---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Trigger capability profile from configuration item related list

# Trigger the Microsoft Defender for Endpoint from Configuration Item related
list {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Trigger a capability profile manually from the configuration item related
list.

## Before you begin

Role required: sn_si.admin or sn_si.analyst

## Procedure

1. Navigate to Security IncidentsShow All Incidents.
2. Select the security incident that you want to review with the Microsoft Defender for Endpoint information.
3. Click Show All Related Lists.
4. Click the Configuration Item related list.
5. Select the added configuration items.
6. From the Actions on selected rows, select a capability.  
   The selected capability is triggered manually.
7. Validate the work notes and activities section.
8. View the tags, and validate the data in the related lists.

*[\>]: and then


