---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure Get Related Machines from Defender capability

# Configure Get Related Machines from Defender Capability in Microsoft Defender for Endpoint {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Get the list of related machines of specific observables.

## Before you begin

Note:  
Supported Observable Types are Domain name, SHA1 hash, and Username. Role required: sn_si.admin or sn_si.analyst

## About this task

You can retrieve the list of machines that have accessed the particular observables.
You can store the list on the Microsoft Defender for Endpoint Related Machines
Details table. You can trigger the Get Related Machines from Defender capability
from the Associated Observables related list.

## Procedure

1. Navigate to Security IncidentsShow All Incidents.
2. Select the security incident that you want to review with the Microsoft Defender for Endpoint information.
3. In the Related links section, select Show IoC.
4. Select the Associated Observables related list.
5. Select the associated observables.
6. From the Actions list, select the Get Related Machines from Defender capability.
7. Validate the automation activity and activities section.
8. View the data, and validate the Microsoft Defender for Endpoint Related Machines details on the related lists.
9. View the automation activities of the execution, and validate them.
**Related tasks**   

* [Configure Isolate Host capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/Ki8P7XtpAtC9Oz~cYQUBMA "Isolate the host from accessing the network in Microsoft Defender for Endpoint based on the severity of the attack. Isolating the host from the network enables you to prevent any other malicious activities or potential attacks on other hosts.")
* [Configure Remove Host Isolation capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/HnP2gQ6shQLJkKVzFgZ6~w "If needed, remove the isolation of a host that was previously isolated from the network in Microsoft Defender for Endpoint. You can prevent any other malicious activities or potential attacks on other hosts.")
* [Configure Run Antivirus Scan capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/HZE53up7dsve2HgSNuujmg "Remotely initiate an anti virus scan to help identify and remediate malware that might be present on a compromised device. Run the scan as part of the investigation or response process.")
* [Configure Restrict App Execution capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/umLfGvVEfqC3On7zpImXeQ "To contain an attack, restrict or lock a device and prevent subsequent attempts of potentially malicious programs from running.")
* [Configure Remove App Restriction capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/tJb_A8aLGdQZSaBW32ONCg "If needed, remove the restrictions of any application on the device.")
* [Configure Stop and Quarantine File capability in Microsoft Defender for Endpoint](https://servicenow-prod.fluidtopics.net/0gn9njCRKqRAEeBM0xIjbQ "Stop and quarantine files from the Microsoft Defender platform.")

*[\>]: and then


