Microsoft 365 E5 Insider Risk Management [New Commerce Experience]
Microsoft 365 E5 Insider Risk Management
An E5 compliance component add-on covering the insider risk area of Microsoft Purview. Microsoft's service description lists it as a qualifying licence for Insider Risk Management, Communication Compliance, Customer Lockbox and Purview Data Connectors. Two boundaries decide whether it fits. Communication Compliance under this add-on covers Teams chats, Viva Engage conversations and Exchange Online email, but Microsoft records prompt and response analysis for Microsoft 365 Copilot as not included; the service description records that for Microsoft 365 E5 with Copilot and for the Purview Suite with Copilot. And the licence is not the whole cost, because Microsoft meters several insider risk indicators separately under a pay as you go billing model.
What it is
One of the Microsoft 365 E5 compliance component add-ons, beside Information Protection and Governance and eDiscovery and Audit, with the full set sold as the Microsoft Purview Suite.
Who it is for
Tenants with a supervision, conduct or data theft obligation that do not need the rest of an E5 upgrade. Confirm the qualifying base entitlement in Product Terms before ordering.
The four solutions it grants
- Insider Risk Management, the policies, alerts and case workflow
- Communication Compliance, covering Teams chats, Viva Engage conversations and Exchange Online email
- Customer Lockbox, the approval step before a Microsoft support engineer can reach your content in Exchange Online, SharePoint, OneDrive, Teams and Windows 365
- Purview Data Connectors, for bringing third party communication sources under policy
The Copilot boundary, stated precisely
Microsoft's Communication Compliance table records Microsoft Copilot for Microsoft 365 prompt and response analysis as not included under this add-on. The service description records it for Microsoft 365 E5 with Microsoft 365 Copilot and for the Purview Suite with Microsoft 365 Copilot.
That is a statement about Communication Compliance only, and it is worth separating from what Insider Risk Management itself can do. Microsoft documents a Risky AI usage template that detects prompts and AI responses containing sensitive information across Microsoft 365 Copilot, Microsoft Copilot and agents, and a Risky Agents template covering agents hosted on Copilot Studio and Microsoft Foundry. Those are insider risk policies, not communication compliance ones, and the Risky AI usage template requires a browser extension deployed to user devices.
So the accurate sentence is narrow: this licence does not grant Copilot prompt and response analysis inside Communication Compliance. It does not follow that Copilot activity is invisible to insider risk.
The licence alone produces nothing
Insider Risk Management scores signals it is given, and Microsoft publishes a prerequisite table per policy template. Most templates carry one, and the detail matters more than a general warning.
- Data theft by departing users triggers on a resignation or termination indicator from an HR connector or on Microsoft Entra account deletion. Microsoft marks the HR connector as optional here and documents the account deletion trigger as the alternative.
- Data leaks needs a data loss prevention policy configured for High severity alerts on Exchange Online, SharePoint Online or OneDrive workloads only, or customised triggering indicators. Microsoft notes that alerts generated exclusively from Endpoint, Teams or Microsoft 365 Copilot data loss prevention are not currently evaluated by the DLP alert indicator.
- Data leaks by risky users and Security policy violations by risky users need an HR connector configured for disgruntlement indicators, or Communication Compliance integration with a dedicated policy, or both.
- Security policy violations needs an active Microsoft Defender for Endpoint subscription as well as the integration configured. For a tenant without Defender for Endpoint that is a second purchase.
The metered part of the bill
Microsoft states that some indicators included in Insider Risk Management are only available when the pay as you go billing model is enabled for the organisation. The per user licence does not cover everything the product can ingest, so an estimate built from seat count alone will be short.
One availability check
Microsoft states that Insider Risk Management is offered in tenants hosted in countries and regions supported by the underlying Azure service dependencies, and publishes a dependency availability list. Confirm the tenant region before ordering.
Does it cover Microsoft 365 Copilot prompts?
Not inside Communication Compliance. Microsoft records Copilot prompt and response analysis there as not included under this add-on, and records it for Microsoft 365 E5 with Copilot and for the Purview Suite with Copilot. Insider Risk Management separately documents a Risky AI usage template that detects prompts and responses containing sensitive information, which needs a browser extension on user devices.
Is the licence enough to start detecting insider risk?
Usually not. Microsoft publishes a prerequisite per policy template. Data leaks needs a High severity data loss prevention policy or customised indicators. Security policy violations needs an active Microsoft Defender for Endpoint subscription and its integration. Data theft by departing users is the lightest: the HR connector is marked optional, with Microsoft Entra account deletion as the alternative trigger.
Is the per user licence the whole cost?
No. Microsoft states that some indicators included in Insider Risk Management are only available when the pay as you go billing model is enabled for the organisation. Budget for metered indicator usage alongside the seats.
What else comes with it?
Microsoft lists this add-on as a qualifying licence for Communication Compliance, Customer Lockbox and Purview Data Connectors as well as Insider Risk Management itself.
Does it grant information barriers?
The current Microsoft Purview service description carries no licensing table for Information Barriers, so we do not state that this add-on grants them. Confirm with Microsoft before relying on it.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- 1-Year, Monthly
- Unit price
- €4.90 /mo
- SKU
- MST-NCE-109-C100
Term or edition paths Microsoft allows this subscription to move to.
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta). VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant, with no third-party MSP markup.
- 3You keep the tenant. Sovereign by default: every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.