Map the Microsoft Defender for Endpoint indicator types
Map the ServiceNow Observable type with the Microsoft Defender for Endpoint indicator type. This mapping would be used in Observable Enrichment and Create Indicator actions in Microsoft Defender.
Before you begin
Role required: sn_si.admin or sn_si.analyst (read-only)
About this task
In a scenario where the observable type is not mapped to an indicator type, such observables are not eligible for Observable enrichment and indicator creation in Microsoft Defender for Endpoint.