Control 1.12: Insider Risk Detection and Response - Troubleshooting
This playbook provides troubleshooting guidance for Control 1.12.
Common Issues
Issue: No Alerts Being Generated
Symptoms: Policy active but no alerts
Solutions:
- Verify policy is in "Production" mode (not test)
- Check user scope includes target users
- Review indicator thresholds (may be too high)
- Verify data connectors are functioning
- Wait 24-48 hours for initial data collection
Issue: Too Many False Positives
Symptoms: High volume of non-risky alerts
Solutions:
- Adjust threshold settings to higher values
- Refine priority content selection
- Use priority user groups to focus
- Add exclusions for known legitimate activities
- Review and tune indicator weights
Issue: HR Connector Not Working
Symptoms: Departing user policy not triggering
Solutions:
- Verify HR connector configuration
- Check field mappings are correct
- Validate test user has resignation date
- Review connector logs for errors
- Ensure Microsoft Entra ID integration is active
Issue: Cannot See User Activities
Symptoms: Alert shows no activity details
Solutions:
- Verify audit logging is enabled
- Check user isn't in privacy exclusion
- Confirm reviewer has proper role
- Review privacy settings in config
- Enable content preview if needed
Issue: Alerts Not Escalating
Symptoms: High-severity alerts not creating cases
Solutions:
- Verify escalation rules are configured
- Check investigator assignments
- Review alert severity mapping
- Confirm notification settings
- Check for workflow bottlenecks
Issue: Analytics Not Showing Data
Symptoms: Analytics dashboard empty after 48 hours
Solutions:
- Verify analytics is enabled
- Check sufficient data volume exists
- Confirm policies are active
- Review data connector status
- Contact Microsoft support if persists
Issue: Priority User Group Not Applied
Symptoms: Priority users not receiving enhanced monitoring
Solutions:
- Verify user is member of priority group
- Check policy includes priority user group
- Confirm group synchronization complete
- Review group membership sources
- Test with new user added to group
Escalation Path
If issues persist:
- First tier: Insider Risk Admin - policy configuration
- Second tier: HR - data connector coordination
- Third tier: Legal - investigation procedures
- Fourth tier: Microsoft Support - platform issues
Updated: January 2026 | Version: v1.2