logo

NJP

DLP Incident Response integration with Microsoft

DLP Incident Response integration with Microsoft

by Service-now.com

Integration with Microsoft (DLP) to automate DLP incident response workflow.

0 installs 0 reviews v1.5.3 Scoped Application Free (integration tables[7] not counted) 7 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 18 -18
174 days of no change
2025-11-03 17 +1
2 days of no change
2025-10-31 16 +1
39 days of no change
2025-09-21 15 +1
97 days of no change
2025-06-15 14 +1
32 days of no change
2025-05-13 13 +1
50 days of no change
2025-03-23 12 +1
64 days of no change
2025-01-17 11 +1
78 days of no change
2024-10-30 8 +3

About

Provides out-of-the-box integration to import DLP incidents from Microsoft Purview (OneDrive, SharePoint, Teams, Exchange Online) and other event types as well. This app can be used in combination with Data Loss Prevention Incident Response app to automate DLP incident remediation workflow for incidents generated by Microsoft Purview. This app also provides the ability to automatically release emails quarantined by Microsoft Purview post an approval workflow.

Key Features

- Import DLP incidents created for OneDrive, SharePoint, Exchange Online, and Teams.
- Ability for DLP analysts to view matched sensitive data types, confidence score, match count, and the text snippet that violated the policy (matched text snippets are not stored in ServiceNow).
- Ability for DLP analysts to download the evidence file/email.
- Added correlation ID within the DLP incident table to map the integration ID to the DLP incidents.

Version History (14)
v1.5.3 2026-07-09 17:40:51
Fixed: Added the PowerShell dependency required to enable the Release Quarantine Email flow.
v1.5.2 2026-06-16 17:11:16
Fixed: The read_only_options attribute has been moved from IF folder–based plugin configuration to dictionary attributes on the table fields.
v1.5.1 2026-05-05 15:06:14
Fixed: Access issues for security analysts while querying tables. UI issue in the profile for displaying endpoint evidence file storage type. Fie...
v1.5.0 2026-02-06 01:27:14
New: Support internal storage of Match content in Microsoft Purview Integration. Fixed: Prevent permanent data loss by adding support to re-proc...
v1.3.1 2026-01-20 15:05:26
Fixed: Removed redundant ACLs from the Match Content field in the Detected Sensitive Info table.
v1.2.0 2025-12-11 15:47:57
New Upgraded dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes. This update ensures the ...
v1.1.21 2025-10-16 15:12:08
Fixed :  Release from quarantine feature not functioning when configured with a target state.  Added support for Microsoft DLP integrati...
v1.1.10 2025-07-31 15:43:34
Fixed :  Release Email from Quarantine Failure for DLP Exchange Online.
v1.1.2 2025-07-10 15:11:07
Fixed: Microsoft DLP Quarantine Release Error Handling: Resolved an issue where attempting to Release Email from Quarantine for incidents that we...
v1.1.1 2025-06-06 01:53:13
Fixed : Generation of unnecessary error logs on clicking the Sensitive Information tab in the Workspace. Bug where multiple Sensitive Information ...

+ 4 more versions

ID: eaf471689f9d1110d1f7e1ac98a9c8fc · Published: Jul 2026 · Updated: Sep 09, 2026