Forum Discussion
Insider Risk Level not being correctly picked up by DLP
I have two users currently with assigned Insider Risk levels, one elevated and one minor. I have taken the templated DLP policy (DSPM for AI - Block sensitive info from AI sites) which looks for sensitive information being pasted to generative AI sites, and applies a block if the user is an elevated risk user, and a block with override for a moderate/minor risk user (this was audit only originally).
For each advanced DLP rule within that policy, I have a separate policy tip which shows so I know which Advanced DLP rule has been hit.
However, I'm having some discrepancies with the correct insider risk level being identified by Purview and therefore the wrong advanced DLP rule is being applied.
Testing examples:
Logged into a Windows 11 PC with the account, and using Medium confidence UK NINO's I try pasting the content into ChatGPT:
- Elevated risk user: Block with Override
- Minor Risk user: Block with Override
If I try the exact same scenario on a different PC, I can sometimes get to the point where even though its the same set of data, Purview allows me to paste it at after checking the data. Or in another scenario, I was getting both users hitting the "elevated risk" advanced DLP rule.
The Devices are all showing as up to date sync wise with DLP policies, and the policy itself is showing as fully synced.
Assigned insider risk levels:
DLP Rules:
Elevated:
Moderate/Minor: