---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Microsoft Threat and Vulnerability Management

# Understanding the Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Understanding the Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management

The Microsoft Threat and Vulnerability Management (TVM) integrations are part of the Microsoft Defender Integration for Security Exposure Management application, available via the ServiceNow Store.
These integrations enable you to prioritize and remediate vulnerabilities by importing vulnerability and asset data from Microsoft TVM into your ServiceNow AI Platform instance.
Vulnerability data is visualized through dashboards in the Security Exposure Management workspace to improve security exposure insights.
Show full answer Show less  

## Key Features

* **Domain Separation:** Supports importing vulnerability data into specified domains by assigning users accordingly, enabling domain-separated data management.
* **Vulnerable Items and Vulnerabilities:** Vulnerabilities imported from Microsoft TVM or other scanners are matched to Configuration Items (CIs) in your CMDB. Unmatched assets lead to creation of new CIs using the Identification and Reconciliation Engine (IRE).
* **Third-Party Vulnerability Entries:** Imports CVE and non-CVE vulnerability entries from Microsoft TVM and other scanners, leveraging exploit information for risk calculations.
* **Configuration Items (CIs) and Discovered Items:** Existing assets in your CMDB are matched with imported data; unmatched assets become new CIs in Unmatched CI classes. Discovered items show asset identification and mapping status.
* **CI Lookup Rules:** Automatically match machines/assets from Microsoft TVM data to CIs in your CMDB using lookup rules based on MAC address, FQDN, and IP address to ensure accurate vulnerability association.
* **Multi-Source and Multi-Instance Support:** Deploy multiple Microsoft TVM instances/integrations across environments to consolidate vulnerability data from various accounts.
* **Machine Tags:** Import and use machine (host) tags from Microsoft TVM for organizing assets and filtering in assignment and remediation rules. Tags are case-insensitive and controlled globally.
* **Scheduled and On-Demand Jobs:** Integrations run on configurable schedules or on-demand to update vulnerability, asset, and remediation data timely.

## Microsoft TVM Integrations Included

* **Microsoft TVM Recommendations Integration:** Daily retrieval of actionable security recommendations for remediation.
* **Microsoft TVM Vulnerability (CVE) Integration:** Daily import of national vulnerability database entries, third-party vulnerabilities, and exploit data.
* **Microsoft TVM Machines Integration:** Daily import of machine (asset) data including tags.
* **Microsoft TVM Machines Vulnerabilities Integration (Full Import):** Weekly import of all open vulnerabilities across assets, run automatically after machines import.
* **Microsoft TVM Machines Vulnerabilities Integration (Delta Import):** Daily import of changes such as new, fixed, or updated vulnerabilities.

## Roles and Permissions

To configure and manage the Microsoft TVM integrations, the following roles are required in the ServiceNow AI Platform instance:

* **admin:** Installs the Microsoft TVM application and assigns necessary roles.
* **snvul.vulnerabilityadmin:** Has full access to Vulnerability Response and configures integrations.
* **snvulmsfttvm.configureintegration:** Configures the Microsoft TVM integration.
* **snvulmsfttvm.readintegration:** Read-only access to Microsoft TVM integration records.
* **Vulnerability Response group:** Provides default access to read and remediation ownership roles.

## Practical Guidance for ServiceNow Customers

* After downloading the Microsoft TVM integration from the ServiceNow Store, use the Setup Assistant in Vulnerability Response to install and configure the integrations efficiently.
* Run the Microsoft TVM Machines integration before creating assignment or remediation rules to ensure all machine tags are available.
* Use CI lookup rules to accurately map imported vulnerabilities to existing assets, improving vulnerability management accuracy.
* Leverage machine tags for filtering and organizing assets but avoid using them as group keys in remediation task rules due to possible inconsistencies.
* Utilize scheduled jobs to keep vulnerability and asset data up-to-date and run jobs on-demand when immediate updates are needed.
* Manage domain-separated imports to maintain data segregation according to organizational structure.

## What to Expect

By integrating Microsoft TVM data into your ServiceNow environment, you gain enhanced visibility and control over vulnerabilities across your assets. The integration supports automated data imports, asset matching, and vulnerability grouping to streamline remediation workflows. This enables proactive risk management and efficient security exposure reduction within your enterprise.  
The Microsoft Threat and Vulnerability Management integrations are included with the Microsoft Defender Integration for Security Exposure Management application available with a subscription from the ServiceNow Store.
Prioritize and remediate vulnerabilities across your environment with vulnerability and asset data imported from the Microsoft Threat and Vulnerability Management integrations. You can view reports about vulnerabilities on the
dashboards in the Security Exposure Management workspace.

## Domain separation {#mstvm-integration__section_nxm_1vs_4xb}

Import vulnerability integration data to a specified domain by assigning a user in that domain to run the integrations. To create domain-separated imports for the integration, see [Create domain-separated imports for an integration](https://servicenow-prod.fluidtopics.net/0N9JZHv_nZJYrkMbQYSBbQ "If you require imported data to be in a specific domain, the user assigned to run the integrations must belong to that domain.").

## Terms and key features of the integrations {#mstvm-integration__section_gt5_xfv_wmb}

Vulnerable items and vulnerabilities
:   A vulnerable item is created in your ServiceNow AI Platform instance when:

    * An imported vulnerability from a third-party scanner is matched to an existing asset (configuration item) in your CMDB. The MS TVM product refers to these matches as "vulnerabilities".
    * An imported vulnerability from a third-party scanner is not matched to an existing asset in your CMDB. In this case, an unmatched configuration item (CI) is also created with a vulnerable item.

      Use the Identification and Reconciliation Engine (IRE) to create CIs in
      two new classes when an existing CI can't be matched with a host. Otherwise, unmatched CIs are created in the Unmatched CI classes. For more information, see [Creating CIs using the Identification and Reconciliation engine](https://servicenow-prod.fluidtopics.net/DbogQZg9imYEow6lfHeXHQ "You can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB.").
    {#mstvm-integration__ul_nh4_kr3_3nb}

Third-party vulnerability entries
:   Third-party vulnerability entries are imported from third-party scanners such as MS TVM and are listed in the Third-Party Vulnerability Entries table in your ServiceNow AI Platform instance. Also, National Vulnerability Database entries (CVEs) are imported from MS TVM. The exploit information that is associated with both these types of entries comes from MS TVM. This
    exploit information can be used for risk calculation.  
    Note:  
    A third-party vulnerability is retrieved only for vulnerabilities that don't have a CVE assigned to them. MS TVM can add a temporary name for the vulnerability, for example, `TVM-XXXX-XXXX`. This name is updated after a CVE ID is assigned.

Configuration item (CI)
:   CIs are the existing assets that are listed in your CMDB.

Discovered item
:   Discovered items are the assets that are ingested from the MS TVM machine import that match existing CIs in your CMDB.

    If a match is not found, a CI is created in the Unmatched CI class of the CMDB. Enable the CMDB CI Class Models plugin, the Identification and Reconciliation Engine (IRE) creates CIs by using new classes. For more information, see [Creating CIs using the Identification and Reconciliation engine](https://servicenow-prod.fluidtopics.net/DbogQZg9imYEow6lfHeXHQ "You can create configuration items (CIs) in the Configuration Management Database (CMDB) using the Identification and Reconciliation engine (IRE) API. By using the IRE API to create CIs, you can prevent duplicate CIs from being created and you can reconcile CI attributes by allowing only authoritative data sources to write to CMDB."). If the original, unmatched CI is reclassified, the discovered item records are updated to reflect that state. Discovered items give you visibility into how assets are identified
    and mapped to CIs in the CMDB.

CI lookup rules
:   When data is imported from MS TVM, Vulnerability Response automatically uses machine (asset) data to search for matches in the CMDB. CI lookup rules are used to identify CIs and to add them to VI records when VIs are created.

Instance
:   An instance refers to multiple accounts of MS TVM. Each account can be an instance in the MS TVM application.

Integration
:   An integration is a scheduled job that retrieves information from a third-party source, such as the integration of the MS TVM machines.

Deployment
:   When an integration supports multi-source, a single integration existence is referred to as a deployment of your integration. A deployment refers to the integrations and products across your environment. For example,
    you might have multiple deployments of MS TVM in your environment.

The MS TVM integration also includes the following key features:

* Identify the assets across your environment and update the CIs on your existing discovered items, vulnerable items, and detection records to give you more details about your vulnerabilities.
* Schedule when you want the jobs to run for all the MS TVM integrations. You can also execute scheduled jobs on-demand.
* Group vulnerable items.
* Configure CI lookup rules to define how the asset data from third-party sources is used to identify CIs in your CMDB.
{#mstvm-integration__ul_hs1_f3v_wmb}

## Required ServiceNow AI Platform roles {#mstvm-integration__section_plr_nfg_tlb}

The integration tasks require the following roles in your ServiceNow AI Platform instance.

admin
:   The admin uses Setup Assistant to install the MS TVM application. If not assigned, the admin assigns the vulnerability admin (sn_vul.vulnerability_admin) and other roles in Setup Assistant.

sn_vul.vulnerability_admin
:   Once assigned, the vulnerability admin completes the configuration of the MS TVM integrations in Setup Assistant. This role has complete access to the Vulnerability Response application and its records. The vulnerability admin configures all Vulnerability Response applications and rules for installed third-party integrations.

sn_vul_msft_tvm.configure_integration

:   This role contains the `sn_vul_msft_tvm.read_integration` granular role. Users with this role can configure the  Vulnerability Response Integration with the Microsoft Threat and Vulnerability Management
    application.

sn_vul_msft_tvm.read_integration

:   Users with this role can only view the  Vulnerability Response Integration with the Microsoft Threat and Vulnerability Management application records.

Vulnerability Response group
:   By default, the Vulnerability Response group is available in Setup Assistant. Users assigned to the Vulnerability Response group inherit the sn_vul.read_all and sn_vul.remediation_owner roles automatically.

## MS TVM integrations {#mstvm-integration__section_v24_cth_tlb}

Multi-source is supported for all the MS TVM integrations. You can add and deploy multiple instances of the following integrations across your environment from Setup Assistant in Vulnerability Response.

Navigate to Microsoft Defender Integration for USEMAdministrationIntegrations to view the MS TVM integrations included with the Microsoft Defender Integration for Security Exposure Management application. Vulnerability Response provides integrations with MS TVM end points to import the data according to the scheduled time intervals. The following integrations are included in the base system.  
{#mstvm-integration__table_o1x_dth_tlb__entry__4}

| Run sequence | Schedule | Integration | Description |
|-|-|-|-|
| 1 | Daily | Microsoft TVM Recommendations Integration | Retrieves a list of all the actionable security recommendations to remediate the vulnerabilities. |
| 2 | Daily | Microsoft TVM Vulnerability (CVE) Integration | Retrieves a list of the national vulnerability database entries and third-party vulnerability entries, and their exploit information. |
| 3 | Daily | Microsoft TVM Machines Integration | Retrieves all asset (machine) data, including machine tags, from the Microsoft TVM and processes it in your instance. |
| 4 | Weekly Note: After installation, this integration is run automatically after the machines import. | Microsoft TVM Machines Vulnerabilities Integration (Full Import) | Retrieves all the open vulnerabilities on all the assets. |
| 5 | Daily | Microsoft TVM Machines Vulnerabilities Integration (Delta Import) | Retrieves all the information that has changed in the full vulnerability import of the organization, including the new, fixed, and updated vulnerabilities. |
[Table 1. MS TVM integrations]

{#mstvm-integration__table_o1x_dth_tlb}

Vulnerable items are grouped into remediation tasks according to the group rules that you set and are assigned for remediation based on your assignment rules. For more information, see [Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.") and .

## CI lookup rules {#mstvm-integration__section_otj_5hz_2mb}

When data is imported from MS TVM, Vulnerability Response automatically uses machine (asset) data to search for matches in the Configuration Management Database (CMDB). CI lookup rules are used to identify CIs and add them to VI records when VIs are created. For more information on how CI lookup rules work, see [Create a Vulnerability Response CI lookup rule](https://servicenow-prod.fluidtopics.net/DQQBP6USedqPaEVrEOS8cg "The CI Lookup Rules module contains rules that are used to find the matching record for host information received during third-party vulnerability integration imports. The host information is matched with the discovered items, unmatched configuration item classes, and the Configuration Management Database (CMDB).").  
Note:  
Once you remove a rule, you can't recover it. Instead of removing an existing rule, you should disable it.  
The following MS TVM lookup rules are shipped with the base system:

* MAC_ADDRESS
* FQDN
* IP
{#mstvm-integration__ul_l1g_r3z_2mb}  
Note:  
You can use multiple values for the IP_ADDRESS and MAC_ADDRESS of an asset. A CI lookup rule considers all values for matching.

## Discovered items {#mstvm-integration__section_p24_2jz_2mb}

You can see the CIs that were detected during an import from the MS TVM Machines integration.  
Note:  
The default filter for this list is set to Unmatched. You can view all discovered items from an import by removing the filter.
For more information, see [Discovered Items](https://servicenow-prod.fluidtopics.net/eCeTriYKp1Wkq_Ym33tczQ "Assets are automatically matched to configuration items (CIs) in the Configuration Management Database (CMDB) when they are imported using CI Lookup Rules. Discovered Items give you visibility into how asset identification is mapped to CIs in the CMDB.").

## Machine tags {#mstvm-integration__section_ddd_vjz_2mb}

Machine tags, also known as host tags, are used for organizing and tracking the assets in your organization. You assign tags to your machines.  
All machine tags are imported as part of the MS TVM Machines integration. Machine tags are generally used for filtering in Vulnerability Response assignment rules and remediation task rules. The tags are displayed in the Discovered Item form.  
Note:  
Run the MS TVM Machine integration before you create Vulnerability Response assignment or remediation task rules in the Vulnerability Response application so that all tags are available for these rules before vulnerable items are imported and grouped. Also note the following points about tags:

* Tag storage is not case sensitive. If a Paris tag is created, then a PARIS tag cannot be stored in the Machine tag table. <kbd class="ph userinput">Paris</kbd> and <kbd class="ph userinput">PARIS</kbd> are considered to be the same machine tag by the system. Whichever tag is imported first is the tag that is stored and recognized.
* Using machine tags as a group key in a remediation task rule may have unexpected results. Group keys are columns in the remediation tasks table, whereas machine tags are intended for use only in the condition builder.
* Machine tags are controlled by the global sn_vul.import_host_tags system property. This property is set to true by default. Disabling tags disables them across all ServiceNow AI Platform® instances.
{#mstvm-integration__ul_xfb_pkz_2mb}

## What to do next {#mstvm-integration__section_yz3_vdg_4nb}

After you download the Vulnerability Response integration with Microsoft Threat and Vulnerability Management from the ServiceNow® Store, installation and configuration are supported by Setup Assistant in Vulnerability Response. For more information, see [Install and configure the Microsoft TVM integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/_4JEVEZ2UqTxWFrzov1j_g "Install, activate, and configure the Microsoft TVM integrations for the Microsoft Defender Integration for Security Exposure Management with the Setup Assistant.").

*[\>]: and then


