---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Create a new incident profile for Microsoft DLP integration

# Create a new incident profile for Microsoft DLP integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an incident profile in your  ServiceNow AI Platform instance to retrieve the data from the Microsoft Purview and add the data into the ServiceNow
DLP IR incident table.

## Before you begin

Role required: sn_dlir.admin(Create, edit, and delete)

sn_dlir.analyst - View (read-only)

## About this task

Configure the ServiceNow AI Platform® to retrieve the events from the Microsoft Purview. Store these events on the DLP IR Incident table on your ServiceNow® instance.

## Procedure

1. Navigate to Microsoft DLP integrationIncident Profile.
2. Click New.
3. On the form, fill the fields in the Name section.  
   {#create-profile-microsoft-dlp-integration__table_dq5_sbz_2tb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the profile. This field helps you to identify the profile. Note: The name must be unique for each profile. |
   | Source | The Microsoft DLP IR instance that you configured to ingest incidents. If you have multiple integration configurations, select the appropriate integration configuration record for the incident types that you are planning to ingest for the profile. |
   | Active | Option to indicate if the profile is active. This field can only be enabled after you click the Finish field in the Scheduling section. When the profile is active, it implies that the  ServiceNow AI Platform is actively polling Microsoft DLP IR events based on the configuration defined in the profile. |
   | Order | Order of the profile execution. The profile with the lowest order considered as the highest priority. By default, the value is 100. |
   | Description | Unique description for the profile. |
   [Table 1. Create a profile form]

   {#create-profile-microsoft-dlp-integration__table_dq5_sbz_2tb}
{#create-profile-microsoft-dlp-integration__steps_vs4_mjf_jtb}

## What to do next

To move to the Filtering section,  click Continue.
* **[Microsoft purview endpoint storage configuration](https://servicenow-prod.fluidtopics.net/KmJ7XyVyiFGId9nkVn~MLg)**   
  Microsoft Purview endpoint evidence files storage configuration tells you where the endpoint evidence files are being stored by the purview- Custom managed store or Microsoft managed storage environments.
* **[Define filters to apply for the Incident creation](https://servicenow-prod.fluidtopics.net/sdDrznqZVhA7QKBQ227UsA)**   
  Define and set filter conditions to filter the incoming  Microsoft DLP  events. Control which of these events should be created as DLP IR incidents on your ServiceNow instance.
* **[Configure the match content for the incident](https://servicenow-prod.fluidtopics.net/L3QUTVqkNsJgsqcGa7WpXg)**   
  Provide the configuration to store the sensitive information internally, on the ServiceNow® storage, or on the external cloud storage, such as Azure Storage or AWS S3 bucket. Retrieve the stored content while accessing the DLP IR Incident.
* **[Schedule the DLP IR Microsoft incident retrieval](https://servicenow-prod.fluidtopics.net/qz5vBvmrrv_VHQ832Aky1g)**   
  Set a schedule to retrieve the incident data and ingest Microsoft DLP IR incidents that match the criteria in the profile. Configure the schedule to define how and when you pull incidents from Microsoft.

*[\>]: and then


