McAfee ePO integration for Security Operations release notes

  • Release version: Store
  • Updated June 11, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of McAfee ePO integration for Security Operations release notes

    The McAfee ePO integration for Security Operations enhances ServiceNow Security Incident Response (SIR) by enabling automated and manual interactions with McAfee ePO for threat detection and remediation. It supports multiple McAfee ePO consoles and offers flexible profile configurations to respond to diverse incident types, improving security workflows and auditability.

    Show full answer Show less

    Key Features

    • Automated triggering of McAfee ePO queries and actions based on incident conditions in ServiceNow SIR.
    • Manual launch of McAfee ePO capabilities directly from SIR security incidents.
    • Creation of multiple profiles for triggering different McAfee ePO and ServiceNow Security Operations capabilities tailored to specific incident types like malware.
    • Validation of profile configurations with preview functionality showing McAfee ePO results on SIR incidents.
    • Capabilities to initiate malware scans, isolate compromised systems, and restore them to the network post-remediation.
    • Security tagging to track which McAfee ePO capabilities are launched by workflows and their execution status.
    • Comprehensive audit trails linking McAfee ePO queries and actions with SIR incidents, including command logging in the McAfee ePO console.
    • Support for multiple McAfee ePO consoles to apply different policies based on user groups and regions.
    • Upgrades to security with strict read-only enforcement across UI, scripts, and integrations to prevent unauthorized changes.
    • Migration of workflows to Flow Designer for improved automation and maintainability.
    • Localization support and enhanced access controls to improve user experience and security analyst access.

    Key Outcomes

    • Improved security operations efficiency by automating McAfee ePO actions triggered by incident conditions.
    • Enhanced control and security through strict read-only fields and refined access controls.
    • Better workflow management and flexibility using Flow Designer and capability framework integration.
    • Increased visibility and traceability of security actions via detailed audit trails and tagging mechanisms.
    • Support for global and segmented security policies through multiple McAfee ePO console management.
    • Reduced errors and improved usability through localization and key management enhancements.

    Version history for the McAfee ePO integration for Security Operations on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.

    Version history

    Version 10.6.1 - June 2026
    Fixed: Access issues for Security Analyst while querying tables.
    Version 10.6.0 - December 2025
    New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
    Version 10.5.11 - August 2025
    Fixed: Error sys_scope during Lookup Source in McAfee EPO Integration.
    Version 10.5.1 - February 2025
    New: Migrated existing default Workflows to Flow Designs using Flow Designer.
    Version 10.4.7 - November 2024
    New: Migrated existing default Workflows to Flow Designs using Flow Designer.
    Version 10.4.6 - December 2023
    Fixed: Misconfiguration of table/field ACLs within com.snc.secops.mcafee.epo plugin.
    Version 10.4.5 - November 2023
    • Changed: Added localization translations.
    • Fixed: The report_view access control list (ACL) was missing for some tables.
    Version 10.4.3 - August 2023
    Changed:
    • Migrated this integration to the capability framework.
    • UI Framework built for capabilities in the new workspace.
    Version 10.3.6 - June 2022
    Fixed: Localization and Internationalization issues in UI messages, and ACL-related issues are resolved to enable the Security Analyst to see capability profile records.
    Version 10.3.5 - October 2021
    Fixed: Added additional password-related policies.
    Version 10.3.3 - December 2020
    Changed: With Key Management Framework plugin, developers will have an ability to manage keys used for Password2 fields through crypto module definition.
    Version 5.0.0 - April 2019
    • Supports automated triggering of McAfee ePO queries and actions based on incident conditions
    • Supports launching McAfee ePO capabilities manually from ServiceNow AI Platform® Security Incident Response (SIR) security incidents
    • The flexibility to create multiple profiles for triggering different types of McAfee ePO and ServiceNow AI Platform Security Operations capabilities. These profiles automatically gather threat event information that is based on the conditions of specific incident types such as malware.
    • Validate your profile configuration with a preview of the McAfee ePO results on SIR security incidents.
    • Initiate malware scans from a SIR security incident to identify potential system compromise.
    • Isolate compromised systems from the network, and, after remediation, return the systems to the network.
    • If tagging is enabled, security tags identify which McAfee ePO capabilities are initially launched by a workflow and when the queries or actions are successfully completed.
    • A complete audit trail of the McAfee ePO queries and actions is posted on SIR security incidents, and commands from the ServiceNow AI Platform are logged in the McAfee ePO console.
    • Supports multiple McAfee ePO consoles so that you can apply different policies to user groups and regions.