logo

NJP

Microsoft Graph Security API Alert Ingestion Integration For Security Operations

Microsoft Graph Security API Alert Ingestion Integration For Security Operations

by Service-now.com

Create Security Incidents automatically from Microsoft Graph Security API alerts.

0 installs 0 reviews v10.5.5 Scoped Application Free (integration tables[7] not counted) 7 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 75 -75
163 days of no change
2025-11-14 74 +1
28 days of no change
2025-10-16 73 +1
41 days of no change
2025-09-04 71 +2
44 days of no change
2025-07-21 70 +1
31 days of no change
2025-06-19 69 +1
51 days of no change
2025-04-28 68 +1
3 days of no change
2025-04-24 67 +1
27 days of no change
2025-03-27 66 +1
24 days of no change
2025-03-02 65 +1
23 days of no change
2025-02-06 64 +1

About

The Microsoft Graph Security API is an intermediary service (or broker) that provides a single programmatic interface to connect multiple security providers (Native to Microsoft and ServiceNow Partners).

The Microsoft Graph Security Alert Ingestion integration allows you to automatically retrieve alerts from multiple security providers, convert them into security incidents, and enable automated response actions.

Key Features

This integration includes the following key features:

- Discovery of Microsoft Graph Security Alerts that are candidates for security incidents and automate the creation of security incidents.
- Mapping of alert fields to security incident fields.
- Aggregation of similar alerts to existing open security incidents instead of creating duplicate security incidents.
- Validate your mapping with a preview of the alert field values in a security incident.
- Automatic alert status update for SIR incident creation and closure.
- Setup scheduled ingestion of alerts to create security incidents periodically.

Version History (7)
v10.5.5 2026-07-09 17:40:12
Fixed: Restored the buildInputValue function in the Graph Security API transform, fixing SIR fields being mapped as empty when a referenced source ...
v10.5.3 2026-06-16 16:44:06
Changed: Replaced hardcoded endpoint path to system properties. 
v10.5.2 2026-03-12 16:13:38
Fixed: Reintroduced a new column to filter alerts.
v10.5.1 2026-02-06 01:21:55
Fixed: Successful validation message getting displayed during configuration tile validation despite invalid credentials.
v10.5.0 2025-12-11 13:41:52
New : Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures ...
v10.4.13 2025-07-31 15:36:36
Fixed : Improved Handling of Next Poll Date for Microsoft Graph Security Alert Integration on HTTP Failures.
v10.4.8 2024-05-09 15:01:39
The dependency on the new UI is removed.
ID: 92712ec3c7000010c20eb5a827c26059 · Published: Jul 2026 · Updated: Sep 09, 2026