You are designing an IRM deployment for a multinational organization with employees in Germany, where works council agreements require that no employee's activity be viewable by analysts outside Germany. You configure Administrative Unit scoping for the German analyst team. What additional step is critical to ensure the privacy boundary actually holds?
Correct answer: C. Confirm that each analyst in the scoped German role group does NOT also hold a broader Microsoft Entra role (such as Global Reader or Compliance Administrator), and validate effective access using a test account before treating the AU scope as the privacy boundary.
Microsoft Learn's permissions documentation confirms that members of Microsoft Entra ID Global Administrator, Compliance Administrator, Purview Organization Management, and Purview Compliance Administrator have the same permissions as IRM Admins and can see all data regardless of AU scoping. When a user holds a broader Entra or Purview role alongside a scoped AU role group assignment, the broader role takes precedence and bypasses the AU scope. The validation step (testing with a clean account that holds only the scoped assignment) is critical before relying on AU scoping as an enforceable privacy boundary.
Why the other options are wrong:
- A. The Investigator role does not override AU scoping. The override mechanism is broader Microsoft Entra roles (Global Reader, Compliance Administrator), not IRM-specific roles like Investigators.
- B. Pseudonymization is a tenant-wide switch; Learn confirms it applies to 'all users with current and past policy matches.' No per-user or per-group scoping of the setting is documented, so it cannot be enabled for German users only.
- D. Policy scoping and analyst visibility are separate concerns. An IRM policy scoped to German users determines whose activity gets scored. It does not prevent an analyst with tenant-wide role access from viewing all users' alerts. Analyst visibility is governed by role group and AU scoping, not policy user-scope configuration.
Memory hook: AU scoping only holds if no broader Entra role exists on the same user. Validate with a clean test account before telling the works council it's enforced.
Microsoft Learn: Insider risk management permissions





