---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and Configure

# Install and Configure {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

Install and Configure Microsoft Defender integration from the ServiceNow® Store to control how incidents are retrieved, processed, and converted into security incidents within SIR.

## Antes de Iniciar

Role required: sn_si.admin, sn_si.ingestion_profile_admin  
Nota:  
Users with the sn_si.admin role can perform all operations available to a profile admin because this role inherits the required permissions by default.

## Procedimento

1. Download Microsoft Defender integration from the ServiceNow® Store and install it.
2. Navigate to AllSecurity OperationsIntegrationsIntegration Configurations.
3. Search for Microsoft Defender-Incident Ingestion Configuration tile, and select Configure.
4. On the form, fill in the fields.  
   {#configure-ms-defender__table_evw_xjl_gxc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the Microsoft Defender integration. |
   | Cloud Environment | Isolated instance of Microsoft Defender cloud services configured to meet specific requirements such as data residency, security, compliance, and regulatory standards. Options include: GLOBAL, US-GOV-GCC-HIGH, US-GOV-DOD, CHINA |
   | Tenant ID | Microsoft Defender Tenant ID. Instance from which all the incidents in the Microsoft portal are retrieved. |
   | Client ID | Client ID of the application registered in the Microsoft portal. Roles required in Defender include: * SecurityIncident.Read.All * SecurityIncident.ReadWrite {#configure-ms-defender__ul_ljb_sqp_13c} |
   | Client Secret | Client secret of your registered application in the Microsoft portal. |
   [ ]

   {#configure-ms-defender__table_evw_xjl_gxc}
5. Select Submit.  
   The configured integration tile displays.

## O que Fazer Depois

[Create an incident profile](https://servicenow-prod.fluidtopics.net/wE6WaDmNXB4ZZp8OUiofug "Determine the Microsoft Defender incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.")

