In addition to employee communication, the system can access device and browser data on file/app/web activity, meetings, 'employee profile data', performance rating from HR systems, badging data, and activity data from other software provided by Microsoft (e.g. Exchange, Teams, OneDrive, Entra, Defender) and other vendors (e.g. Salesforce, Dropbox, SIEM systems).
Section 6 in my report summarizes the data practices/sources/purposes identified for the Purview insider risk management system.
Employers can then use Microsoft Purview's communication monitoring and insider risk systems to further investigate 'suspicious' employees and their past behavior, including their website visits, file and application usage, badging activity and communication contents.
For 'forensic' investigations, employers can access screen recordings and fine-grained user interaction data.