logo

NJP

Microsoft Exchange Online for Security Operations

Microsoft Exchange Online for Security Operations

by Service-now.com

Search and delete phishing email threats.

0 installs 0 reviews v10.7.4 Scoped Application Free (integration tables[3] not counted) 3 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 88 -88
19 days of no change
2026-04-07 89 -1
12 days of no change
2026-03-25 90 -1
130 days of no change
2025-11-14 89 +1
2025-11-13 88 +1
15 days of no change
2025-10-28 87 +1
47 days of no change
2025-09-10 86 +1
40 days of no change
2025-07-31 85 +1
117 days of no change
2025-04-04 84 +1
22 days of no change
2025-03-12 83 +1
6 days of no change
2025-03-05 82 +1
8 days of no change
2025-02-24 81 +1
52 days of no change
2025-01-02 80 +1
63 days of no change
2024-10-30 78 +2

About

Integrating ServiceNow® Security Incident Response with the Microsoft Exchange Online service, part of the Microsoft Office 365 suite of products, provides a security operations center (SOC) analyst with an email search and delete capability. With this integration, your SOC analyst can search your corporate email environment for security-related threats and remove phishing emails.

Key Features

The integration includes the following key features: 

- Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
- For large and lengthy email searches, the security incident analyst is notified via email when a search is successfully completed, along with the number of matched messages. 
- Status for individual messages informs you if recipients have read or deleted suspicious emails.
- If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
- A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents. 
- If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents. 

Version History (7)
v10.7.4 2026-06-16 16:43:20
Fixed: Email search by subject line keywords returned no results because the Hunting API query used exact match (==) instead of keyword match (has)...
v10.7.3 2026-03-12 16:12:11
Fixed : Comments entered while rejecting email requests are now correctly reflected in the associated Security Incident Response. Email search re...
v10.7.2 2026-01-20 15:04:20
Fixed: Fixed an incorrect “email search is still running” message shown during the deletion approval step.
v10.7.0 2025-12-11 13:42:29
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v10.6.5 2025-05-01 18:55:03
Fixed: Remove/hide unsupported email fields from the email search criteria.
v10.6.3 2025-01-30 15:18:01
Changed: Migrated workflows to flow designer
v10.6.2 2024-03-07 15:37:27
Fixed: Supports non-ANSI characters in Threat-Hunting API query. Supports Graph URL configuration for Federal customers.
ID: 032838c30b2332009f66e94685673aa8 · Published: Jun 2026 · Updated: Sep 09, 2026