Like Forcepoint/Everfox, Microsoft's insider risk tech promises to detect suspicious employee behavior and communication.
It calculates risk scores for employees and ranks them by risk. To detect 'unusual' behavior, it can profile behavior across many employees, and over time.
A lot of personal data processing and profiling.
In addition to employee communication, the system can access device and browser data on file/app/web activity, meetings, 'employee profile data', performance rating from HR systems, badging data, and activity data from other software provided by Microsoft (e.g. Exchange, Teams, OneDrive, Entra, Defender) and other vendors (e.g. Salesforce, Dropbox, SIEM systems).
Section 6 in my report summarizes the data practices/sources/purposes identified for the Purview insider risk management system.