---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Exchange Online integration

# Microsoft Exchange Online
integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Microsoft Exchange Online integration

The Microsoft Exchange Online integration with ServiceNow AI Platform® Security Incident Response (SIR) enables Security Operation Center (SOC) analysts to search and manage corporate email environments for phishing threats.
Analysts can locate suspicious emails using flexible search criteria such as sender, recipient, and subject, and delete confirmed phishing emails directly from Microsoft Exchange Online.
An optional approval workflow can be configured to add control over email deletions.
This integration supports phishing response workflows by helping identify and remediate phishing campaigns across the organization.
Show full answer Show less  

## Key Features

* Customizable email search criteria based on sender, recipient, and subject to detect phishing threats.
* Email search notifications inform analysts of search completion and matched message counts.
* Status tracking for individual emails indicates if recipients have read or deleted suspicious messages.
* Optional approval processes enforce control before deleting suspicious emails.
* Comprehensive audit trails log delete requests and email deletion counts in security incident work notes.
* Configurable security tags visually track the status of email search and delete workflows on security incidents.

## Supported Environments

This integration supports Microsoft Exchange Online services within the Microsoft Office 365 suite. It does not support hosted Microsoft Exchange environments and is compatible with Exchange 2016 as deployed by Microsoft.

## Prerequisites and Setup

* Install the **com.snc.sidep** plugin to support Security Incident Response and its dependencies.
* Install and activate required Security Operations applications in the prescribed order: Security Integration Framework, Security Support Common, Security Support Orchestration, and Security Incident Response.
* Complete setup of a Microsoft Azure account with access to the Exchange Online tenant to enable email data retrieval.
* Install the Microsoft Exchange Online application from the ServiceNow Store and configure it to connect to your ServiceNow AI Platform instance to activate search and delete workflows.

## Operational Workflow

* Security analysts with the **snsi.analyst** role define search criteria and submit email search requests linked to security incidents.
* Upon locating suspicious emails, analysts can request deletion of those emails from Exchange Online, with optional approval workflows ensuring organizational control.
* Delete email requests are routed to a configured approval group for authorization, adding a safeguard before removal.
* Deleted emails can be recovered by Microsoft Exchange administrators if needed during incident remediation.
* Security tags in the ServiceNow AI Platform can be customized to visually indicate the progress and outcomes of email search and delete actions.  
For the Microsoft Exchange Online
integration application by ServiceNow, the
ServiceNow AI Platform®
Security Incident Response (SIR) product is integrated with the Microsoft Exchange Online service, one of the
cloud-based services in the Microsoft
Office 365 suite of products. Your Security Operation Center (SOC) analyst can search your
corporate email environment for security-related threats and remove and remediate phishing emails
with email search and delete capabilities.

## Overview of Microsoft Exchange Online integration {#ms-exchange-online-lookups__section_vsn_fzh_z2b}

As the security incident analyst, you execute the integration from the security analyst
interface, and the workflow returns email message details that match search criteria. Email
searches are based on criteria that include subject lines as well as sender and recipient email
addresses. After the email search is complete, you can delete suspicious emails from the Microsoft Exchange Online service, and, an
optional approval process can be configured to request approval prior to deleting emails.

This email search and delete integration can be used with a broader phishing response incident
workflow or runbook. After a corporate user or employee receives a suspicious email and reports
it to the company's phishing response team or inbox, the reported email is forwarded to the ServiceNow AI Platform and categorized as a security
incident. After you have verified that an email is a phishing attack, as the analyst responsible
for investigating phishing incidents, you can initiate an email search to determine if other
corporate users have received this phishing email. The search allows you to locate related
emails from the same phishing campaign and identify other potential victims who may have
received the email, read it, and also potentially clicked a malicious URL or opened an
attachment.

## Key features {#ms-exchange-online-lookups__section_dn4_n1z_mfb}

The integration includes the following key features:

* Configure search criteria for phishing threats in Security Incident Response based on combinations of the sender, recipient, and subject fields on email messages.
* For large and lengthy email searches, the security incident analyst is notified via email when the search has successfully completed, along with the number of matched messages.
* Status for individual messages informs you if recipients have read or deleted suspicious emails.
* If configured, optional approval processes ensure that suspicious emails are not deleted without prior approval.
* A complete audit trail for delete requests that includes the number of deleted emails is logged in the work notes of security incidents.
* If tagging is configured, security tags record when email search and delete workflows are initiated and successfully completed on security incidents.
{#ms-exchange-online-lookups__ul_bpn_1fc_j2b}

## Supported Microsoft Exchange Online
versions {#ms-exchange-online-lookups__section_j25_1jm_y2b}

This integration supports Microsoft Exchange Online services, which are
part of the Microsoft Office 365 suite.
The integration does not support hosted Microsoft Exchange environments. Microsoft runs Microsoft Exchange Online services on the
Exchange 2016 version.

## Prerequisites {#ms-exchange-online-lookups__section_x15_vjm_y2b}

The com.snc.si_dep plugin is required for any ServiceNow AI Platform version. This plugin
automatically installs all the dependencies that are required to support the Security Incident Response product. Install and activate this plugin before installing and
activating the other Security Operations applications.  
The following Security Operations applications must be installed and activated from the ServiceNow Store. Install and then activate one application at a time in the order listed below to ensure a smooth installation:

1. Security Integration Framework
2. Security Support Common
3. Security Support Orchestration
4. Security Incident Response
{#ms-exchange-online-lookups__ol_xcx_jzk_tgb}
1. [Set up your Microsoft Azure account](https://servicenow-prod.fluidtopics.net/xrfZ7jhb8zBjZmgNX8mJbw)  
   Complete the following setup tasks in your Microsoft Azure portal prior to installing the ServiceNow application for this integration. This account permits access to the Microsoft Exchange Online tenant for email message details.
2. [Install Microsoft Exchange Online application](https://servicenow-prod.fluidtopics.net/s6jKx0Dt64gK5dcCr6rLvQ)  
   Before you run the integration on your instance, install the Microsoft Exchange Online application for the integration from the ServiceNow Store.
3. [Configure the Microsoft Exchange Online integration](https://servicenow-prod.fluidtopics.net/Lq95wViOo_H3WCH_nIKDwA)  
   After you've installed the application from the ServiceNow Store, configure it to connect to your ServiceNow AI Platform instance. This activation activates the search and delete workflows.
4. [Define email search criteria and request a search](https://servicenow-prod.fluidtopics.net/1RzsS82psRGigRxdm6QEKg)  
   As a user with the sn_si.analyst role, set up search criteria and submit an email search request based on incident details on a security incident record.
5. [Request delete approval for emails on Microsoft Exchange online service](https://servicenow-prod.fluidtopics.net/IOAZeK5jZl2y2_eK5ZDc3g)  
   After an email search is successfully completed and matching messages are identified, you can permanently delete all the suspicious emails from the Microsoft exchange online service that are related to the security incident and phishing campaign.
6. [Approve delete email requests for the Microsoft Exchange Online integration](https://servicenow-prod.fluidtopics.net/mYg5JL99D4mdMZi6hEQB3g)  
   If the approval option is enabled in your ServiceNow AI Platform instance, requests to delete emails are sent to each member of the approval group via email. You select the approval group during the configuration step. Approvals provide your organization with an additional level of control over the deletion of emails.
7. [Recover deleted emails on the Microsoft Exchange Online service](https://servicenow-prod.fluidtopics.net/YsIGrjLvp71w3nK4MfH~tA)  
   (Optional) As a Microsoft Exchange Administrator, you can recover deleted emails if your incident remediation requires that you to recover the emails deleted by the workflow of this integration.
8. [Edit security tags for the Microsoft Exchange Online integration](https://servicenow-prod.fluidtopics.net/6PT~VvN4hN2zOqSQksS7zA)  
   You can edit the names and colors of the security tags in your ServiceNow AI Platform® instance for the Microsoft Exchange Online integration. These security tags help you quickly identify when email search either completes or fails. They also identify when requests to delete emails are initiated and when the email items are successfully deleted.

