---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Map alert fields

# Mapping of alert fields for Microsoft Graph Security API alert ingestion integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

After you identify the sources for scheduled alert ingestion, the next step is to map
individual alert fields to the fields on a ServiceNow AI Platform
SIR security incident.

For the mapping step, you must first ingest sample alerts from the Microsoft Azure tenant. Then you must ensure that all relevant alert field data is mapped to the appropriate
place on the SIR incident form and then visualize the SIR incident in the preview section.  
Mapping of the sample alert fields involves the following:

* [Ingest sample Microsoft Graph Security API alerts](https://servicenow-prod.fluidtopics.net/dFTOtFBjF4wkbL6cDqSNKA "Ingest sample alerts from your Microsoft Azure tenant.")
* [Mapping alerts to security incident response fields](https://servicenow-prod.fluidtopics.net/vPbJI4ItshIqU~ObNMGqsQ "Map individual alert fields from triggered alerts to fields on a ServiceNow AI Platform security incident.")
{#ms-graph-mapping-about__ul_d3f_1x3_llb}

