What and why
We are retiring Data Risk Graph in Microsoft Purview Insider Risk Management (IRM).
Data Risk Graph provides a visual investigation experience that helps investigators review connections among impacted data, users, and alert-related activities. As part of ongoing investments in Insider Risk Management investigation experiences, we are retiring this capability and directing customers to alternative investigation tools that provide detailed activity timelines and investigative context.
After retirement, investigators can continue reviewing potentially risky activity by using Activity explorer, Content explorer, and User activity experiences within Microsoft Purview Insider Risk Management.
Rollout schedule
For Worldwide, GCC, GCC High, DoD:
- The ability to configure Data Risk Graph was removed in early September 2026
- New onboarding for Data Risk Graph ends September 24, 2026
- Data Risk Graph retirement begins in early December 2026 and is expected to be fully retired by December 8, 2026
Impact on your organization
Who is affected
- Microsoft Purview Insider Risk Management administrators
- Insider Risk Management investigators
- Organizations currently using the Data Risk Graph experience
Platforms and services
- Microsoft Purview Insider Risk Management
- Web
What will happen
After retirement:
- The Data Risk Graph tab will no longer be available in Insider Risk Management alert details.
- Organizations will no longer be able to configure or begin using Data Risk Graph.
- Existing Insider Risk Management policies, alerts, cases, reports, and investigation workflows will remain available.
- Customers can continue to investigate potentially risky activity using Activity explorer, Content explorer, and User activity experiences.
- No changes will be made to existing Insider Risk Management policy configurations as a result of this retirement.
- No user action is required for feature disablement. The feature will be removed by Microsoft as part of the retirement process.
Action required and recommendations
Action is recommended if your organization currently uses Data Risk Graph.
- Notify Insider Risk Management administrators and investigators about this retirement.
- Review current investigation workflows that rely on the Data Risk Graph tab.
- Update internal documentation, training materials, and standard operating procedures that reference Data Risk Graph.
- Transition investigators to Activity explorer, Content explorer, and User activity experiences for investigation scenarios.
Learn more
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.