---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Defender for Endpoint integration

# Microsoft Defender for Endpoint integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Microsoft Defender for Endpoint enables you to proactively inspect,
analyze, and contain known and unknown threats on any endpoint.

The Microsoft Defender for Endpoint integration helps Security Analysts efficiently
investigate and remediate security incidents without having to navigate between tools.

You can use this integration to create configurations to retrieve the host details, details of
logged-in users, related machines details, and other enrichment capabilities. You can request to
isolate any machine from accessing the networks or remove the machines from isolation. Requests
can be accepted or rejected by the approvers.

## Request apps on the Store {#microsoft-defender-for-endpoint-integration__section_qdr_5nw_v4b}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#microsoft-defender-for-endpoint-integration__inline-send-to-store}

## Key features {#microsoft-defender-for-endpoint-integration__section_s2w_51b_3sb}

Microsoft Defender for Endpoint has the following key features:

* Perform Enterprise Security Search to sight potential malicious observables across endpoints, and take remediation actions.
* Perform response actions such as Isolate host, Remove isolation, Restrict app execution, Run antivirus scan, Remove app restriction, and Stop and quarantine file.
* Create or update indicators.
* Perform observable enrichment and retrieve data related to indicators.
{#microsoft-defender-for-endpoint-integration__ul_a3p_kv1_3sb}

|-|-|-|
| [Explore ![]() Get started with Microsoft Defender for Endpoint](7f~6BTKQLnM8HsF9sRTsgw "The following section lists the setup tasks that you are required to complete in your ServiceNow AI Platform instance prior to installing the Microsoft Defender for Endpoint application from the ServiceNow store.") | [Install ![]() Install the application and configure a source for the integration](V1UkN1j6pJZDLIngqdLLXg "Install and configure the Microsoft Defender for Endpoint integration from the ServiceNow Store on your ServiceNow AI Platform instance. Start creating capability profiles using the configurations.") | [Configure ![]() Configure profiles and security incidents for the Microsoft Defender for Endpoint](Li_XTTg9x_LZIxdq47tWYw "Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run. You need to configure the settings so that the profile can be triggered only under the defined conditions.") |
| [Capability profile ![]() Create a capability profile for the Microsoft Defender for Endpoint integration.](xzKnibrbZ_k290WDBbyMyw "Create a profile and select the Microsoft Defender for Endpoint capabilities that you want the profile to run.") | [Additional configurations ![]() Additional configurations that you can perform in the Microsoft Defender for Endpoint](OJJ3Tz3x3gEQAV2rOy85rQ "The Microsoft Defender for Endpoint integration supports running additional actions beyond the standard actions.") | [Miscellaneous ![]() Create and configure a profile for sightings search and indicators with Microsoft Defender for Endpoint.](X4iSf5JDMb7JQWDVaa6ZlQ "Create and configure the sightings search profile automatically using the Microsoft Defender for Endpoint.") |
[Table 1. Microsoft Defender for Endpoint]

{#microsoft-defender-for-endpoint-integration__table_cn4_5nt_45b}

