---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# McAfee ePO integration

# McAfee ePO integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of McAfee ePO integration

The McAfee ePO integration with ServiceNow AI Platform® enhances Security Operations Center (SOC) analysts' ability to detect, investigate, and remediate cyber threats using McAfee's endpoint detection and response (EDR) capabilities.
This integration enables automated or manual invocation of McAfee ePO actions and queries directly from ServiceNow Security Incident Response (SIR) incidents.
Show full answer Show less  
Key McAfee ePO capabilities available through the integration include:

* Gathering system details (including OS information)
* Initiating malware scans on endpoints
* Isolating or unisolating hosts from the network
* Listing threat events and compliance status

## Key Features

* Automated triggering of McAfee ePO queries and actions based on incident conditions in ServiceNow.
* Manual launch of McAfee ePO capabilities from SIR security incidents for on-demand actions.
* Support for multiple profiles to tailor triggers and actions to specific incident categories such as malware.
* Preview functionality to validate profile configurations and McAfee ePO results within SIR incidents.
* Use of security tags to track the initiation and completion of McAfee ePO capabilities, enhancing visibility.
* Comprehensive audit trails in both ServiceNow work notes and the McAfee ePO console for all executed commands.
* Support for multiple McAfee ePO consoles and versions (McAfee ePO 5.9.1 \& 5.10, McAfee Agent 5.5.1.388, and McAfee Endpoint Security Threat Prevention 10.5).

## Setup and Configuration Essentials

* Required ServiceNow plugin: **com.snc.sidep**, which installs dependencies for Security Incident Response.
* Installation and activation of Security Operations applications in a prescribed order to ensure smooth deployment.
* Installation of the **ServiceNow Security Operations Extension for McAfee ePO℠** plugin within the McAfee ePO console.
* Deployment of a configured MID Server to enable communication between ServiceNow AI Platform and the McAfee ePO server.
* Creation and synchronization of security tags in both McAfee ePO and ServiceNow to enable tag-based actions and tracking.
* Creation of approval groups within ServiceNow to manage requests such as host isolation and network restoration.

## Operational Use and Management

* Profiles allow grouping of McAfee ePO queries and actions and specify when these should trigger automatically for new incidents or be run manually.
* Capabilities such as listing threat events and initiating malware scans can be executed as additional actions on demand.
* Analysts can leverage McAfee ePO functions directly from the Security Incident Response Analyst Workspace.
* Testing facilities enable validation of malware scan profiles and host isolation workflows, including previewing results directly in security incidents.
* Customization of security tag names and colors for start and completion statuses improves incident clarity and workflow tracking.

## Benefits for ServiceNow Customers

This integration streamlines SOC workflows by embedding McAfee ePO's powerful endpoint management and threat response capabilities within the ServiceNow AI Platform environment. Customers gain automated incident-driven response actions and detailed endpoint insights without leaving their incident management console, improving detection speed, response accuracy, and auditability. The integration's flexibility in configuration and tagging supports tailored security operations aligned with organizational needs and compliance requirements.  
The McAfee ePO integration endpoint detection and response (EDR) capability that helps Security Operations Center (SOC) analysts identify cyberthreats and repair the damage caused by malicious files.

## Overview of McAfee ePO integration {#mcaffee-epo-overview-arch__section_zks_4kt_mfb}

There are two sets of McAfee ePO capabilities used in this integration, the capabilities that invoke actions, such as isolating a host and initiating a malware scan, and the capabilities that run queries to gather system details and
threat events. Both types of capabilities, the actions and the queries, are invoked from your ServiceNow AI Platform® instance. You can group these capabilities together so that they automatically run when a specific type of security event occurs, or, you can invoke them manually from a ServiceNow AI Platform® security incident.

The following McAfee ePO capabilities are available for this
integration.

Get system details
:   Gather system details that include operating system details.

Initiate malware scan
:   Based on scan configuration and scheduling, initiate a scan of an impacted
    endpoint.

Isolate/Unisolate host
:   Remove a system from network access for investigation and restore access to the
    network.

List threat events
:   Gather compliance status and the most current threat events.

## Key features {#mcaffee-epo-overview-arch__section_hdr_4lz_mfb}

This integration includes the following key features.

* Supports automated triggering of McAfee ePO queries that are based on incident conditions.
* Supports launching McAfee ePO capabilities manually from ServiceNow AI Platform® Security Incident Response (SIR) security incidents that perform on-demand actions.
* The flexibility to create multiple profiles for triggering different types of McAfee ePO and ServiceNow AI Platform® Security Operations capabilities. These profiles gather threat event information or perform actions based on the conditions of specific incident categories such as malware.
* Validate your profile configuration with a preview of the McAfee ePO results on SIR security incidents.
* If tagging is enabled, security tags identify which McAfee ePO capabilities are initially launched by a workflow and when the queries or actions are successfully completed.
* A complete audit trail of the McAfee ePO queries and actions is posted in the work notes on SIR security incidents, and commands from the ServiceNow AI Platform® are logged in the McAfee ePO console.
* Supports multiple McAfee ePO consoles.
{#mcaffee-epo-overview-arch__ul_k43_bjx_42b}

## ServiceNow Plugins {#mcaffee-epo-overview-arch__section_sw3_mqb_2gb}

The com.snc.si_dep plugin is required. This plugin automatically installs all the
dependencies that are required to support the Security Incident Response product.
Install and activate this plugin before installing and activating the other Security Operations applications.  
The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed below to ensure a smooth installation:

1. Security Integration Framework
2. Security Support Common
3. Security Support Orchestration
4. Security Incident Response
5. Security Incident Response Workspace
{#mcaffee-epo-overview-arch__ol_xcx_jzk_tgb}

For more information on setting up your ServiceNow AI Platform instance for the
integration, see [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g "The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.").

## The ServiceNow extension plugin {#mcaffee-epo-overview-arch__section_pys_t2d_t3b}

The ServiceNow Security Operations Extension for McAfee ePO℠
extension plugin is required for this integration. You install this ServiceNow plugin in your McAfee ePO console. For more
information, see [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g "The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.").

## MID Server {#mcaffee-epo-overview-arch__section_e2y_5rb_2gb}

This integration requires an installed and configured MID Server in your ServiceNow AI Platform® instance to connect to the McAfee ePO server
(console). See the [ServiceNow Product Documentation website](https://www.servicenow.com/docs) for more information about MID
Servers.

## Supported versions of McAfee {#mcaffee-epo-overview-arch__section_uj4_xgr_qfb}

The integration supports version 5.9.1 \& 5.10 of McAfee ePO. It supports McAfee Agent: MA 5.5.1.388 For more information about McAfee products and the ePolicy Orchestrator, see the [McAfee product website](https://www.mcafee.com/en-us/index.html).

The integration supports the version 10.5 of the McAfee Endpoint Security Threat Prevention
product. If you are not running version 10.5, consult with your McAfee ePO
administrator to see if your version can support on-demand scans via tag actions.

McAfee ePO security tags are used in this integration. You are required to
create these tags in your McAfee ePO console. For more information on these
tags, see [Set up your McAfee ePO console to integrate with Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/4Fc9alaTLobWBPEyQUWwgQ "The following section lists the setup steps that you're required to complete in your McAfee ePO console before installing the application from the ServiceNow Store for the integration.").

## References {#mcaffee-epo-overview-arch__section_y2r_wqb_2gb}

{#mcaffee-epo-overview-arch__table_axk_n23_2gb__entry__3}

| Reference | Document Identifier | Document Title |
|-|-|-|
| 1 | McAfee product website | [McAfee product website](https://www.mcafee.com/en-us/index.html) |
| 2 | McAfee Business Product Documentation for ePolicy Orchestrator Cloud | [McAfee Product Documentation](https://docs.mcafee.com/bundle?value=225) |
| 3 | ServiceNow Product documentation website | [ServiceNow Product Documentation website](https://www.servicenow.com/docs) |
[ ]

{#mcaffee-epo-overview-arch__table_axk_n23_2gb}

For a checklist to track your progress with setting up, installing, and verifying results
for the integration, see [Checklist for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/3j27H7ObSpuDMZQAKXIxaA "Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.").

For a smooth installation of the application and to help you verify expected results,
follow the topics in the order they are presented.
1. [Integration architecture for McAfee ePO](https://servicenow-prod.fluidtopics.net/Bo3ZWMoABtJ~KDUVW4CsmA)  
   The following topic is an overview of the system architecture and lists key features of the integration. This section also provides information about the setup steps that you are required to complete in your ServiceNow AI Platform instance and in the McAfee ePolicy Orchestrator (McAfee ePO) console prior to installing the application from the ServiceNow Store.
2. [Checklist for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/3j27H7ObSpuDMZQAKXIxaA)  
   Use this checklist to guide you through all the tasks of the integration. The following checklist includes setup and installation tasks and examples of use cases that include expected results for the integration.
3. [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g)  
   The following section lists the setup tasks that you're required to complete in your ServiceNow AI Platform® instance prior to installing the application for the McAfee ePO integration.
4. [Set up your McAfee ePO console to integrate with Security Incident Response (SIR)](https://servicenow-prod.fluidtopics.net/4Fc9alaTLobWBPEyQUWwgQ)  
   The following section lists the setup steps that you're required to complete in your McAfee ePO console before installing the application from the ServiceNow Store for the integration.
5. [Install the application and configure a server for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/558OQkqyXS4AEEgA~ew3UQ)  
   Before you invoke the workflows for the integration, install and configure the McAfee ePO application from the ServiceNow Store on your ServiceNow AI Platform instance. The configuration is required to connect to the McAfee ePO console.
6. [Edit security tags in the ServiceNow AI Platform for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/t7yjTKU86iIWWMRdYA4o7Q)  
   As part of the setup for the integration, edit the security tag names that you created in your McAfee ePO console in your ServiceNow AI Platform instance. Edit the tag names in your ServiceNow AI Platform instance so that they match the names of the tags in your McAfee ePO console.
7. [Create an approval group](https://servicenow-prod.fluidtopics.net/RzTYtSmYWZcZe5dYqerc5A)  
   Create an approval group for the McAfee ePO for Security Operations integration that can approve requests for isolating host machines, restoring them to the network.
8. [McAfee ePO integration capability profiles](https://servicenow-prod.fluidtopics.net/KmuSjd1MW7GTkaPslRhOSQ)  
   As a user with the security incident administrator (sn_si.admin) role, you create profiles for the McAfee ePO capabilities in your ServiceNow AI Platform® instance. You group queries or actions in profiles and determine which McAfee ePO capabilities you want to run when a new security incident is created.
9. [Trigger McAfee ePO profile manually from a security incident](https://servicenow-prod.fluidtopics.net/r9EYGt8yhuNtg3GMsS_X9A)  
   Trigger a capability profile manually from a ServiceNow AI Platform Security Incident Response (SIR) security incident.
10. [Trigger additional actions in McAfee ePO integration](https://servicenow-prod.fluidtopics.net/1wm9FhnWasGcdZdOjtMQ7A)  
    The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.
11. [Using McAfee ePO integration in Analyst Workspace](https://servicenow-prod.fluidtopics.net/YW6qwfIK8LbVu4mUYfslTg)  
    Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.
12. [Test security incidents to initiate malware scan](https://servicenow-prod.fluidtopics.net/0cfMeygiSF_iKVEpFmtD3A)  
    After you configure a profile for the malware scan, test the profile and view the security incidents that match the settings of your profile. Preview the scan results on the related lists of a ServiceNow AI Platform Security Incident Response (SIR) security incident.
13. [Test security incidents and approve requests for the isolate host](https://servicenow-prod.fluidtopics.net/UMixk4nABVwyyt2n67pWyQ)  
    The test and preview step permits you to validate that the host isolation and remove host isolation workflow results are returned as expected for the profile.
14. [Edit the start and completion tag names and colors](https://servicenow-prod.fluidtopics.net/t0GAbfGiZnCJtPccC5Y_PQ)  
    You may prefer to edit the names and colors of the start and complete tags for the initiate malware scan and isolate host capabilities. The start and complete tags help you quickly identify which capabilities are invoked from ServiceNow AI Platform Security Incident Response (SIR) security incidents.

**Related concepts**   

* [Integration architecture for McAfee ePO](https://servicenow-prod.fluidtopics.net/Bo3ZWMoABtJ~KDUVW4CsmA "The following topic is an overview of the system architecture and lists key features of the integration. This section also provides information about the setup steps that you are required to complete in your ServiceNow AI Platform instance and in the McAfee ePolicy Orchestrator (McAfee ePO) console prior to installing the application from the ServiceNow Store.")

