---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and Configure

# Install and Configure {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install and Configure Microsoft Defender integration from the ServiceNow® Store to control how incidents are retrieved, processed, and converted into security incidents within SIR.

## Before you begin

Role required: sn_si.admin, sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin because this role inherits the required permissions by default.

## Procedure

1. Download Microsoft Defender integration from the ServiceNow® Store and install it.
2. Navigate to AllSecurity OperationsIntegrationsIntegration Configurations.
3. Search for Microsoft Defender-Incident Ingestion Configuration tile, and select Configure.
4. On the form, fill in the fields.  
   {#configure-ms-defender__table_evw_xjl_gxc__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the Microsoft Defender integration. |
   | Cloud Environment | Isolated instance of Microsoft Defender cloud services configured to meet specific requirements such as data residency, security, compliance, and regulatory standards. Options include: GLOBAL, US-GOV-GCC-HIGH, US-GOV-DOD, CHINA |
   | Tenant ID | Microsoft Defender Tenant ID. Instance from which all the incidents in the Microsoft portal are retrieved. |
   | Client ID | Client ID of the application registered in the Microsoft portal. Roles required in Defender include: * SecurityIncident.Read.All * SecurityIncident.ReadWrite {#configure-ms-defender__ul_ljb_sqp_13c} |
   | Client Secret | Client secret of your registered application in the Microsoft portal. |
   [ ]

   {#configure-ms-defender__table_evw_xjl_gxc}
5. Select Submit.  
   The configured integration tile displays.

## What to do next

[Create an incident profile](https://servicenow-prod.fluidtopics.net/PKyrZhG2tntTt9x03VGvkw "Determine the Microsoft Defender incidents that are suitable for creating security incidents by creating an incident profile in your ServiceNow AI Platform instance.")

*[\>]: and then


