---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# DLP default configuration settings

# DLP default configuration settings {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Define the default configuration settings for Data Loss Prevention Incident Response (DLP IR) incidents to identify and set up the incident notification and incident assignment preferences for your end users.

## Before you begin

Role required:

* sn_dlir.admin - Create, edit, and delete.
* sn_dlir.analyst and sn_dlir.analyst_read - View (read-only).
{#configure-data-loss-prevention__ul_i4v_zgh_h5b}

## About this task

You can use this module to define the default configuration settings when the core assignment rules and identifier rules are exhausted and unable to match to a condition or user. You can also define and reapply End user lookup
rules and Assignment rules to existing Active DLP incidents.

The end user incident notification enables you to specify the frequency at which email notifications are sent to your end users. For example, you can set up notification preferences to accumulate incidents and to send an email
digest once a week. By assigning an incident, you can specify which group you initially assign the DLP incidents to. You can also specify how the end users are further identified by the DLP operations team.

For example, let's say that a user has stored credit card information in a file on a
network. When the third-party DLP integration product creates an incident for a
sensitive data policy violation, the incident data that the ServiceNow AI Platform
DLP ingests would contain information about the end user. You would then be able to
assign the incident to the right end user.

## Procedure

1. Navigate to AllDLP AdministrationDefault Configuration.
2. On the form, fill in the fields.  
   {#configure-data-loss-prevention__table_rxk_lqg_zrb__entry__3}

   | Configuration Name | Field | Description |
   |-|-|-|
   | End User Incident Notification | Notification Period (days) | Define the number of days after which an email notification should be sent to the end user. The number of days must be between 1--60 days. |
   | End User Incident Notification | Automatically update parent state based on cloned/child incidents | Option to automatically update the parent state incident based on the cloned or child incidents. |
   | Incident Assignment | End User Identifier | Specify the field to be used from Incident data to identify the end user. Possibles values are the following: * Data owner email * Destination * File created by * File modified by * File owner * FTP user name * Sender {#configure-data-loss-prevention__ul_gk2_crv_1xb} |
   | Reapply End User Lookup Rules Behavior | When reapply option is chosen for end user lookup rules | Option to reapply End user lookup rules to existing Active DLP incidents. You can select one of the following option to reapply: * Update the End user value when the field is empty: Updates the existing active DLP incidents' End user value if that field is empty. * Update the End user value: Updates the existing active DLP incidents' End user value. * Update the End user and Assigned to values when both fields are empty: Updates the existing active DLP incidents' End user and Assigned to values if both fields are empty. Note: If this option is selected, then the Update the Assigned to value when the field is empty option gets disabled automatically in the Reapply Assignment Rules Behavior section as it's applicable for both. * Update the End user and Assigned to values for all the active DLP incidents: Updates the End user and Assigned to values for all active DLP incidents. Note: If this option is selected, then the Update the Assigned to value for all the active DLP incidents option gets disabled automatically in the Reapply Assignment Rules Behavior section as it's applicable for both. {#configure-data-loss-prevention__ul_zzn_s3w_1xb} |
   | Reapply Assignment Rules Behavior | When reapply option is chosen for assignment rules | Option to reapply assignment rules to existing Active DLP incidents. You can select one of the following option to reapply: * Update the Assigned to value when the field is empty. * Update the Assigned to value for all the active DLP incidents. {#configure-data-loss-prevention__ul_odd_z3w_1xb} |
   [Table 1. DLP Default Configuration form]

   {#configure-data-loss-prevention__table_rxk_lqg_zrb}
3. Select the Default Assignment Group from the related list section where all the DLP incidents are assigned to.  
   Click Edit to add the user group. When you click Edit from the related list section and select an item from the Collections columns and then add that selected assignee to the Group columns in the Edit Members page, and save the list.  
   Note:  
   You can only view and select groups that have been assigned with the sn_dlir.analyst role from the related list. You can only select one group.
4. Click Save.
**Related concepts**   

* [Monitor DLP Integration Run process](https://servicenow-prod.fluidtopics.net/1Ov8JAQizZC7T2HLNPiOvg "Track and monitor the ongoing ingestion or the integration run process. The integration run processes contains the statistics on how much the data was processed and the integration status.")
* [DLP Incident Access Restrictions](https://servicenow-prod.fluidtopics.net/RLjeozrMpG2FVpJaLmRMuQ "Manage the visibility of a particular DLP incident that contains sensitive information. You can use incident access restrictions to define who can access a particular DLP incident and restrict specific users or groups from accessing that incident.")  
**Related tasks**   

* [Create end user lookup rules](https://servicenow-prod.fluidtopics.net/ccMfdPxSgHsL9Fh1Q_~JsA "You can create and configure end user lookup rules and assign the DLP incidents to the respective end users based on those rules.")
* [Create assignment rules](https://servicenow-prod.fluidtopics.net/8vAoEijgHvURfLHuuPSmqQ "Create assignment rules and assign the Data Loss Prevention Incident Response (DLP IR) incidents to user groups, end users, managers, or user from incident.")
* [Create incident consolidation rules](https://servicenow-prod.fluidtopics.net/vvKTITK9qLCsbKKkoqVL5A "Create incident consolidation rule to consolidate multiple incidents of similar nature under one parent incident.")
* [Create response due date rules](https://servicenow-prod.fluidtopics.net/VgO2TB6WZtrxmG4~JWv2vA "Set up the response due date rules to determine the time you want to give your end users to respond to the assigned Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create Approval Rules](https://servicenow-prod.fluidtopics.net/y~1XZvQsmLOqBjkfbVKDbw "Configure approval rules that require one or more approvers to authorize an advanced response option before it is applied to a DLP incident.")
* [Create user instructions templates](https://servicenow-prod.fluidtopics.net/CAThP9D~817jopKRDJeJPg "Create and manage user instructions template for DLP incidents to help the users understand the instructions involved incident resolution and the next steps involved in the resolution process.")
* [Create email templates](https://servicenow-prod.fluidtopics.net/wQtZqtIiLEBZdQR8aYbIiA "Create and manage the preconfigured email templates for sending notifications to your end users, user groups, or managers. With these templates, you can coach and communicate with your end users about the Data Loss Prevention Incident Response (DLP IR) incidents.")
* [Create a Data Loss Prevention Incident Response SLA trigger](https://servicenow-prod.fluidtopics.net/n4qzNvzCeD6gk9FwYIJ9Vw "Create a Data Loss Prevention Incident Response SLA trigger condition that enables a prompt and efficient response to an incident when triggered.")
* [Create a Data Loss Prevention Incident Response SLA definition](https://servicenow-prod.fluidtopics.net/80miwPm0oR7Ix7EQ~DpIew "Create a Data Loss Prevention Incident Response SLA definition that outlines the conditions and duration for responding to data breaches. Establishing clear expectations and protocols helps ensure a swift response to incidents, minimizing potential damage and enhancing overall data protection strategies.")
* [Create assessments](https://servicenow-prod.fluidtopics.net/XzB5FSKtotEb1LiHYADPog "Create and manage assessments to enable end users to respond to DLP incidents. You can use the assessments to gather information about the sensitive data exposed or leaked from the DLP incidents.")
* [Configure response option for your DLP incidents](https://servicenow-prod.fluidtopics.net/1QqdESchbNTpm8Sp8oXHyQ "Use this feature to configure the type of response that an end user or analyst should perform.")
* [Create incident response option rules](https://servicenow-prod.fluidtopics.net/RLu4r6VrzMF9Vaxug9KjQg "Create the incident response option rules that end user or analyst can use while responding to an incident.")
* [Create age chart configurations](https://servicenow-prod.fluidtopics.net/iocRbBQN3eOFUtEHfseXng "Configure the age chart that appears in the Data Loss Prevention Incident Response (DLP IR) Ops portal. This chart shows the count of open incidents by the number of days.")
* [Create user delegate configurations](https://servicenow-prod.fluidtopics.net/taEwNu9D1oCTDUG~7YRq4w "Prevent certain executives in the organization from receiving notifications about the incidents assigned or escalated to them.")
* [Create repeat offender identification rules](https://servicenow-prod.fluidtopics.net/ya7_7zLs~83PA_eUuYF80w "Create repeat offender identification rules to identify users who repeat the same issue multiple times.")
* [Create additional incident data fields](https://servicenow-prod.fluidtopics.net/CmlVgnvum6xrhlmBr5xSOA "Create Additional Incident Data Fields for the DLP incidents. You can create different types of fields such as string, number, check box, choice, date and time, and use them in the DLP incident forms.")
* [Configure advanced settings](https://servicenow-prod.fluidtopics.net/wwOHIHO~QiPeMQlpBVMNrw "Configure the advanced settings to customize the incident display and behavior. For example, enable displaying the sensitive data on an incident and its clone, or specifying fields on the incident to identify the end users. In addition, activate and customize the evidence files preview properties.")
* [DLP Incidents Archival](https://servicenow-prod.fluidtopics.net/1Y6pdckWs2tO8~g24W_scg "The Data Loss Prevention Incident Response is provisioned with one archival rule in the base system for the DLP incident table. The related records are also added in the base system to the DLP incident archive rule.")  
**Related reference**   

* [DLP SLA Definition form](https://servicenow-prod.fluidtopics.net/Z4MZ3Z00jp3m79J8c5joqQ "Field descriptions for the DLP SLA Definition form used to create an SLA record.")

*[\>]: and then


