Configure Service Graph Connector for Microsoft Defender Endpoint using SGC Central
- UpdatedJul 15, 2025
- 3 minutes to read
- Zurich
- Now Platform Capabilities
Set up scheduled import jobs to pull in Microsoft Defender for Endpoint data into your Configuration Management Database (CMDB).
Before you begin
- Install Service Graph Connector for Microsoft Defender Endpoint version 1.1.0 or later from the ServiceNow Store. For ServiceNow Store installation steps, see Install a ServiceNow Store application.
- Verify that you have an active subscription to Microsoft Defender for Endpoint.
- Verify that you have created an Azure application to get programmatic access to Microsoft Defender for Endpoint. See Create an app to access Microsoft Defender for Endpoint without a user in the Microsoft 365 documentation.
- Obtain the tenant ID, client ID, and client secret details for the Microsoft Defender for Endpoint administrator account.
- Enable the Machine.Read.All and Machine.ReadWrite.All permissions in Microsoft Defender for Endpoint. See Permissions for the List machines API in the Microsoft 365 documentation.
| Stage | Role |
|---|---|
| Prerequisites | admin |
| Setup | cmdb_inst_admin or admin |
About this task
The playbook experience for onboarding connectors is activated with SGC Central in the CMDB Workspace. To configure the SGC Central application, see Configuring SGC Central and for more information on how to interact with a playbook, see Interact with Playbook.
Procedure
What to do next
Select View all connections to review the connection details. The configured connection appears in the Installed connections list.
Related Content
- Service Graph Connector for Microsoft Defender Endpoint
Use the Service Graph Connector for Microsoft Defender Endpoint to pull data from machines protected by the Microsoft Defender for Endpoint security solution into your ServiceNow instance.
- CMDB classes targeted in Service Graph Connector for Microsoft Defender Endpoint
When you complete setting up the connection, you can configure the integration to pull data periodically from machines utilizing the Microsoft Defender for Endpoint security solution. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.
- Accessing the connection details of Service Graph Connector for Microsoft Defender Endpoint
You can access the connection details of the Service Graph Connector for Microsoft Defender Endpoint in a single view using the common connection framework (CCF) included within the Integration Commons for CMDB (sn_cmdb_int_util) store app.