- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
on 03-25-2026 08:05 AM
We are excited to announce the general availability of the Microsoft Defender Incident ingestion integration with ServiceNow Security Incident Response (SIR). This integration brings unified, bi-directional alert and incident synchronization between Microsoft's modern security operations hub and SIR thus enabling your SOC to work faster without context-switching between platforms. You can find the integration in the store here.
Alongside this launch, we are also releasing a migration utility to help existing customers who have integrated Microsoft Sentinel on Azure Portal with SIR to move to this new Defender Portal integration with minimal disruption.
Why you should migrate?
Microsoft extended the original July 2026 deadline to March 31, 2027 based on customer feedback, giving organizations additional runway. However, Microsoft has made clear that all new capabilities are being delivered exclusively in the Defender Portal.
How does the migration utility help?
To ease the transition for our existing customers, we have built a migration Utility, available post you install the Microsoft Defender Incident ingestion integration app. The utility handles the most complex parts of the migration for you as below -
- run pre-migration assessment to validate your transition of your Microsoft Sentinel environment to the Defender portal
- Profile migration from your Sentinel integration to the newly authenticated Defender portal integration
- Incident mapping to help identifies active Sentinel incidents associated with the migrated profile and prepare corresponding mappings with the Defender incidents to ensure continuity with any update on those incidents
We have published a detailed KB article which you can access here.
If you have any issues or need more information, please contact our support team or reach out to your account team; we'll be happy to help.
- 785 Views
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
We have deployed this Microsoft Defender Incident ingestion integration, but we are dissatisfied with the to import mapping to the SIR record.
We are using the Security Operations Workspace and I have been unable to find suitable mapping from the imported defender records.
I am not able to access the link to KB2795226. (Image Attached).
Is anyone able to send me the content please? (I hope this contains more details than the information provide on the production pages).
Thanks.
Charles.
- Mark as Read
- Mark as New
- Bookmark
- Permalink
- Report Inappropriate Content
Hi @charles2024 , I do not see an image attached; could you retry with this link (you would need to be a logged in user to access this).
In the meantime, if you are still facing issue with the mapping, do raise a support ticket here and we would help you out.
Sudipta
