---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Microsoft Defender for Office 365 integration

# Configure Microsoft Defender for Office 365 integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Gain valuable insights into phishing simulation metrics directly within the Cybersecurity Executive Dashboard through seamless integration with Microsoft Defender for Office 365.

## Before you begin

Role required: sn_sec_phish_msatk.ms_admin

## About this task

To learn more about simulating a phishing attack and setting up a tenant, see:

* [Simulate a phishing attack with Attack simulation training](https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-simulations)
* [Getting started using Attack simulation training](https://learn.microsoft.com/en-us/defender-office-365/attack-simulation-training-get-started)
* [Set up a tenant](https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-create-new-tenant)
{#configure-microsoft365-defender-integration-vr__ul_wth_yxn_4dc}

## Procedure

1. Navigate to AllMicrosoft Attack IntegrationMicrosoft Attack Configurations.
2. Select New.
3. On the form, fill in the details:  
   {#configure-microsoft365-defender-integration-vr__table_z5k_bwb_glb__entry__2}

   | Field | Description |
   |-|-|
   | Integration Instance | Name of the integration instance. Select the integration instance using the Lookup icon. |
   | Tenant ID | Tenant ID of the application created on the Microsoft Azure portal. |
   | Client ID | Client ID of the application created on the Microsoft Azure portal. |
   | Client Secret | Client secret of the application created on the Microsoft Azure portal. |
   | Bookmark | Date from which the simulations must be fetched. |
   | Token Url | Base URL from where the token is created to access the Microsoft Simulations API. |
   | All Simulation Url | Base URL of the Microsoft Simulations API. |
   [Table 1. Microsoft Attack Configuration form]

   {#configure-microsoft365-defender-integration-vr__table_z5k_bwb_glb}
   1. Select New if no integration instance is available.
   2. On the form, fill in the details:  
      {#configure-microsoft365-defender-integration-vr__table_z3j_1yy_kzb__entry__2}

      | Field | Description |
      |-|-|
      | Name | Name of the integration instance. |
      | Application | Name of the application (Microsoft Defender for Office 365). |
      | Integration | Third-party integration reference (Microsoft Attack Integration). |
      | Active | Default is activated (selected). If cleared, the instance isn't active. |
      | Description | Short description of the integration instance. |
      [Table 2. Integration Instance form]

      {#configure-microsoft365-defender-integration-vr__table_z3j_1yy_kzb}
   {#configure-microsoft365-defender-integration-vr__substeps_h2m_fpd_lzb}
4. Select Submit.
5. Navigate to AllSecurity Simulation and TrainingIntegrations.
6. Select Microsoft Attack integration.
7. Select Execute Now to execute and collect data from Microsoft.

*[\>]: and then


