---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up the Office Malicous File Detected playbook

# Set up the Office Malicous File Detected playbook {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the following steps to set up the Office Malicous File Detected playbook.

## Before you begin

Role required:

* sn_si.admin
* flow_designer
{#playbook-setup-office-malicous-file-detected__ul_ub3_m35_xzb}

Make sure you have installed Security Operations Spoke (sn_sec_spoke).

## Procedure

1. Login as a user with sn_si.user and flow_designer roles.
2. Navigate to AllFlow Designer and select the Office 365 - Malicious File Detected playbook.
3. **Optional:** You can create a copy of the Office 365 - Malicious File Detected playbook flow and make the necessary modifications.  
   To create a copy of the playbook's flow, select the ![More actions menu]() icon and select Copy flow. Perform this step only if you plan to customize or make specific changes to the flow.
4. Activate the playbooks.  
   * Activate the main flow to use the playbook available in the base system.
   * Activate the copied flows after making the required changes.
   {#playbook-setup-office-malicous-file-detected__ul_qps_ktw_fzb}
5. Set a Trigger Condition for the playbook.  
   This playbook is triggered and associated with the security incident when the Category is Malicious code activity.
**Related tasks**   

* [Use the Office 365 Malicious File Detected playbook](https://servicenow-prod.fluidtopics.net/6RnTsg2_j1O9JGxFL3erLA "Use this playbook to investigate malicious files detected in Office 365. The following steps give you a walkthrough of the actions, tasks, and subflows that are available in the Office 365 Malicious File Detected playbook.")

*[\>]: and then


