Microsoft Defender Incident ingestion integration for Security Operations
Microsoft Defender Incident ingestion integration for Security Operations
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
About
The **Microsoft Defender integration for ServiceNow Security Operations** ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.
Key Features
**This integration includes the following key features:**
- Create flexible event‑forwarding profiles to ingest Microsoft Defender incidents into ServiceNow SIR.
- Ingest historical, ongoing, new, and updated notable events on configurable intervals.
- Filter out noisy or low‑value alerts and bring only actionable notable events into SIR.
- Map Microsoft Defender incident, alert, and event fields directly to SIR security incident fields.
- Bi-directional synchronization of status, and work notes between Microsoft Defender and ServiceNow SIR.