---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Configure the MS TVM Vulnerability Integration using Setup Assistant

# Configure the MS TVM Vulnerability Integration using Setup Assistant {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Configure the Vulnerability Response integration with Microsoft Threat and
Vulnerability Management (MS TVM) application, after you install it using the Setup
Assistant.

## Before you begin

In addition to the instructions and prompts that are provided in Setup Assistant for the Vulnerability Response integration with Microsoft Threat and Vulnerability Management integration, do the following actions:

* Verify that you have already installed the application before you begin. For more information, see [Install Vulnerability Response third-party applications using Setup Assistant](https://servicenow-prod.fluidtopics.net/4SVUHu2n7I65KBpfqP4EBg "Install the third-party integration applications you have entitlement for in Vulnerability Response using the Setup Assistant.").
* See [Set up Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management](https://servicenow-prod.fluidtopics.net/fV0EgfwHBVhdkKfPFKkeXg "Prepare for the integration installation and configuration by performing setup tasks.") for more information before you configure the Microsoft Threat and Vulnerability Management integration for Vulnerability Response.
* Verify that you have MS TVM account credentials available. To obtain these credentials, see [Set up Microsoft Azure for the MS TVM integration](https://servicenow-prod.fluidtopics.net/5~371BIKzVdVsMnN50UqWg "Set up your account in the Microsoft Azure portal to access the Microsoft Threat and Vulnerability Management (MS TVM) API remotely. You need this account to access the MS TVM tenant to gather information for machines, vulnerabilities, and security recommendations.").
{#mstvm-vr-config-in-SA__ul_gg2_lt4_ymb}

Roles required: System Admin (admin) for installation, Vulnerability Admin
(sn_vul.vulnerability_admin) or sn_vul.admin (deprecated), and Configure Integration
(sn_vul_msft_tvm.configure_integration) for configuration

## Procedure

1. Navigate to AllVulnerability ResponseAdministrationSetup AssistantIntegration ConfigurationScanner Integrations.  
   The Microsoft Threat \& Vulnerability Management tile is displayed.

   MS TVM is a multi-source integration, which means that you can have multiple
   deployments of the same third-party integration. The settings from your
   original third-party integration are used as a template for the settings of
   each new integration.  
   Note:  
   If you delete the original vulnerability integration, you have to select another integration to use as your template. Consider disabling the integration instead of deleting it. Integrations created from disabled templates are disabled by default.

   Data from each third-party integration is uniquely identified and available
   in a single instance of Vulnerability Response.
2. To configure the Microsoft Threat and Vulnerability Management integration, select Edit.
3. On the form, fill in the fields.  
   {#mstvm-vr-config-in-SA__table_wjl_wks_4pb__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name of the instance. |
   | TVM region | Region close to your server location. Use the server nearest to your location for optimal performance of the API. |
   | Authentication type | Method to verify the identity. User authentication controls the visibility of specific assets to specific users. MS TVM exports the device groups that are entitled for this user. The default value is Application. |
   | Tenant ID | Tenant identity of your organization. |
   | Client ID | Client identity that is generated after registering MS TVM in Microsoft Azure. |
   | Username | User that has access to the complete device group. This field appears only when User is selected from the Authentication type. |
   | Password | Password for the username that has access to the complete device group. This field appears only when User is selected from the Authentication type. |
   | Client secret | Client secret that is generated after registering the MS TVM application. This field appears only when Application is selected from the Authentication type. |
   [Table 1. Account Credentials form]

   {#mstvm-vr-config-in-SA__table_wjl_wks_4pb}
4. To save your changes and proceed to the first integration form, select Next.  
   The Vulnerabilities Import Configuration form is displayed.
5. Enable or disable the vulnerabilities import, determine the initial start date for the vulnerabilities that you want imported, and schedule when the MS TVM Vulnerabilities import should run.  
   If you want to import all the vulnerabilities, leave the initial start date blank.
   1. To import data on-demand, select Import Vulnerabilities Now.
   2. To see the integration record, select Advanced Settings.
   {#mstvm-vr-config-in-SA__ol_rj3_hrf_5pb}
6. To save your changes and proceed to the first integration form, select Next.  
   The Recommendations Import Configuration form is displayed.
7. Enable or disable the recommendations import and determine the schedule when the MS TVM Vulnerabilities import should run.  
   1. To import data on-demand, select Import Recommendations Now.
   2. To see the integration record, select Advanced Settings.
   {#mstvm-vr-config-in-SA__ol_fm5_ttf_5pb}
8. To save your changes and proceed to the first integration form, select Next.  
   The Machines Import Configuration form is displayed.
9. Enable or disable the Machines Import, determine the initial start date for the machines that you want imported, and schedule when the MS TVM Machines import should run.  
   If you want to import all the machines, leave the initial start date blank.  
   Note:  
   Machine tags are imported by default and used for organizing and tracking the machines listed in the MS TVM environment.
   1. To display the default configuration item (CI) lookup rules, click CI Lookup rules. CI Lookup Rules define how machine data from third-party sources are used to identify Configuration Items (CI)s in the ServiceNow AI Platform CMDB. You have the option to add lookup rules or modify the default CI lookup rules on this page. For more information, see [Create a Vulnerability Response CI lookup rule](https://servicenow-prod.fluidtopics.net/DQQBP6USedqPaEVrEOS8cg "The CI Lookup Rules module contains rules that are used to find the matching record for host information received during third-party vulnerability integration imports. The host information is matched with the discovered items, unmatched configuration item classes, and the Configuration Management Database (CMDB).").
   2. To import data on-demand, click Import Machines Now.  
      Note:  
      Machines that have the status as onboarded in MS TVM are retrieved by the ServiceNow application.
   3. To see the integration record, select Advanced Settings.
   {#mstvm-vr-config-in-SA__ol_htv_g1g_5pb}
10. To save your changes and go to the first integration form, select Next.  
    The Machine Vulnerabilities Import Configuration form is displayed.
11. Enable the following integrations and determine the initial start date for the vulnerabilities that you want imported.  
    {#mstvm-vr-config-in-SA__table_qnb_3ns_4pb__entry__2}

    | Integration | Description |
    |-|-|
    | Microsoft TVM Machine Vulnerabilities Delta Import | Retrieves vulnerabilities that have been updated during the full vulnerability import, including new, fixed, and updated vulnerabilities. You can only import delta data for the past 14 days. |
    | Microsoft TVM Machine Vulnerabilities Full Import | Retrieves all the open vulnerabilities. Due to the high volume of data import, you can schedule it to run weekly. |
    [Table 2. Machine Vulnerabilities Import Configuration form]

    {#mstvm-vr-config-in-SA__table_qnb_3ns_4pb}  
    Note:  
    Run the machines import before the Machine Vulnerabilities integration. Otherwise, VITs aren't created for the missing machines.
12. To save your changes and complete the configuration in Setup Assistant, select Finish.

## What to do next

If you want to activate a vulnerable item grouping in the classic environment, navigate to Vulnerability ResponseAdministrationRemediation Task RulesMicrosoft TVM Recommendation.

In the form that is displayed, select the
Active option to activate it. Alternatively, select
New to create a new rule.

For more information, see
[Vulnerability Response remediation tasks and remediation task rules overview](https://servicenow-prod.fluidtopics.net/a7Z9DVk5024DYfVdfELq8A "Configure remediation tasks (VULs) to help analysts and remediation specialists organize vulnerable items (VI) and analyze them in bulk. The criteria by which remediation tasks are formed is configured so that you do not have to manually assign vulnerable items into remediation tasks. Using remediation tasks, you can monitor progress and drive the remediation process more efficiently.").

*[\>]: and then


