logo

NJP

Microsoft Defender Integration for Security Exposure Management

Microsoft Defender Integration for Security Exposure Management

by Service-now.com

Integrate with Microsoft Defender TVM and Defender for Cloud to import vulnerabilities and misconfigurations into Security Exposure Management

0 installs 0 reviews v31.4.2 Scoped Application Free (integration tables[7] not counted) 7 tables
Developer Instance Sub-Production

Install Trend

First tracked: 2024-10-30 Latest: 2026-09-09 (0 installs)
View Install Data
Date Install Count Change
2026-09-09 0 -
134 days of no change
2026-04-27 162 -162
150 days of no change
2025-11-27 161 +1
14 days of no change
2025-11-12 158 +3
5 days of no change
2025-11-06 157 +1
1 days of no change
2025-11-04 156 +1
1 days of no change
2025-11-02 155 +1
6 days of no change
2025-10-26 154 +1
3 days of no change
2025-10-22 153 +1
2 days of no change
2025-10-19 152 +1
18 days of no change
2025-09-30 150 +2
4 days of no change
2025-09-25 149 +1
2025-09-24 148 +1
2 days of no change
2025-09-21 147 +1
13 days of no change
2025-09-07 146 +1
16 days of no change
2025-08-21 145 +1
1 days of no change
2025-08-19 144 +1
13 days of no change
2025-08-05 143 +1
5 days of no change
2025-07-30 142 +1
8 days of no change
2025-07-21 141 +1
11 days of no change
2025-07-09 140 +1
1 days of no change
2025-07-07 139 +1
2025-07-06 138 +1
7 days of no change
2025-06-28 137 +1
7 days of no change
2025-06-20 136 +1
16 days of no change
2025-06-03 135 +1
7 days of no change
2025-05-26 134 +1
5 days of no change
2025-05-20 133 +1
4 days of no change
2025-05-15 132 +1
13 days of no change
2025-05-01 131 +1
23 days of no change
2025-04-07 130 +1
3 days of no change
2025-04-03 129 +1
5 days of no change
2025-03-28 128 +1
1 days of no change
2025-03-26 127 +1
3 days of no change
2025-03-22 126 +1
3 days of no change
2025-03-18 125 +1
25 days of no change
2025-02-20 124 +1
3 days of no change
2025-02-16 123 +1
13 days of no change
2025-02-02 122 +1
1 days of no change
2025-01-31 121 +1
2025-01-30 120 +1
2025-01-29 119 +1
2025-01-28 118 +1
10 days of no change
2025-01-17 117 +1
14 days of no change
2025-01-02 116 +1
63 days of no change
2024-10-30 113 +3

About

**Note:**

**This app version is intended for Unified Security Exposure Management (USEM), a significant architectural upgrade to the Vulnerability Response applications.**

**If you are currently using Vulnerability Response and upgrading to USEM for the first time, you must use the Migration assistant for Unified Security Exposure Management to ensure a safe and successful upgrade. For full details, please refer to the [KB2556844](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2556844) and [documentation](https://www.servicenow.com/docs/bundle/zurich-security-management/page/product/security-exposure-management-workspace/concept/unified-security-exposure-management-landing-page.html) before proceeding.**

**If you do not intend to upgrade to USEM, please select a version below 30.x when installing or upgrading.**

The Microsoft Defender Integration for Security Exposure Management application bundles two independent integrations, each with its own configuration steps and distinct API URLs. These integrations let you configure and manage Microsoft security data imports in your ServiceNow instance.

- **Microsoft Threat and Vulnerability Management (MS TVM)** for endpoint vulnerability and asset data.
- **Microsoft Defender for Cloud** for cloud misconfiguration findings, compliance assessment data, and container image vulnerabilities.  

Together, these integrations give you a consolidated view of your Microsoft security posture and enable remediation workflows directly from ServiceNow. Works with Vulnerability Response and Configuration Compliance.

This application replaces the standalone Microsoft Defender for Cloud Integration for Security Operations application. If you are upgrading from the standalone application, see [Migrate from Microsoft Defender for Cloud Integration](https://www.servicenow.com/docs/r/x8~ohSTeWLioGLVI5x3Vgg/rbBO8tcbACizT8~Hnvs9QA). 

Key Features

The Microsoft Defender Integration for Security Exposure Management application includes the following key integrations: 

- **Microsoft TVM Machines Integration** : Import the collection of assets that communicate with MS TVM. Asset records serve as the foundation for linking vulnerability findings imported by subsequent integrations.
- **Microsoft TVM Vulnerability Integration** : Import endpoint vulnerability findings via the MS TVM Machines Vulnerabilities Integration. Supports both full and delta imports. Findings are mapped to Vulnerable Items (VITs) and Detections within the Vulnerability Response application to support triage, prioritization, and remediation workflows.
- **Microsoft TVM Recommendations Integration** : Import actionable security recommendations from MS TVM to help identify and prioritize remediation actions across your endpoint environment.
- **Microsoft TVM Vulnerability (CVE) Integration**: Import vulnerability and exploit information for CVEs from MS TVM, with support for Common Vulnerability Data (CVD) API enrichment and source-specific field prioritization.
- **Microsoft Defender for Cloud Configuration Compliance Integration** : Import cloud security posture and misconfiguration findings from Microsoft Defender for Cloud. Findings are mapped to Tests and Test Results in the Configuration Compliance application to help you enforce security policies and track compliance across your cloud environment.
- **Microsoft Defender for Cloud Container Vulnerability Integration** : Import container image vulnerability findings from Microsoft Defender for Cloud. Findings are mapped to Container Vulnerable Items (CVITs) to support container-specific triage, risk prioritization, and remediation workflows. 

Version History (11)
v31.4.2 2026-08-07 19:01:08
Fixed: Authentication failure for the Microsoft TVM integration if the authentication URL is not provided in the Setup Assistant. If not provided,...
v31.3.0 2026-06-16 16:46:59
Changed: Migrated query access control list (ACL) definitions to the standard product codebase in Vulnerability Intelligence, improving long-term ...
v31.0.3 2026-04-09 15:30:46
New:Uptake of Common Vulnerability Data (CVD) APIs in the Microsoft Defender TVM integration for CVE creation and enrichment, with source-specific ...
v30.1.0 2025-12-11 14:57:36
Changed If Vulnerability Response Integration with Microsoft Threat and Vulnerability Management for Security Operations is installed, a tile to r...
v3.0.3 2026-04-09 15:36:16
New: Microsoft Defender for Cloud container image vulnerability imports. In addition to cloud misconfigurations, the integration now supports impo...
v2.8.1 2025-12-11 15:00:12
Fixed The Vulnerability Response integration with Microsoft TVM now processes cloud resources ingested from Microsoft TVM. The system uses CI loo...
v2.6.6 2025-09-10 12:04:56
Fixed Resolved an issue where integration payloads without IP address information were displaying "undefined" in the corresponding detection reco...
v2.6.5 2025-07-31 15:40:11
Changed: Introduced a feature to Split Vulnerable Items with multiple remediation recommendations into separate VIs, each with a unique recommenda...
v2.6.3 2025-05-01 18:58:58
Fixed: Minor fixes for this release.
v2.6.2 2025-01-30 16:21:52
Changed: Verify that CVSS scores are populated on the CVE records from TVM

+ 1 more versions

ID: 3aa063f90e31201021b86bb11fc55ea2 · Published: Aug 2026 · Updated: Sep 09, 2026