---
sourceDocument: Xanadu Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/security-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Install and configure the Microsoft Azure Sentinel integration

# Install and configure the Microsoft Azure Sentinel integration {#ariaid-title1}

* Release version: Xanadu
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install and configure the Microsoft Azure Sentinel integration from
the ServiceNow Store on your ServiceNow AI Platform instance to start ingesting
Azure Sentinel incidents.

## Before you begin

Role required: sn_si.ingestion_profile_admin  
Note:  
Users with the sn_si.admin role can perform all operations available to a profile admin, as the sn_si.admin role inherits the required permissions by default.

## Procedure

1. Download the Microsoft Azure Sentinel integration from the ServiceNow Store and install it.
2. Navigate to Security OperationsIntegrationsIntegration Configurations.
3. Search for the Microsoft Azure Sentinel tile and click Configure.
4. On the form, fill in the fields.  
   {#install-and-configure-microsoft-azure-sentinel-integration__table_kyc_qbg_p4b__entry__2}

   | Field | Description |
   |-|-|
   | Name | Name for the Microsoft Azure Cloud instance configuration. |
   | Identity URL | Identity URL for the Microsoft Azure Cloud tenant. For example, <kbd class="ph userinput">login.microsoftonline.com</kbd>. For additional information, see [Microsoft Azure documentation](https://learn.microsoft.com/en-us/azure/azure-government/compare-azure-government-global-azure). |
   | Azure Resource Manager | Azure Resource Manager Endpoint for Microsoft Azure Cloud tenant. For example, <kbd class="ph userinput">management.azure.com</kbd>. For additional information, see [Microsoft Azure documentation](https://learn.microsoft.com/en-us/azure/azure-government/compare-azure-government-global-azure). |
   | Tenant ID | Microsoft Azure Sentinel Tenant ID. This is the instance from which all the incidents in the Microsoft Azure portal are retrieved. |
   | Client ID | Client ID for the application that you've registered in the Microsoft Azure portal. |
   | Client Secret | Client secret for your registered application. |
   | Subscription ID | Subscription ID for your registered application. |
   | Resource Group Name | Resource group name for your registered application. |
   | Workspace Name | Workspace name for your registered application. |
   [Table 1. Microsoft Azure Sentinel - Incident Ingestion Configuration form]

   {#install-and-configure-microsoft-azure-sentinel-integration__table_kyc_qbg_p4b}
5. Click Submit.

## Result

After you successfully validate and submit the configuration, each incident ingestion server configuration is saved on the Security Integrations page as a tile.

*[\>]: and then


