logo

NJP

Microsoft Defender Incident ingestion integration for Security Operations

Microsoft Defender Incident ingestion integration for Security Operations

by Service-now.com

Microsoft Defender Incident ingestion integration for Security Operations

0 installs 0 reviews v4.0.1 Scoped Application Free-ish (consumes 11 tables) 11 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2026-03-13 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -

About

The  **Microsoft Defender integration for ServiceNow Security Operations**  ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.

Key Features

**This integration includes the following key features:**

- Create flexible event‑forwarding profiles to ingest Microsoft Defender incidents into ServiceNow SIR.
- Ingest historical, ongoing, new, and updated notable events on configurable intervals.
- Filter out noisy or low‑value alerts and bring only actionable notable events into SIR.
- Map Microsoft Defender incident, alert, and event fields directly to SIR security incident fields.
- Bi-directional synchronization of status, and work notes between Microsoft Defender and ServiceNow SIR.

Version History (2)
v4.0.1 2026-05-05 14:58:52
Fixed :  SIRs are not created from SIEM ingestion due to "Secure Notes" access issue to Crypto module since the Yokohama upgrade was fixed. A...
v4.0.0 2026-03-12 16:13:40
New: The Microsoft Defender integration allows you to automatically retrieve incidents from Microsoft Defender, convert them into security inciden...
ID: 0f7bf8eaffa1be505423f6648c4fd922 · Published: May 2026 · Updated: Sep 09, 2026