Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
The integration of ServiceNow's IT Service Management (ITSM) module and Defender for Cloud allow you to create governance rules that automatically open tickets in ServiceNow for specific recommendations or severity levels. ServiceNow tickets can be created, viewed, and linked to recommendations directly from Defender for Cloud, enabling seamless collaboration between the two platforms and facilitating efficient incident management.
Prerequisites
Before you create governance rules, make sure you meet the following requirements:
Have an application registry in ServiceNow.
Enable Defender Cloud Security Posture Management (CSPM) on your Azure subscription.
Admin permissions to ServiceNow to create an assignment.
Assign an owner with a governance rule
You can create a governance rule to automatically assign an owner to a recommendation in Defender for Cloud. The rule can be based on either the recommendation's severity or a specific recommendation.
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Environment settings.
Select Governance rules.
Select Create governance rule.
Enter a rule name and select a scope.
Select ServiceNow In the Type field.
Enter a priority.
Select and integration instance.
Select a ServiceNow ticket type.
Select Next.
Select either:
- By Severity and the severity level.
- By recommendation and the recommendation.
Select an owner.
Select a remediation timeframe.
(Optional) Toggle the switch to apply a grace period.
(Optional) Set email notifications.
Select Create.
Next steps
Learn more about cloud security posture management: