---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure

# Install and configure the Servicenow application for Microsoft Graph Security API alert
ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Before you run the integration on your ServiceNow AI Platform® instance,
complete these installation and configuration steps so the application properly integrates
with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.

## Before you begin

Role required: sn_si.admin

## Procedure

1. If you have not installed the Microsoft Graph Security API application from the ServiceNow Store for the integration, see [Install a Security Operations integration](https://servicenow-prod.fluidtopics.net/dIzJWROPdytPu1FmtvPx3w "All ServiceNow integrations are available on the ServiceNow Store. Core applications, such as Security Incident Response, are visible in the ServiceNow Products tab on the store. Integration add-ons are visible in the Certified Apps tab.") and follow the steps to install it.
2. After you have successfully installed the application, navigate to IntegrationsIntegrations Configurations and locate the Microsoft Graph Security API - Alert Ingestion tile.  

   <br />

3. To configure the application, select Configure.
4. In the Alert Ingestions Configuration dialog that is displayed, fill in the fields.

   | Field | Description |
   | Name | Name of the Microsoft Azure Cloud instance. You can enter only alphanumeric values and hyphens (-) in this field. |
   | Tenant ID | The Microsoft Azure Tenant ID. This is the instance from which all the alerts in the Microsoft Azure portal are retrieved. |
   | Client ID | The Client ID for the application that you have registered in the Microsoft Azure portal. See [Configure the Microsoft Azure portal](https://servicenow-prod.fluidtopics.net/O8_z8h1LiULLFc_jN~zzhw "To retrieve security alerts for an application available in the Microsoft Azure tenant using the Microsoft Graph Security API, you must register the application in the Microsoft Azure portal and grant security event read and write access to the application.") for details. |
   | Client Secret | The password for your registered application. |
   |-|-|

   {#ms-graph-install__choicetable_rrp_bwk_kdb}
5. Select Submit.  
   After it is successfully validated and submitted, each alert ingestions server configuration is saved on the Security Integrations page as a tile. If your saved configuration tiles are not displayed on the Security Integrations page, on the top right corner of the page, from the Show Configurations list, select Yes.
{#ms-graph-install__steps_rvh_qsv_3fb}

## What to do next

You have successfully installed and configured the application. The next step is to create an alert profile.

*[\>]: and then


