Install and configure the Microsoft Defender for Cloud Integration for Security Operations, so that you can use the data that is imported from Microsoft Defender for Cloud to prioritize and remediate any misconfigurations on your assets.

Before you begin

Create a new app registration on Azure Active Directory. For more information on how to register a new application on Azure Active Directory, search for Register a client application in Azure Active Directory on the Microsoft documentation site. Assign the Security Reader role for the newly created app registration on the relevant scope with which you would like to connect to ServiceNow. It can be on a management group or subscription level.

Role required: sn_vulc.admin

Procedure

  1. Navigate to All > System Definition > Plugins.
  2. In the search bar, search for Microsoft Defender for Cloud Integration for Security Operations.
  3. Select Install.

    Any dependencies that will be installed are displayed.

  4. Navigate to All > Microsoft Defender for Cloud Integration > Administration > Configuration > Microsoft Defender for Cloud Configuration.
  5. On the form, fill in the fields.
  1. Configure or run the integrations by selecting Save and test.