Today, admins can enable the risk score booster “Activity is above user’s usual activity for that day”. With this update, the model to detect unusual activity will be enhanced to improve the ability to detect when a user’s activity is unusual compared to their historical norms. If an admin has opted-in to the “Activity is above user’s usual activity for that day” risk score booster in settings, the organization might see fewer activities with the risk score booster. Microsoft Purview Insider Risk Management correlates various signals to identify potential malicious or inadvertent insider risks, such as IP theft, data leakage, and security violations. Insider Risk Management enables customers to create policies to manage security and compliance. Built with privacy by design, users are pseudonymized by default, and role-based access controls and audit logs are in place to help ensure user-level privacy.