---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure the match content for the incident

# Configure the match content for the incident {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Provide the configuration to store the sensitive information internally, on the ServiceNow® storage, or on the external cloud storage, such as Azure Storage or AWS S3 bucket. Retrieve the stored content while accessing the DLP IR Incident.

## Before you begin

Role required:

* sn_dlir.admin
* sn_dlir.analyst
{#matching-content-configuration-microsoft__ul_rb5_gnk_13c}

## Procedure

1. On the progress bar, click the Match Content Configuration step.
2. On the form, fill in the fields.  
   {#matching-content-configuration-microsoft__table_ott_mkl_nwb__entry__2}

   | Field | Description |
   |-|-|
   | Store Match Content | Option to store the matched content. Important: Enable this option to store the match content, and retrieve and display the match content when a DLP incident is opened in the workspace. For information on the External Cloud Storage configuration, see [Install and configure the Microsoft DLP integration](https://servicenow-prod.fluidtopics.net/xkPla2nJ51jLV91WZo0wNw "Install and configure the  DLP Incident Response integration with Microsoft DLP from the  ServiceNow Store on your  ServiceNow AI Platform instance. Start investigating DLP incidents using the  Microsoft DLP event data."). |
   | Storage Source for Match content | Option to choose whether to store the matched content internally, on the ServiceNow® storage, or externally, on the cloud storage. |
   | External Cloud Credentials | The External Cloud Storage where the match content gets stored. You can refer to the External Cloud Credentials added for the Storage configuration. This option is visible only when the Store Match Content field is selected. |
   | Delete Match Content on Incident Deletion | Option to delete the incident match content from the external cloud storage. This option is visible only when the Store Match Content field is selected. |
   [Table 1. Match Content Configuration]

   {#matching-content-configuration-microsoft__table_ott_mkl_nwb}
3. Click Continue and move to the Scheduling section.

