Indicators that contribute to assessing employees as potential 'insider threats' can include "unacceptable web usage" or "risky browser usage".
Microsoft explains that “workplace stress may lead to uncharacteristic or malicious behavior” by employees that could “surface as potentially inappropriate behavior” in employee communication.
It suggests to use the system to address a wide range of "risks from illegal, inappropriate, unauthorized, or unethical behavior and actions" by employees.
While Microsoft Purview combines various tools for security, risk profiling and compliance, Microsoft Sentinel specifically promises to help organizations prevent cyberattacks, including by 'insiders'.
At its core, Sentinel is a 'security information and event management' (SIEM) system. It analyzes log data on device, file, process, network and mail activity, up to millions of log records per second, including activity logs from Office, Exchange, Teams, Salesforce, SAP, Confluence/Jira, Zoom...