Forensic evidence is an opt-in add-on feature in Microsoft Purview Insider Risk Management that gives security teams visual insights into potential insider data security incidents, with user privacy built in. Organizations can purchase the add-on in units of 100GB per month.
Forensic Evidence add-on for Microsoft Purview Insider Risk Management
100GB monthly capacity
Optional feature with customizable event triggers
Built-in user privacy protection controls
Opt-in, off by default
Dual authorization required for policy creation
User pseudonymization on by default
Role-based access controls (RBAC)
Monthly capacity resets on the first of the month
Unused capacity does not carry over
Supports security investigation and incident response
Supports insider data risk detection and analysis