---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Use

# Using McAfee ePO integration in Analyst Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use the McAfee ePO integration to leverage the McAfee ePO capabilities on the SIR Analyst workspace.

## Before you begin

Role required: sn_si.admin

Before you use McAfee ePO integration on the Security Incident Response workspace, you must download it from the ServiceNow Store and configure it. For more information, see [Set up your ServiceNow AI Platform instance for the McAfee ePO integration](https://servicenow-prod.fluidtopics.net/rbGPf~1aAPlwY3JYNinz8g "The following section lists the setup tasks that you’re required to complete in your ServiceNow AI Platform instance prior to installing the application for the McAfee ePO integration.").

## About this task

You can use the McAfee ePO integration to make remediation actions on the endpoints in real-time, use profiles to gather details about the host, and make specific queries or actions on the endpoint using the Security Incident Response workspace.  
The McAfee ePO integration enables analysts to use the following McAfee ePO capabilities on the Security Incident Response Analyst workspace:

* Get Host Details
* Isolate Host
* Remove Isolation
* Run Additional Action(s) on Endpoint
{#using-mcafee-integration-aws__ul_izb_ckx_hxb}

## Procedure

1. To open the security incident in the SIR workspace, click Switch to SIR Workspace on the security incident.
2. In the SIR workspace, select the Related Records tab.
3. Select any Configuration Item, and choose a McAfee ePO capability to trigger from the related list drop down action.  
   For example, Get Host Details.
4. In the Get Host Details pop-up, select the McAfee ePO implementation.
5. Select Submit.  
   The Get Host Details capability is invoked on the CI. You can view the worknotes for the results and findings.
6. To view the data for the triggered capability, select the Investigation tab.
7. Select the Configuration Item, and click the View Associated Info action.
8. Select the Configuration Item to view the host details.  
   Similarly, you can try using the other McAfee ePO capability for you security incidents on the SIR Analyst Workspace.
9. You can use the McAfee ePO capabilities on the Endpoint Detection and Reponse (EDR) related list for analysis.
10. Browse and select a profile from the list of available profiles.  
    The list of available profiles are Get Host Details, Isolate Host machine, and Remove Isolation. For example, let's select Get Host Details.
11. Select the McAfee ePO implementation, and click Submit.
**Previous topic:** [Trigger additional actions in McAfee ePO integration](https://servicenow-prod.fluidtopics.net/1wm9FhnWasGcdZdOjtMQ7A "The List Threat Events and Initiate Malware Scan capabilities can be triggered from Run Additional Actions.​")  
**Next topic:** [Test security incidents to initiate malware scan](https://servicenow-prod.fluidtopics.net/0cfMeygiSF_iKVEpFmtD3A "After you configure a profile for the malware scan, test the profile and view the security incidents that match the settings of your profile. Preview the scan results on the related lists of a ServiceNow AI Platform Security Incident Response (SIR) security incident.")

