Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a new incident profile for Microsoft DLP integration

Create an incident profile in your  ServiceNow AI Platform instance to retrieve the data from the Microsoft Purview and add the data into the ServiceNow DLP IR incident table.

Before you begin

Role required: sn_dlir.admin(Create, edit, and delete)

sn_dlir.analyst - View (read-only)

About this task

Configure the ServiceNow AI Platform® to retrieve the events from the Microsoft Purview. Store these events on the DLP IR Incident table on your ServiceNow® instance.

Procedure

  1. Navigate to Microsoft DLP integration > Incident Profile.

  2. Click New.

  3. On the form, fill the fields in the Name section.

FieldDescription
NameName of the profile. This field helps you to identify the profile.Note: The name must be unique for each profile.
SourceThe Microsoft DLP IR instance that you configured to ingest incidents. If you have multiple integration configurations, select the appropriate integration configuration record for the incident types that you are planning to ingest for the profile.
ActiveOption to indicate if the profile is active. This field can only be enabled after you click the Finish field in the Scheduling section.When the profile is active, it implies that the  ServiceNow AI Platform is actively polling Microsoft DLP IR events based on the configuration defined in the profile.
OrderOrder of the profile execution. The profile with the lowest order considered as the highest priority.By default, the value is 100.
DescriptionUnique description for the profile.

What to do next

To move to the Filtering section,  click Continue.

  • Microsoft purview endpoint storage configuration
    Microsoft Purview endpoint evidence files storage configuration tells you where the endpoint evidence files are being stored by the purview- Custom managed store or Microsoft managed storage environments.
  • Define filters to apply for the Incident creation
    Define and set filter conditions to filter the incoming  Microsoft DLP  events. Control which of these events should be created as DLP IR incidents on your ServiceNow instance.
  • Configure the match content for the incident
    Provide the configuration to store the sensitive information internally, on the ServiceNow® storage, or on the external cloud storage, such as Azure Storage or AWS S3 bucket. Retrieve the stored content while accessing the DLP IR Incident.
  • Schedule the DLP IR Microsoft incident retrieval
    Set a schedule to retrieve the incident data and ingest Microsoft DLP IR incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Microsoft.

Parent Topic:Data Loss Prevention Incident Response with Microsoft