---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Sentinel integration

# Microsoft Sentinel integration {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Threat Intelligence Security Center for Microsoft Sentinel offers several capabilities, including importing observables from TISC to Sentinel, enriching Sentinel incidents with details of related observables, and also allow exporting observables from Sentinel to TISC.  
Note:  
On Microsoft Sentinel, observables are referred as entities.

## Prerequisites {#tisc-sentinel-integration__section_f55_2ln_c2c}

Dependencies

The Threat Intelligence solution from Microsoft Sentinel Content Hub must be installed.  
{#tisc-sentinel-integration__table_yg1_hpw_c2c__entry__3}

| Application | Roles and Permissions | Description |
|-|-|-|
| Microsoft Sentinel-specific roles | 1. Logic App Contributor 2. Microsoft Sentinel Contributor {#tisc-sentinel-integration__ol_v4h_ppw_c2c} | 1. To install the required playbooks on a Resource Group level. 2. Interact with Microsoft Sentinel playbooks. {#tisc-sentinel-integration__ol_v41_bpw_c2c} For more information, see [Roles and Permissions](https://learn.microsoft.com/en-us/azure/sentinel/roles#roles-and-permissions-for-working-in-microsoft-sentinel) in Microsoft Sentinel. |
| Threat Intelligence Security Center | sn_sec_tisc.api_azure_sentinel_solution | User configured in the TISC Custom Connector should have this role to allow access to TISC APIs. |
[Table 1. Roles and permissions]

{#tisc-sentinel-integration__table_yg1_hpw_c2c}
* **[TISC playbook templates](https://servicenow-prod.fluidtopics.net/WeVT9DoWGpT202anwmLtBg)**   
  This section describes the playbook templates that are shipped with TISC Sentinel solution.

