Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT154
  • Created: 03rd May 2026
  • Updated: 03rd May 2026
  • Contributor: The ITM Team

Microsoft Purview Communication Compliance

Microsoft Purview Communication Compliance enables investigators to detect policy-violating, inappropriate, or high-risk communications across Microsoft 365 and supported third-party communication channels, including enterprise AI. It can identify messages involving sensitive data disclosure, harassment, threats, regulatory misconduct, business conduct violations, or other communications that may indicate insider risk.

 

This detection supports review of subject communications using defined policies, machine learning classifiers, keyword matching, sensitive information types, and investigator workflows. Alerts should be assessed in context and correlated with related evidence such as DLP events, audit logs, eDiscovery results, Teams activity, HR context, and prior case history. Communication Compliance findings should not be treated as standalone proof of intent, but as structured investigative leads requiring authorized human review.

Sections

ID Name Description
IF036Misuse of Corporate Communication Channels

A subject uses organization-managed communication channels to send, distribute, or amplify messages that violate acceptable use expectations, undermine workplace safety, damage operational trust, or create legal, reputational, or personnel risk. This may occur through email, enterprise messaging platforms, collaboration tools, internal forums, ticketing systems, shared document comments, or other corporate communication environments.

PR050Trusted Relationship Cultivation

A subject deliberately develops a relationship of trust with a colleague, administrator, service provider, customer, or control owner to obtain future assistance, information, approval, or reduced scrutiny.

 

The conduct may involve repeatedly offering help, volunteering for tasks, creating dependency, demonstrating apparent reliability, or establishing informal communication outside approved processes. The relationship is later used to secure exceptional access, accelerate a request, obtain confidential information, bypass verification, or discourage challenge.

 

This would not classify ordinary professional relationship-building. Investigative relevance arises where the relationship is developed or exploited to enable a subsequent infringement.

IF044Abuse of Decision-Making Authority

A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.

 

The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.

 

This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.

 

This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right.

IF036.004Extremist Communication Content

A subject distributes extremist, radicalizing, terrorist-supportive, or ideologically violent material through organization-managed communication channels. This may include propaganda, manifestos, violent ideological imagery, symbols associated with extremist organizations, recruitment material, or communications endorsing politically, religiously, racially, or ideologically motivated violence.

IF036.003Offensive Communication Content

A subject distributes offensive, graphic, obscene, degrading, or inflammatory material through organization-managed communication channels. This may include content that violates acceptable use expectations, disrupts workplace operations, damages team trust, or creates legal, reputational, or personnel risk.

IF036.002Inappropriate Sexual or Explicit Communications

A subject uses corporate communication channels to send, request, display, or distribute sexually explicit, obscene, or otherwise inappropriate material unrelated to legitimate business activity. This may include explicit images, sexualized comments, unwanted personal advances, or inappropriate jokes distributed through work systems.

IF036.001Hostile, Abusive, or Threatening Communications

A subject uses organization-managed communication channels to send hostile, abusive, coercive, intimidating, or threatening messages to another individual or group. This may include direct insults, aggressive language, repeated disparagement, intimidation, implied retaliation, coercive demands, or threats of professional, personal, or physical harm.

IF043.003Equipment or Facility Diversion

A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity.

IF044.001Unauthorized Approval

A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.

 

Examples include:

  • approving access for a favored individual without business justification
  • approving a supplier despite an undisclosed conflict
  • authorizing expenditure outside the intended purpose
  • approving an exception using false or incomplete supporting information

 

The defining evidence is an affirmative decision made through authority legitimately assigned to the subject.

IF044.002Improper Denial

A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.

 

Examples include:

  • denying a legitimate customer request because of a personal dispute
  • refusing an employee entitlement in retaliation
  • blocking a supplier or applicant to benefit an associate
  • rejecting an access request despite established eligibility
  • withholding an approval to exert pressure on another individual
IF044.004Suppression of Escalation or Review

A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.

 

Examples include:

  • preventing a security concern from being referred to the appropriate team
  • closing a complaint without the required review
  • declining to escalate a report involving an associate
  • directing that an audit finding not be formally recorded
  • narrowing an investigation to exclude relevant conduct or evidence
IF044.005Unauthorized Waiver or Control Exception

A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.

 

Examples include:

  • waiving identity-verification requirements
  • exempting a transaction from secondary review
  • overriding a mandatory security or compliance check
  • allowing work to proceed despite an unmet control condition
  • approving an exception without recording the required rationale
IF044.006Unauthorized Prioritization or Deprioritization

A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.

 

Examples include:

  • moving an associate’s request ahead of others without justification
  • deliberately delaying a complaint until a deadline expires
  • deprioritizing a customer because of a personal disagreement
  • changing case urgency to avoid scrutiny or service obligations
  • accelerating a transaction so that required review cannot occur
AF030.004Bulk Deletion of Message History

A subject deletes a substantial volume of messages, conversations, threads, channels, or communication history to remove or materially reduce the records available for investigation.

 

Bulk deletion may involve selecting and deleting multiple messages, repeatedly deleting individual messages within a short period, clearing an entire conversation, removing channel history, deleting archived communications, or using scripts, administrative tools, application programming interfaces, or automation to remove content at scale.

 

The behavior may occur after the subject becomes aware of an investigation, disciplinary process, access review, audit, legal dispute, or anticipated offboarding. It may also occur immediately before the subject conducts another infringement where prior communications could reveal planning, coordination, relationships, or intent.

 

The significance of bulk deletion should be assessed against the subject’s normal messaging activity, the amount of content removed, the time period affected, the platforms involved, and whether the deleted communications related to known subjects, external parties, sensitive projects, or active investigations.

 

Investigators should identify deletion event volume, timestamps, conversation identifiers, affected participants, client or application source, administrative actions, and any corresponding data preserved through retention or legal-hold systems.

AF030.005Administrative Deletion of Communication Messages

A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.

 

The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.

 

This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.

 

Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.

 

The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event.

AF030.006Deletion of Communication Containers

A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.

 

Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.

 

The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.

 

Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed.