detections
- ID: DT154
- Created: 03rd May 2026
- Updated: 03rd May 2026
- Contributor: The ITM Team
Microsoft Purview Communication Compliance
Microsoft Purview Communication Compliance enables investigators to detect policy-violating, inappropriate, or high-risk communications across Microsoft 365 and supported third-party communication channels, including enterprise AI. It can identify messages involving sensitive data disclosure, harassment, threats, regulatory misconduct, business conduct violations, or other communications that may indicate insider risk.
This detection supports review of subject communications using defined policies, machine learning classifiers, keyword matching, sensitive information types, and investigator workflows. Alerts should be assessed in context and correlated with related evidence such as DLP events, audit logs, eDiscovery results, Teams activity, HR context, and prior case history. Communication Compliance findings should not be treated as standalone proof of intent, but as structured investigative leads requiring authorized human review.
Sections
| ID | Name | Description |
|---|---|---|
| IF036 | Misuse of Corporate Communication Channels | A subject uses organization-managed communication channels to send, distribute, or amplify messages that violate acceptable use expectations, undermine workplace safety, damage operational trust, or create legal, reputational, or personnel risk. This may occur through email, enterprise messaging platforms, collaboration tools, internal forums, ticketing systems, shared document comments, or other corporate communication environments. |
| PR050 | Trusted Relationship Cultivation | A subject deliberately develops a relationship of trust with a colleague, administrator, service provider, customer, or control owner to obtain future assistance, information, approval, or reduced scrutiny.
The conduct may involve repeatedly offering help, volunteering for tasks, creating dependency, demonstrating apparent reliability, or establishing informal communication outside approved processes. The relationship is later used to secure exceptional access, accelerate a request, obtain confidential information, bypass verification, or discourage challenge.
This would not classify ordinary professional relationship-building. Investigative relevance arises where the relationship is developed or exploited to enable a subsequent infringement. |
| IF044 | Abuse of Decision-Making Authority | A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.
The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.
This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.
This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right. |
| IF036.004 | Extremist Communication Content | A subject distributes extremist, radicalizing, terrorist-supportive, or ideologically violent material through organization-managed communication channels. This may include propaganda, manifestos, violent ideological imagery, symbols associated with extremist organizations, recruitment material, or communications endorsing politically, religiously, racially, or ideologically motivated violence. |
| IF036.003 | Offensive Communication Content | A subject distributes offensive, graphic, obscene, degrading, or inflammatory material through organization-managed communication channels. This may include content that violates acceptable use expectations, disrupts workplace operations, damages team trust, or creates legal, reputational, or personnel risk. |
| IF036.002 | Inappropriate Sexual or Explicit Communications | A subject uses corporate communication channels to send, request, display, or distribute sexually explicit, obscene, or otherwise inappropriate material unrelated to legitimate business activity. This may include explicit images, sexualized comments, unwanted personal advances, or inappropriate jokes distributed through work systems. |
| IF036.001 | Hostile, Abusive, or Threatening Communications | A subject uses organization-managed communication channels to send hostile, abusive, coercive, intimidating, or threatening messages to another individual or group. This may include direct insults, aggressive language, repeated disparagement, intimidation, implied retaliation, coercive demands, or threats of professional, personal, or physical harm. |
| IF043.003 | Equipment or Facility Diversion | A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity. |
| IF044.001 | Unauthorized Approval | A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.
Examples include:
The defining evidence is an affirmative decision made through authority legitimately assigned to the subject. |
| IF044.002 | Improper Denial | A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.
Examples include:
|
| IF044.004 | Suppression of Escalation or Review | A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.
Examples include:
|
| IF044.005 | Unauthorized Waiver or Control Exception | A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.
Examples include:
|
| IF044.006 | Unauthorized Prioritization or Deprioritization | A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.
Examples include:
|
| AF030.004 | Bulk Deletion of Message History | A subject deletes a substantial volume of messages, conversations, threads, channels, or communication history to remove or materially reduce the records available for investigation.
Bulk deletion may involve selecting and deleting multiple messages, repeatedly deleting individual messages within a short period, clearing an entire conversation, removing channel history, deleting archived communications, or using scripts, administrative tools, application programming interfaces, or automation to remove content at scale.
The behavior may occur after the subject becomes aware of an investigation, disciplinary process, access review, audit, legal dispute, or anticipated offboarding. It may also occur immediately before the subject conducts another infringement where prior communications could reveal planning, coordination, relationships, or intent.
The significance of bulk deletion should be assessed against the subject’s normal messaging activity, the amount of content removed, the time period affected, the platforms involved, and whether the deleted communications related to known subjects, external parties, sensitive projects, or active investigations.
Investigators should identify deletion event volume, timestamps, conversation identifiers, affected participants, client or application source, administrative actions, and any corresponding data preserved through retention or legal-hold systems. |
| AF030.005 | Administrative Deletion of Communication Messages | A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.
The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.
This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.
Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.
The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event. |
| AF030.006 | Deletion of Communication Containers | A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.
Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.
The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.
Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed. |