---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Defender

# Understanding the Microsoft Defender for Cloud integrations for Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated July 16, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding the Microsoft Defender for Cloud integrations for Security Exposure Management

The Microsoft Defender Integration for Security Exposure Management application in ServiceNow enables seamless import and management of cloud security data from Microsoft Defender for Cloud.
This integration supports ingestion of cloud misconfiguration findings, compliance data, and container image vulnerabilities, helping organizations maintain continuous visibility and compliance for their cloud resources.
Show full answer Show less  
This integration is subscription-based and available through the ServiceNow Store.

## Key Features

* **Integration with Configuration Compliance:** Maps security tests to configuration items (CIs) to generate test results, ensuring resources are assessed against recognized security standards such as the Center for Internet Security (CIS).
* **Multi-deployment Support:** Supports multiple Microsoft Defender for Cloud Platform deployments, consolidating overlapping resource data into a unified view reconciled with your CMDB.
* **Automated Scheduled Jobs:** Scheduled jobs automatically invoke integrations to keep your instance synchronized with the latest Microsoft Defender for Cloud data. These jobs can also be run manually.
* **Run-As User Configuration:** Integrations require a designated run-as user (default: VR.System) to prevent duplicate data attachments and ensure consistent data transformation.
* **Role-Based Access Control:** Specific roles are required to configure and view integrations, ensuring controlled access to sensitive integration data.
* **Identification and Reconciliation Engine (IRE):** Automatically creates new CIs in the CMDB when no existing match is found for imported hosts, enriching CMDB accuracy and completeness. Note that automatic reconciliation does not apply to cloud resources.

## Included Integrations

The base application includes several integrations that enrich compliance data by retrieving and processing specific Microsoft Defender for Cloud data sets:

* **Policy Definitions Integration:** Imports policy definitions and creates policy records.
* **Comprehensive Assessment Integration:** Retrieves assessment metadata and creates corresponding tests.
* **Compliance Standards \& Controls Integration:** Retrieves standards and controls, creates authorization sources and citations, and links them to tests.
* **Assessment Integration:** Imports assessment data and generates test results.
* **Assessment Metadata Integration:** Stores assessment metadata in a dedicated import table.
* **Container Image Vulnerabilities Integration:** Imports container image vulnerability data and creates vulnerability items in ServiceNow.

## Practical Benefits for ServiceNow Customers

* Gain continuous, automated visibility into cloud security posture directly within ServiceNow.
* Streamline compliance management by linking Microsoft Defender for Cloud findings to your CMDB and Configuration Compliance framework.
* Reduce manual data reconciliation by consolidating multiple Defender for Cloud deployments and automating CI creation for unmatched resources.
* Maintain data integrity and performance by adhering to run-as user configuration best practices.
* Enhance vulnerability and compliance workflows with up-to-date policy, assessment, and vulnerability data integrated into your ServiceNow environment.  
The Microsoft Defender for Cloud integrations included with the Microsoft Defender Integration for Security Exposure Management application import cloud misconfiguration findings, compliance data, and container image
vulnerabilities.
The Microsoft Defender Integration for Security Exposure Management application is available with a subscription from the ServiceNow Store.

The Microsoft Defender Integration for Security Exposure Management integrates with the Configuration Compliance application to map tests to configuration items (CIs) to create test results. It continuously discovers new cloud resources deployed across workloads and determines whether they are configured
according to security standards such as the Center for Internet Security (CIS).

## Multiple deployments of the Microsoft Defender for Cloud Platform {#cc_asc_overview__section_gdx_gxg_3rb}

If you have multiple deployments of the Platform application, you can add an integration for each deployment. Resources that are identified by multiple third-party deployments are consolidated and reconciled with your Configuration Management Database (CMDB). This consolidation takes place even when scan processes overlap between the multiple deployments.

## Integrations {#cc_asc_overview__section_ift_yxh_x1b}

The Microsoft Defender for Cloud integrations that are included with the Microsoft Defender Integration for Security Exposure Management application enrich the compliance data on your instance. These integrations retrieve data
from the Microsoft Defender for Cloud product. A series of scheduled jobs invokes the integrations automatically. You can also run these scheduled jobs manually. Scheduled jobs simplify the test results remediation life
cycle by keeping the instance synchronized with Microsoft Defender for Cloud.  
There is a configured run-as user for each integration record, with the default value VR.System. This value must remain the same.  
Note:  
If you don't set a valid run-as user, duplicate or multiple data retrieval attachments are created for the data source records. The number of attachments increases each time the integration is run. This increases the processing time, resulting in inconsistent transform results.  
The integration tasks require the following roles.

* sn_vul_msft_tvm.configure_integration: Ability to read, write, and delete records.
* sn_vul_msft_tvm.read_integration: Ability to read records.
{#cc_asc_overview__ul_vgz_3qj_v1b}

## Viewing the Microsoft Defender for Cloud Integrations {#cc_asc_overview__section_hj4_gxh_x1b}

You can view the integrations by navigating to AllMicrosoft Defender Integration for USEMAdministrationIntegrations.

The following integrations are included in the base system.  
{#cc_asc_overview__table_sbn_qtp_dt__entry__2}

| Integration | Description |
|-|-|
| Microsoft Defender for Cloud Policy Definitions Integration | Retrieves policies and creates policy entries in your instance. |
| Microsoft Defender for Cloud Comprehensive Assessment Integration | Retrieves assessment metadata and creates tests in your instance. |
| Microsoft Defender for Cloud Compliance Standards \& Controls Integration | Retrieves standards and controls and creates the authorization source and citations. It then links them to the tests created. |
| Microsoft Defender for Cloud Assessment Integration | Retrieves assessments and processes them in your instance. The output of this integration is test results. |
| Microsoft Defender for Cloud Assessment Metadata Integration | Retrieves assessment metada and stores it in the ASC Assessment Metadata Import \[sn_vul_msft_tvm_assesment_metadata_import\] table. |
| Container Image Vulnerabilities Integration | Retrieves vulnerabilities of Container Images and creates Container vulnerable items in your instance. |
[ ]

{#cc_asc_overview__table_sbn_qtp_dt}

## Create CIs using the Identification and Reconciliation Engine {#cc_asc_overview__section_ahn_2z2_4nb}

Use the Identification and Reconciliation Engine (IRE) to create CIs, when an existing CI cannot be matched with a host imported from a third-party scanner.  
If a CI is not matched in the CMDB, a CI is created in the cmdb_ci_cmp_resource class. Later, when a discovery finds the same CI, it enriches the CI or creates another one.  
Note:  
Automatic reconciliation does not happen for cloud resources.

*[\>]: and then


