---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Data Loss Prevention Incident Response Integration with Proofpoint

# Data Loss Prevention Incident Response Integration with Proofpoint {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Proofpoint DLP integration supports the ingestion of Data Loss
Prevention incidents created on the Proofpoint Data Loss Prevention deployment.
After ingestion, you can use the incident management functionalities to remediate the DLP
incidents.

## Request apps on the Store {#dlp-incident-response-integration-proofpoint__section_vhj_kxv_3tb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release
notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#dlp-incident-response-integration-proofpoint__inline-send-to-store}

## Overview and key features {#dlp-incident-response-integration-proofpoint__section_p5g_5xv_3tb}

The Proofpoint DLP integration helps companies to track the usage and movement
of sensitive data on various platforms.  
This integration includes the following key features:

* Multiple profile creation for different Proofpoint endpoints.
* Automating the creation of DLP incidents.
* Mapping of the Proofpoint DLP incident state field to DLP incident state field.
* Filtering of Proofpoint DLP incidents.
* Ingestion of incidents in your ServiceNow instance as soon as the incidents are created on Proofpoint DLP tenant.
* Proofpoint DLP integration supports both endpoints and email type of incidents.
* Automatic updates for the Proofpoint DLP incident status and comments for DLP incident creation, and for state change and closure on ServiceNow side.
{#dlp-incident-response-integration-proofpoint__ul_rtg_5p2_ntb}

## Learn about this integration {#dlp-incident-response-integration-proofpoint__section_ykh_1yv_3tb}

{#dlp-incident-response-integration-proofpoint__table_ggn_x4y_ymb__entry__2}

| Document identifier | Document title |
|-|-|
| Proofpoint product documentation website | [Proofpoint product documentation](https://help.proofpoint.com/) |
| ServiceNow® product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

{#dlp-incident-response-integration-proofpoint__table_ggn_x4y_ymb}
* **[Getting started with Proofpoint integration for Data Loss Prevention](https://servicenow-prod.fluidtopics.net/aH9LVxbcIHhvS6N92DTOdw)**   
  The Proofpoint DLP integration supports the ingestion of Data Loss Prevention incidents created on the Proofpoint Data Loss Prevention tenant. After ingestion, the incident management functionalities that remediate the DLP incidents will be used.
* **[Install and configure the Proofpoint integration for Data Loss Prevention](https://servicenow-prod.fluidtopics.net/RY5tPTrE_gCRNTypCIPWWw)**   
  Install and configure the  Proofpoint DLP integration from the  ServiceNow® Store on your  ServiceNow AI Platform instance. Start investigating DLP incidents using the  Proofpoint DLP incident data.
* **[Create an Application in Proofpoint and Obtain Client Credentials](https://servicenow-prod.fluidtopics.net/ReXdFFj6jcJzvBdUsVpwOQ)**   
  Create an Application in Proofpoint and configure the required settings to obtain client credentials. These credentials enable secure access to Proofpoint's API for seamless integration and automation.
* **[Create a Profile for Proofpoint DLP integration](https://servicenow-prod.fluidtopics.net/o92rY8DC5uF5J79w7XET8Q)**   
  Create an incident profile in your  ServiceNow AI Platform instance. Determine the  Proofpoint DLP incidents that are suitable for creating DLP incidents.
* **[Map Proofpoint DLP incidents status with ServiceNow incident status](https://servicenow-prod.fluidtopics.net/8cd2DwQWqzQ7Q8RVXUvOuQ)**   
  Synchronize the status of the DLP incidents ingested on your ServiceNow instance and DLP incidents of the Proofpoint. Map the ServiceNow Incident status with the Proofpoint Incident status.
* **[Configure Proofpoint DLP integration settings](https://servicenow-prod.fluidtopics.net/S3tZVSWLyqenHheHNw7qww)**   
  Modify the  Proofpoint DLP  integration default system properties.
* **[Domain Separation in Proofpoint DLP integration](https://servicenow-prod.fluidtopics.net/6aVoBEVpXUWe4qfbNJmu3Q)**   
  Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can then control several aspects of this separation, including which users can see and access data.

**Related concepts**   

* [Symantec Integration for Data Loss Prevention Incident Response](https://servicenow-prod.fluidtopics.net/F2AvvNAwqBtWdrL72MFvWQ "The Symantec DLP integration supports the ingestion of Data Loss Prevention Incident Response incidents created on the Symantec Data Loss Prevention Incident Response deployment. After ingestion, you can use the incident management functionalities to remediate the DLP incidents.")
* [Data Loss Prevention Incident Response Integration with Netskope](https://servicenow-prod.fluidtopics.net/X0VZV3Zk0gDqNvuc2nm6FA "The Netskope DLP integration supports the ingestion of Data Loss Prevention incidents created on the Netskope Data Loss Prevention deployment. Netskope DLP helps companies to track the usage and movement of sensitive data on various platforms.")
* [Internet Content Adaption Protocol (ICAP) integration for DLP IR](https://servicenow-prod.fluidtopics.net/lZ4ZwkNgZ22tGC1XWaJGlQ "The Internet Content Adaption Protocol (ICAP) DLP integration supports the ingestion of Data Loss Prevention Incident Response alerts, allows the fetching of match content, and evidence files from Amazon S3 created on the ICAP supported Data Loss Prevention Incident Response deployment.")
* [Data Loss Prevention Incident Response with Microsoft](https://servicenow-prod.fluidtopics.net/MGNPNajD4H9ReQz~6_j1LQ "The Data Loss Prevention Incident Response with Microsoft provides a core framework to import Data Loss Prevention (DLP) incidents from multiple sources, such as Microsoft Purview apps, Microsoft Teams, Exchange Online, SharePoint Online, OneDrive for Business, and other event types.")

