---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Prepare for installation and configuration

# Set up Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated July 29, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Set up Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management

This guide outlines the preparation steps required to install and configure Microsoft Threat and Vulnerability Management (MS TVM) Vulnerability integrations within ServiceNow's Security Exposure Management.
These integrations enable the import and management of vulnerability data from Microsoft Defender into your ServiceNow AI Platform® instance, enhancing your vulnerability response capabilities.
Show full answer Show less  

## Preparation Checklist

Before installing the MS TVM integration, ensure the following:

* **Microsoft Account Credentials:** Obtain either ClientSecret, ClientId, and TenantId or Username, Password, ClientId, and TenantId for your MS TVM account. These credentials are necessary for integration setup.
* **Vulnerability Response Application:** Verify that the Vulnerability Response application is installed and activated, as it includes the Setup Assistant used to configure MS TVM integrations.
* **Integration Application:** Download and install the Microsoft Defender Integration for Security Exposure Management from the ServiceNow® Store if not already present.
* **Instance Capacity:** Estimate the number of vulnerable items you expect to import and confirm your ServiceNow instance can handle this volume to avoid performance issues. Contact ServiceNow Technical Support if unsure.
* **Roles and Groups:** Ensure necessary roles and user groups are assigned for integration management and remediation:
  * **admin:** Uses Setup Assistant to install and assign roles like Vulnerability Admin.
  * **Vulnerability Admin (snvul.vulnerabilityadmin):** Manages Vulnerability Response configurations and third-party integrations.
  * **MS TVM Integration Configurator (snvulmsfttvm.configureintegration):** Configures the MS TVM integrations.
  * **MS TVM Integration Reader (snvulmsfttvm.readintegration):** Views MS TVM integration records.
  * **Vulnerability Response Group:** Automatically provides users with read and remediation roles; consider creating additional user groups as needed.
* **Vulnerability Response Persona Roles:** Assign persona and granular roles through Setup Assistant to control user access and capabilities.
* **Existing Integrations:** Install the Vulnerability Response integration with the National Vulnerability Database (NVD) and run the NIST National Vulnerability Database Integration API to support CVE data.
* **Performance Optimization:** To improve initial import performance, consider disabling unused vulnerability calculators and notification-related business rules that may generate excessive notifications during data ingestion.

## Next Steps

Once the above preparations are complete, proceed with installing and configuring the Microsoft TVM integrations using the Setup Assistant within the Vulnerability Response application to enable seamless vulnerability data import and management.  
Prepare for the integration installation and configuration by performing setup tasks.

## Before you begin {#mstvm-prep-checklist__section_dsn_4dz_slb}

Use this checklist to verify the items listed are completed before you install the application and import vulnerability data into your ServiceNow AI Platform® instance.  
{#mstvm-prep-checklist__table_qby_jng_tlb__entry__2}

| Task | Description |
|-|-|
| ![Checkbox image.]() | Verify that you have one of the following sets of information: * ClientSecret, ClientId, and TenantId for your MS TVM account * Username, Password, ClientId, and TenantId for your MS TVM account. To obtain this information, see [Set up Microsoft Azure for the MS TVM integration](https://servicenow-prod.fluidtopics.net/5~371BIKzVdVsMnN50UqWg "Set up your account in the Microsoft Azure portal to access the Microsoft Threat and Vulnerability Management (MS TVM) API remotely. You need this account to access the MS TVM tenant to gather information for machines, vulnerabilities, and security recommendations."). {#mstvm-prep-checklist__ul_tz4_lb2_tpb} |
| ![Checkbox image.]() | If not already installed and activated, install the Vulnerability Response application before you install the third-party application. The Setup Assistant you use to configure the integrations is included with the Vulnerability Response application. For more information about installing and activating the Vulnerability Response application, see [Install Vulnerability Response](https://servicenow-prod.fluidtopics.net/sB5D1~3XOF2DyOX7hmc5dA "Before you run the Vulnerability Response application in your ServiceNow AI Platform instance, you must get entitlement and download the application from the ServiceNow Store, install it on your ServiceNow AI Platform instance, and activate it."). |
| ![Checkbox image.]() | If you don't already have the application from the ServiceNow® Store, get entitlements and download the Microsoft Defender Integration for Security Exposure Management application to your ServiceNow AI Platform® instance. |
| ![Checkbox image.]() | Estimate the number of vulnerable items that you expect to import. Verify that your instance can accept the number of vulnerable items that you expect to import. An undersized instance can lead to long load times. If you don't know the size of your instance, or if you need assistance, contact ServiceNow® Technical Support. |
| ![Checkbox image.]() | Verify that you have the following groups or users to manage the integrations and to remediate vulnerable items: admin :   Uses Setup Assistant to install the MS TVM integrations included with the Microsoft Defender Integration for Security Exposure Management application. If not assigned, the admin assigns the Vulnerability Admin (sn_vul.vulnerability_admin) and other roles in Setup Assistant. sn_vul.vulnerability_admin :   Completes the configuration of the MS TVM integrations. This role has complete access to the Vulnerability Response (VR) application and its records. This admin configures all VR applications and rules and configures third-party integrations. sn_vul_msft_tvm.configure_integration :   Configures the MS TVM Vulnerability integrations. This role contains the sn_vul_msft_tvm.read_integration granular role. sn_vul_msft_tvm.read_integration :   Views (reads) records of the MS TVM Vulnerability integrations. Vulnerability Response group :   By default, the Vulnerability Response group is available in Setup Assistant. Users assigned to the Vulnerability Response group inherit the sn_vul.read_all and sn_vul.remediation_owner roles automatically. If not already created, you may prefer to create additional groups and add users with the User Administration module in your instance before you use Setup Assistant. For more information, see [Create a user group](https://www.servicenow.com/docs/access?context=t_CreateAGroup&version=australia&pubname=australia-platform-administration&ft:locale=en-US). Persona and granular roles are available to help you manage what users can do and see in the Vulnerability Response application. For initial assignment of the persona roles in Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://servicenow-prod.fluidtopics.net/msi8kaFkGNjyRib_XBHEzQ "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant."). |
| ![Checkbox image.]() | Install the Vulnerability Response integration with NVD and run the NIST National Vulnerability Database Integration - API (CVE only). |
| ![Checkbox image.]() | To promote improved performance for your first import, you can disable certain features, rules, or jobs in your instance. * Disable vulnerability calculators if you do not use them. These calculators, plus any that you have defined, run every time a vulnerable item record is created or updated. For more information, see [Disable the default vulnerability calculator if not used](https://servicenow-prod.fluidtopics.net/sDN2nVipLAp_nVt88Abf6w "If you do not use vulnerability calculators, disable the default calculator, in addition to any others you have defined. Vulnerability calculators run every time a vulnerable item record is created or updated, and can impact initial import performance."). * During the initial import of records, certain notification-related business rules can cause many notifications to be generated, which could impact the performance of the ingestion. {#mstvm-prep-checklist__ul_x3x_gvg_tlb} |
[Table 1. Integration preparation checklist]

{#mstvm-prep-checklist__table_qby_jng_tlb}

You are ready to [Install and configure the Microsoft TVM integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/_4JEVEZ2UqTxWFrzov1j_g "Install, activate, and configure the Microsoft TVM integrations for the Microsoft Defender Integration for Security Exposure Management with the Setup Assistant.").

