---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Set up Microsoft Azure for the MS TVM integration

# Set up Microsoft Azure for the MS TVM integration {#ariaid-title1}

* Release version: Australia
* 
* Updated July 29, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Set up your account in the Microsoft Azure portal to access the Microsoft Threat and Vulnerability Management (MS TVM) API remotely. You need this account to access the MS TVM tenant to gather information for machines, vulnerabilities, and
security recommendations.

## Before you begin

Role required: Microsoft Azure portal administrator

## About this task

Complete the following setup tasks in your Microsoft Azure portal before you activate the ServiceNow® application for this integration.

To verify that you have access to the most current content, see the [Microsoft documentation](https://docs.microsoft.com) website. If you have not created an application ID for OAuth 2.0 authentication in the Microsoft Azure portal, follow the steps in this procedure.

## Procedure

1. Log in to the Microsoft Azure portal using your Azure portal administrator credentials.
2. In the left navigation panel on the Home pane, select Azure Active Directory.
3. In the Overview pane, select App Registrations (Preview).
4. In the App registrations (Preview) pane, select New Registration.  
   The Register an application form is displayed.
5. Complete the fields on the form.  
   {#mstvm-azure-account__table_qtm_nnf_mgb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the application. In this example, <kbd class="ph userinput">ServiceNow MS TVM Integration</kbd> is entered. |
   | Supported account types | For this account, in Supported account types, select Accounts in this organizational directory only (ServiceNow only - Single tenant). |
   | Redirect URL (optional) | If you enter a value in this field, the integration does not use it. |
   [Table 1. Register an application form]

   {#mstvm-azure-account__table_qtm_nnf_mgb}
6. Select Register.  
   The Application (client) ID and Directory (tenant) ID are created. Enter these values on the configuration page in the Client ID and Tenant ID fields during the configuration step in the ServiceNow VR-TVM integration Setup Assistant. This step is described in [Install and configure the Microsoft TVM integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/_4JEVEZ2UqTxWFrzov1j_g "Install, activate, and configure the Microsoft TVM integrations for the Microsoft Defender Integration for Security Exposure Management with the Setup Assistant.").
7. When you see the Application (client) ID displayed in the ServiceNow MS TVM Integration pane, select View API Permissions.
8. Navigate to Request API permissionsAPIs my organization uses, and then select Windows Defender ATP.
9. In the ServiceNow MS TVM Integration - API permissions pane, select Add a Permission.
10. Include access for the following roles.  
    * Machine.Read.All
    * Machine.ReadWrite.All

    {#mstvm-azure-account__ul_lyr_mfc_zjc}

    For more information see [Microsoft Defender for Endpoint products and services](https://learn.microsoft.com/en-us/defender-endpoint/api/get-machines#permissions).
11. Provide read access to machines, vulnerabilities, and security recommendations.
12. Select Grant Admin Consent for \<your organization name\>.  
    Note:  
    To authenticate as an application from a ServiceNow instance, complete the following steps:
    1. Navigate to Servicenow MS TVM IntegrationCertificates \& Secrets, and then select New Client secret.
    2. Complete the fields on the form.{#mstvm-azure-account__table_kwn_cdh_rpb__entry__2}

       | Field | Description |
       |-|-|
       | Description | Name of the application. |
       | Expires | Date of expiry. |
       [Table 2. Client secrets form]

       {#mstvm-azure-account__table_kwn_cdh_rpb}
    3. Select Add.

       The Value field is populated with the new client secret, which is your new password.  
       Note:  
       You need this password when you configure the integration in your ServiceNow AI Platform instance. For more information, see [Install and configure the Microsoft TVM integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/_4JEVEZ2UqTxWFrzov1j_g "Install, activate, and configure the Microsoft TVM integrations for the Microsoft Defender Integration for Security Exposure Management with the Setup Assistant.").
    4. Save this password in a secure location. After you leave this page, this password is not available.You have successfully created an application ID for authentication in the Microsoft Azure portal.

    {#mstvm-azure-account__ol_plb_rbr_qpb}

## What to do next

You're ready to set up your ServiceNow AI Platform® instance for the integration.

*[\>]: and then


