Connect ServiceNow ITSM to Defender for Cloud

Microsoft Defender for Cloud's integration with ServiceNow's IT Service Management (ITSM) module, allows customers to connect their Defender for Cloud accounts to ServiceNow. ServiceNow is a powerful workflow automation and enterprise solution that helps organizations streamline and automate routine tasks, improving operational efficiencies and increasing productivity. By integrating ServiceNow with Defender for Cloud, customers can prioritize the remediation of recommendations that affect their business. This integration allows you to create and view ServiceNow tickets linked to recommendations directly from Defender for Cloud, which facilitates efficient incident management.

Prerequisites

Connect a ServiceNow account to Defender for Cloud

To connect a ServiceNow account to a Defender for Cloud account:

  1. Sign in to the Azure portal.

  2. Navigate to Microsoft Defender for Cloud > Environment settings.

  3. Select Integrations.

    Screenshot of environment settings page that shows where to select the ServiceNow option.

  4. Select Add integration > ServiceNow.

    Screenshot that shows where the add integration button is and the ServiceNow option.

  5. Enter a name, select the scope, enter the instance URL, User name, Password, Client ID, and client secret that you created for the application registry in the ServiceNow portal.

  6. Select Next.

  7. Select Incident data, Problems data, and Changes table from the drop-down menus.

    Screenshot that shows the custom option selected and the accompanying fields you can enter information into.

  8. Select Save.

A notice appears after successful creation of integration.

Next step