Forum Discussion

Linas1's avatar
Linas1
Copper Contributor
Aug 07, 2025

Insider Risk Management Alerts/Activities issue

Hello,

we have a problem where Insider Risk Management is generating activity data/alerts based on false data (sort of).

There is an activity called: EPOFILEARCHIVED or FileArchived that is done by the SenseCE.exe application. SenseCE is "Windows Defender Advanced Threat Protection Sense CE module" according to 3rd party source and "Data Loss Prevention Classification" according to another, I guess it is related as a service application for Endpoint DLP as well.

Anyways, it is generating lots of false activity and there is not any actual way to exclude this activity (as an app or as an activity type) from Purview and it introduces false data into Insider Risk Management (which picks it up as an Archive activity). 

Anyone have similar issues or have another explanation why this activity is appearing? Perhaps there are ways to remedy this somehow?

Example:

 

1 Reply

  • Linas1's avatar
    Linas1
    Copper Contributor

    It does seem that this FileArchived action triggers with archive type files, but these files were only being opened within File Explorer.

Resources