---
sourceDocument: Zurich Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/security-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Data Loss Prevention Incident Response with Microsoft

# Data Loss Prevention Incident Response with Microsoft {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources, such as Microsoft Purview apps, Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business, and other event types.

## Request apps on the Store {#dlp-integration-microsoft__section_qdr_5nw_v4b}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#dlp-integration-microsoft__inline-send-to-store}

## Overview and key features {#dlp-integration-microsoft__section_trt_1cl_gwb}

The Data Loss Prevention Incident Response integration with Microsoft enables organizations to gain a unified view of incidents across email, network, endpoint, and cloud sources. Endpoint devices enable remediation workflow involving end users, managers, and  DLP 
operations team with automated incident assignment and escalations.  
Use the key features of this integration to do the following actions:

* Create multiple profiles for different accounts.
* Automate the creation of DLP IR incidents.
* Map the Microsoft DLP IR event fields to DLP IR incident fields.
* Filter Microsoft DLP IR events.
* Schedule the ingestion of DLP IR events that create DLP IR incidents periodically.
* Store the matching content of each Microsoft DLP event in external cloud storage.
* Delete matching content at external cloud storage on the deletion of the DLP IR incident in ServiceNow.
* Download files for DLP IR incidents of type Exchange, OneDrive, and SharePoint.
{#dlp-integration-microsoft__ul_m1g_pcl_gwb}

## Learn about this integration {#dlp-integration-microsoft__section_bsv_lws_qpb}

{#dlp-integration-microsoft__section_bsv_lws_qpb__entry__2}

| Document identifier | Document title |
|-|-|
| Microsoft product documentation website | [Microsoft Product Documentation website](https://learn.microsoft.com/en-us/microsoft-365/compliance/dlp-learn-about-dlp) |
| ServiceNow product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

* **[Getting started with Microsoft DLP IR integration for data loss prevention](https://www.servicenow.com/docs/Ycb27ZV8KO1uzD3xY5nLSQ)**   
  Review the following information before you start setting up your Microsoft DLP IR integration for data loss prevention.
* **[Install and configure the Microsoft DLP integration](https://www.servicenow.com/docs/6TkvlrS7BuM~L6Xt12WoTw)**   
  Install and configure the  DLP Incident Response integration with Microsoft DLP from the  ServiceNow® Store on your  ServiceNow AI Platform instance. Start investigating DLP incidents using the  Microsoft DLP event data.
* **[Create a new incident profile for Microsoft DLP integration](https://www.servicenow.com/docs/GX_7G_~ix0uhSguOAIqdDw)**   
  Create an incident profile in your  ServiceNow AI Platform instance to retrieve the data from the Microsoft Purview and add the data into the ServiceNow DLP IR incident table.
* **[Configure Microsoft DLP IR integration settings](https://www.servicenow.com/docs/W4k9T6zBpoGdatxOSYcJqA)**   
  Modify the  Microsoft DLP IR  integration default system properties.
* **[Request release email from quarantine](https://www.servicenow.com/docs/8VPiW10ywoJ5rOPG9KO2gg)**   
  Use this feature to release the email that is quarantined from the Microsoft Purview compliance portal.
* **[Download files for DLP incidents of type Exchange Online, OneDrive, and SharePoint](https://www.servicenow.com/docs/74A~jaLtmGF4jtGKARujRg)**   
  Download files or email that violates the DLP policy on Microsoft Purview. Download this file or email on to your local machine from the DLP IR Incident view. You can download the files for DLP IR incidents of type Scan source Exchange Online, OneDrive, and SharePoint.
* **[Preview Evidence files for DLP incidents of type Exchange Online, OneDrive, and SharePoint](https://www.servicenow.com/docs/VIm6uAoJa4P4cPu8vgDZhg)**   
  Preview Data Loss Prevention Incident Response evidence files in the DLP IR Analyst workspace.
* **[Domain separation in Microsoft DLP integration](https://www.servicenow.com/docs/pd79tkrC0oJPZL2oG3fPzA)**   
  Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

**Related concepts**   

* [Symantec Integration for Data Loss Prevention Incident Response](https://www.servicenow.com/docs/aObXXiVM1lQvXJKsNS8QJA "The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.")
* [Data Loss Prevention Incident Response Integration with Proofpoint](https://www.servicenow.com/docs/vKXSmLnH_RNWq6t6uULo2A "The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.")
* [Data Loss Prevention Incident Response Integration with Netskope](https://www.servicenow.com/docs/Z5Vk6yw5Q0F59RQGs1oRxg "The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.")
* [Internet Content Adaption Protocol (ICAP) integration for DLP IR](https://www.servicenow.com/docs/ByR7~8HlyuGKCs8~4oxOZw "The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.")

