---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Defender for EDR integration

# Microsoft Defender for EDR integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous
monitoring and real-time alerting.
* **[Register and configure the Microsoft Defender in the Microsoft Azure portal](https://servicenow-prod.fluidtopics.net/wVq0tsR8diabV11AOwklcA)**   
  Register the Microsoft Defender EDR in the Microsoft Azure portal and grant the read and write access to the application.
* **[Install and configure Microsoft Defender for EDR Integration](https://servicenow-prod.fluidtopics.net/IuwfnPzEuaDUnNj7GLpDZw)**   
  Install and configure the Microsoft Defender for EDR integration from the ServiceNow Store.
* **[System properties for Microsoft Defender EDR](https://servicenow-prod.fluidtopics.net/3TPJLE5ePWmVVL_LnY58MQ)**   
  The following details the system properties for Microsoft Defender EDR.
* **[Send observables to EDR](https://servicenow-prod.fluidtopics.net/L~4QhLTvEWqiAE80zMaP8Q)**   
  Send observables to the EDR security tool.

