Microsoft Exchange Online for Security Operations
Search and delete phishing email threats.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 88 | -88 |
| 19 days of no change | ||
| 2026-04-07 | 89 | -1 |
| 12 days of no change | ||
| 2026-03-25 | 90 | -1 |
| 130 days of no change | ||
| 2025-11-14 | 89 | +1 |
| 2025-11-13 | 88 | +1 |
| 15 days of no change | ||
| 2025-10-28 | 87 | +1 |
| 47 days of no change | ||
| 2025-09-10 | 86 | +1 |
| 40 days of no change | ||
| 2025-07-31 | 85 | +1 |
| 117 days of no change | ||
| 2025-04-04 | 84 | +1 |
| 22 days of no change | ||
| 2025-03-12 | 83 | +1 |
| 6 days of no change | ||
| 2025-03-05 | 82 | +1 |
| 8 days of no change | ||
| 2025-02-24 | 81 | +1 |
| 52 days of no change | ||
| 2025-01-02 | 80 | +1 |
| 63 days of no change | ||
| 2024-10-30 | 78 | +2 |
About
Integrating ServiceNow® Security Incident Response with the Microsoft Exchange Online service, part of the Microsoft Office 365 suite of products, provides a security operations center (SOC) analyst with an email search and delete capability. With this integration, your SOC analyst can search your corporate email environment for security-related threats and remove phishing emails.
Key Features
The integration includes the following key features:
- Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
- For large and lengthy email searches, the security incident analyst is notified via email when a search is successfully completed, along with the number of matched messages.
- Status for individual messages informs you if recipients have read or deleted suspicious emails.
- If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
- A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents.
- If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents.