Create automatic tickets with governance rules

The integration of ServiceNow and Defender for Cloud allow you to create governance rules that automatically open tickets in ServiceNow for specific recommendations or severity levels. ServiceNow tickets can be created, viewed, and linked to recommendations directly from Defender for Cloud, enabling seamless collaboration between the two platforms and facilitating efficient incident management.

Prerequisites

Assign an owner with a governance rule

You can create a rule to automatically assign an owner to a recommendation in Defender for Cloud. This rule is based on the recommendation's severity or recommendation.

  1. Sign in to the Azure portal.

  2. Navigate to Microsoft Defender for Cloud > Environment settings.

  3. Select Governance rules.

    Screenshot of the environment settings page that shows where the governance rules button is located.

  4. Select Create governance rule.

  5. Enter a rule name and select a scope.

  6. Select ServiceNow In the Type field.

  7. Enter a priority.

  8. Select and integration instance.

  9. Select a ServiceNow ticket type.

  10. Select Next.

  11. Select either:

    • By Severity and the severity level.
    • By recommendation and the recommendation.
  12. Select an owner.

  13. Select a remediation timeframe.

  14. (Optional) Toggle the switch to apply a grace period.

  15. (Optional) Set email notifications.

  16. Select Create.

Next step