Integrating MDC, Sentinel and Azure monitor with ServiceNow

Brynel Peter Libera (CONVERGYS CORPORATION) 40 Reputation points Microsoft Vendor
2025-01-22T06:58:47.3633333+00:00

I want to integrate MS sentinel, MDC, & Azure Monitor with ServiceNow tool. the ServiceNow team has used/created the domain separation in the ServiceNow. In the sentinel integration document, it has been mentioned that domain separation is not supported as a limitation. I want to know if it is true and also to know if there is any work around. Also is there any limitation like this for integration of MDC and azure monitor to service now. 

Azure Monitor
Azure Monitor
An Azure service that is used to collect, analyze, and act on telemetry data from Azure and on-premises environments.
3,428 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,473 questions
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,210 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Rahul Podila 1,395 Reputation points Microsoft Vendor
    2025-01-23T09:35:48.2966667+00:00

    Hi @Brynel Peter Libera (CONVERGYS CORPORATION)

    Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.

    Microsoft Sentinel does not support domain partitions at all in ServiceNow. The main issue is that domain partitions create different “zones” in ServiceNow, and Sentinel’s data does not reside in the correct zone. This can lead to inadvertent data discovery in the domain, which can lead to security concerns.

    The best solution to solve this is to create a custom integration using ServiceNow's REST API, which allows you to control how the data is transferred and make sure it goes to the right domain. You can also create a Scoped Application in ServiceNow to help better isolate data. It is highly recommended that you test this site first to avoid any problems.

    On the other hand, integrating Microsoft Defender for Cloud (MDC) and Azure Monitor with ServiceNow does not present the same issues as domain partitions. However, you will still want to ensure that the data from these tools is correctly sent to the correct domain. You can usually solve this with ServiceNow’s built-in connectors or APIs.

    If you have any concerns, please go through this link: -

    https://learn.microsoft.com/en-us/azure/sentinel/configure-data-connector?tabs=azure-portal

    If you have any further queries, do let us know


    If the answer is helpful, please click "Accept Answer" and "Upvote it"

    1 person found this answer helpful.
    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.