---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Policies for Exploit Protection (EDR)

# Mitigation controls and policies required for Exploit Protection (EDR) mitigation controls {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

This category of mitigation controls covers mitigations available on your assets in the form of endpoint protection agent configuration. This applies to endpoint protection agents such as CrowdStrike and SentinelOne.
Exploit mitigation settings such as 'Force Address Space Layout Randomization' and 'Force DEP' can be enabled in endpoint protection tools like CrowdStrike. SPC automatically detects this configuration on devices with the help of the policies included with the application and the API integration with endpoint protection tools.

Roles required: SPC Admin Group and SPC Analyst Group.

## Prerequisites for CrowdStrike Exploit Protection (EDR) mitigation control detection {#spc-controls-policies-for-edr__section_gnr_dd5_pcc}

1. Verify that you have activated the CrowdStrike Service Graph Connector. This application is available in the ServiceNow Store. The installation and configuration information is included on the app listing. See [Install and configure the CrowdStrike integrations for mitigation controls monitoring](https://servicenow-prod.fluidtopics.net/D_4v~wfYe_LHUZWIC0s86Q "The CrowdStrike Service Graph Connector and API integrations require separate configuration steps. You configure the CrowdStrike Service Graph Connector to import asset details. You configure the CrowdStrike API Integration to gather mitigation data about the assets that are monitored by CrowdStrike.") for more information.
2. Verify that the CrowdStrike API integration is activated in the Security Posture Control Workspace.
{#spc-controls-policies-for-edr__ol_mnq_hd5_pcc}

## Prerequisites for Microsoft Exploit Protection (EDR) mitigation control detection {#spc-controls-policies-for-edr__section_hc1_wfk_fdc}

Microsoft SCCM credentials that include the Script Authors role. The Script Authors role provides required permissions to create a script that is required to import mitigation information on the SCCM server.

You must activate the SCCM integration to identify mitigation controls configured in Microsoft Defender.

See [Install and configure the Service Graph Connector for Microsoft SCCM and the Microsoft Defender Mitigation Control Integration](https://servicenow-prod.fluidtopics.net/HQYgVzPgeJS8GmuaJr4CLA "The Service Graph Connector for SCCM and the Microsoft Defender Mitigation Control Integration require separate configuration steps.") for more information.

* Defender -- Exploit Mitigation -- CFGMicrosoft Defender Control Flow Guard.

* Defender -- Exploit Mitigation -- DEPMicrosoft Defender Data Execution Prevention.

* Defender -- Exploit Mitigation -- Mandatory ASLR and Bottom-Up ASLRMicrosoft Defender force ASLR.

* MITRE tactics addressed: Initial Access, Execution, Credential Access, Defense Evasion, Privilege Escalation, Lateral Movement.
{#spc-controls-policies-for-edr__ol_pzt_ggk_fdc}
1. Verify that you have activated the SentinelOne Service Graph Connector.This application is available in the ServiceNow Store. The installation and configuration information is included on the app listing. See [Install and configure the Service Graph Connector for SentinelOne and the SentinelOne Mitigation Control Integration](https://servicenow-prod.fluidtopics.net/3Si~VbfTp8qLRJsx7f6beQ "The Service Graph Connector for SentinelOne and the SentinelOne Integration for Mitigation Control Integration require separate configuration steps. You install and configure the Service Graph Connector for SentinelOne to import asset details. You configure the SentinelOne Integration for Mitigation Control Integration to gather mitigation data about the assets that are monitored by the Service Graph Connector for SentinelOne.") for more information.

2. Verify that the SentinelOne API integration is activated in the Security Posture Control Workspace.
{#spc-controls-policies-for-edr__ol_ib5_wty_c2c}

