protection scores users against.
  2. On the Insider risk levels tab, select that IRM policy as the source, then accept or customise the built-in Elevated, Moderate and Minor definitions.
  3. In the DLP rule, add the 'User's insider risk level for Adaptive Protection is' condition - this is the one condition required for the policy to participate in Adaptive Protection at all.
  4. Set the condition to the specific levels (Elevated, Moderate, Minor) the rule should enforce against - the policy only fires dynamically for the levels you list.
  5. Tune actions per level: a common pattern is audit-only for Moderate/Minor and block for Elevated.

Rules

Traps