---
sourceDocument: Store Version History Release Notes
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/store-release-notes

 Release :

    - store

ft:locale :

    - en-US

ft:publication_title :

    - Store Version History Release Notes

ft:clusterId :

    - rnst

bundleId :

    - rnst


---

# Microsoft Defender Incident ingestion integration for Security Operations release notes

# Microsoft Defender Incident ingestion integration for Security Operations release notes {#ariaid-title1}

Release version: Store  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Version history for the ServiceNow® Microsoft Defender Incident ingestion integration for Security Operations application on the ServiceNow Store.
Important:  
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

Version 4.1.1 - September 2026
:   Fixed: Close Code Mapping issues have been fixed.

Version 4.0.1 - May 2026
:
    * Fixed:
      * SIRs are not created from SIEM ingestion due to "Secure Notes" access issue to Crypto module since the Yokohama upgrade was fixed.
      * Access issues for Security Analyst on querying tables.
      * Security fixes.
      {#store-secops-rn-sir-ms-defender-incident-ingestion-int-sec-ops__ul_jgr_5rc_cjc}

Version 4.0.0 - March 2026
:   The Microsoft Defender integration for ServiceNow Security Operations ingests alerts and incidents into the ServiceNow Security Incident Response (SIR) platform for centralized case management. Bi-directional synchronization
    keeps status and work notes aligned across both platforms, ensuring teams working in either system maintain consistent information without discrepancies.

