---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Checklist

# Checklist for the McAfee ePO integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Use this checklist to guide you through all the tasks of the integration. The
following checklist includes setup and installation tasks and examples of use cases that
include expected results for the integration.

## Before you begin

Role required: Roles are listed for each step.

## About this task

Track your progress with the setup, installation, and configuration of the
integration with the following table. Complete all the tasks for a step before
moving on to the next step. Each row of the table lists tasks and identifies the
roles that are required to perform the tasks. Numbered topics of the installation
and configuration guide are also referenced.

## Procedure

Follow the steps in the table in the order that they are presented.  
{#mcafee-epo_checklist__table_f2c_xn4_sgb__entry__2}

| Item | Description |
|-|-|
| Check box | As a user with the ServiceNow AI Platform® administrator role, set up your ServiceNow AI Platform® instance. 1. Assign ServiceNow AI Platform® and Security Incident Response roles. 2. Verify that any ServiceNow Security Incident Response and other plugins that support the integration are installed and activated for your release of the ServiceNow AI Platform. 3. Install and configure a MID server in your ServiceNow AI Platform® instance. 4. Create an approval group if you want to process requests submitted from the security incident analyst for the isolate host and initiate malware scan actions. {#mcafee-epo_checklist__ol_tyb_gc5_tgb}For more information, see [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g "The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration."). |
| Check box | As McAfee ePO administrator, set up your McAfee ePO console. 1. Verify that you are using version 5.9 of McAfee ePO. 2. Install the ServiceNow extension plugin in your McAfee ePO console. 3. Verify you have created security tags in your McAfee ePO console for the isolate host and initiate malware scan actions. {#mcafee-epo_checklist__ol_crp_xc5_tgb}For more information, see [Set up your McAfee ePO console to integrate with Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/4Fc9alaTLobWBPEyQUWwgQ "The following section lists the setup steps that you're required to complete in your McAfee ePO console before installing the application from the ServiceNow Store for the integration."). For more information and to obtain the extension plugin file, in your ServiceNow AI Platform instance, navigate to KnowledgeArticlesAll and, in the Search field, enter, <kbd class="ph userinput">ServiceNow Security Operations Extension for McAfee ePO</kbd>. |
| Check box | As a user with the ServiceNow AI Platform administrator role, install the McAfee ePO application from the ServiceNow Store, configure a server, and connect to the McAfee ePO console. For more information, see [Install the application and configure a server for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/558OQkqyXS4AEEgA~ew3UQ "Before you invoke the workflows for the integration, install and configure the McAfee ePO application from the ServiceNow Store on your ServiceNow AI Platform instance. The configuration is required to connect to the McAfee ePO console."). |
| Check box | As a user with the ServiceNow AI Platform security incident administrator role, edit the security tag names in your ServiceNow AI Platform® instance so that they match the tag names that you created in your McAfee ePO console. For more information, see [Edit security tags in the ServiceNow AI Platform for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/t7yjTKU86iIWWMRdYA4o7Q "As part of the setup for the integration, edit the security tag names that you created in your McAfee ePO console in your ServiceNow AI Platform instance. Edit the tag names in your ServiceNow AI Platform instance so that they match the names of the tags in your McAfee ePO console."). |
| Check box | As a user with the security incident administrator role, create a profile for McAfee ePO capabilities. For information about profiles, see [McAfee ePO integration capability profiles](https://servicenow-prod.fluidtopics.net/KmuSjd1MW7GTkaPslRhOSQ "As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created."). For the steps required to create a profile, see [Create a capability profile](https://servicenow-prod.fluidtopics.net/_sVc2qUY5TIf4c2UXfFeRw "Create a profile and select the McAfee ePO capabilities that you want the profile to run."). |
| Check box | As a user with the security incident administrator role, configure a profile and test security incidents. 1. Review the information about triggering conditions and settings. 2. Configure a profile. 3. Test and preview security incidents. 4. Locate search results and other details on the related lists on the security incident. 5. Create and Configure different types of profiles and test security incidents for each type. {#mcafee-epo_checklist__ol_rdf_dp4_sgb} For information about triggering conditions and the alternate CI field, see [Defining triggering conditions with a Configuration item (CI) field](https://servicenow-prod.fluidtopics.net/fXL1DH5oW6BGZNfXQhvQIw "After you create a profile and select the McAfee ePO capabilities that you want the profile to run, you configure the settings of the profile so that it runs only when a set of specific conditions are met."). For the steps required to configure a profile, test, and preview security incidents and examples of profile types, see the examples that follow [Configure settings](https://servicenow-prod.fluidtopics.net/gXWSrQWap~UEfHVn_Tkg1Q "After you create a profile and select the McAfee ePO capabilities that you want the profile to run, configure the settings so that the profile is invoked only under the specific conditions that you define."). |
| Check box | As a user with the ServiceNow AI Platform security incident analyst role, submit additional requests for Malware scans and List threat events. For more information, see [Trigger McAfee ePO profile manually from a security incident](https://servicenow-prod.fluidtopics.net/r9EYGt8yhuNtg3GMsS_X9A "Trigger a capability profile manually from a ServiceNow AI Platform Security Incident Response (SIR) security incident.") In the ServiceNow AI Platform, as a user with an approval role, or, as a member of an approval group, approve requests for isolate host isolation and remove isolation. For more information on processing approval requests, see [Create an approval group](https://servicenow-prod.fluidtopics.net/RzTYtSmYWZcZe5dYqerc5A "Create an approval group for the McAfee ePO for Security Operations integration that can approve requests for isolating host machines, restoring them to the network."). |
[Table 1. Checklist]

{#mcafee-epo_checklist__table_f2c_xn4_sgb}  
You have successfully completed the setup steps, installed and configured the application, and verified expected results for the integration.
**Previous topic:** [Integration architecture for McAfee ePO](https://servicenow-prod.fluidtopics.net/Bo3ZWMoABtJ~KDUVW4CsmA "The following topic is an overview of the system architecture and lists key features of the integration. This section also provides information about the setup steps that you are required to complete in your ServiceNow AI Platform instance and in the McAfee ePolicy Orchestrator (McAfee ePO) console prior to installing the application from the ServiceNow Store.")  
**Next topic:** [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g "The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.")

*[\>]: and then


