Hello, I’m Nora, your AI guide from Technology Last Stop. This guide covers Proofpoint TAP incidents and tickets. Poll Proofpoint TAP SIEM threat email and malicious-link findings with a company-specific service principal. Current availability: Implemented; provider credentials and acceptance required. Before you start. Company administrator or TLS owner; a dedicated provider application for this company. A separate test tenant or approved test records and company responders who can verify results. Proofpoint TAP SIEM entitlement and generated service principal/secret. Step 1. Open Companies > company > Security > Proofpoint TAP > Configure connection and routing. Step 2. Enter the TAP service principal and secret in protected fields. Select minimum severity and Automatically create incident tickets. Step 3. For email, first configure the company notification mailbox using the Security notifications guide; enter responder addresses and enable email routing. Step 4. Save, then Verify read access. Verification reads a recent provider window without creating tickets or sending email. Correct credentials, permissions or entitlement errors before enabling. Step 5. Choose Enable sync. The existing five-minute maintenance handler polls enabled connections using bounded time windows and overlap for recovery; each provider event ID is deduplicated. Step 6. Use Sync now to test an approved finding. Inspect Security events and the linked ticket. Acknowledge or resolve the security event with notes; complete the ticket separately. Now verify the result. A known provider finding creates exactly one company security event and one linked ticket when its severity qualifies. Repeat the same event and verify there is no duplicate ticket or responder notification. Pause the connection, verify no further polling, and check wrong-company API access is denied. If you get stuck. 401/403: check TAP principal/secret and licensed API access. A successful empty read verifies access, not incident delivery; use an approved known finding before acceptance. Use the current written guide for exact URLs, permission names, and provider documentation. Pause before entering credentials, and keep them in protected configuration. I’m Nora, your TLS guide.