Microsoft Graph Security API Alert Ingestion integration for Security Operations release notes

  • Release version: Store
  • Updated July 9, 2026
  • 2 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Microsoft Graph Security API Alert Ingestion integration for Security Operations release notes

    The Microsoft Graph Security API Alert Ingestion integration for Security Operations is a ServiceNow Store application that enables customers to automatically fetch security alerts from multiple providers via a unified Microsoft Graph Security API. These alerts are ingested into ServiceNow as security incidents, facilitating streamlined incident response and automated workflows. The integration supports mapping of MITRE ATT&CK data to enhance threat context within security incidents.

    Show full answer Show less

    This integration acts as a broker service, connecting native Microsoft and ServiceNow partner security solutions into a single programmatic interface for alert ingestion and incident creation.

    Key Features and Updates

    • Alert Ingestion and Incident Creation: Automatically fetches alerts from diverse security providers and converts them into ServiceNow Security Incident Response (SIR) records for efficient incident management.
    • MITRE ATT&CK Integration: Supports mapping of MITRE ATT&CK framework data from Graph Security alerts into corresponding SIR fields, enhancing threat intelligence and investigations.
    • Security Enhancements: Upgraded dictionary-level read-only fields to strict enforcement to prevent unauthorized modifications across UI, scripts, and integrations.
    • Improved Reliability: Enhancements to polling mechanisms to avoid missing alerts during data fetch intervals, and fixes for handling HTTP failures in alert polling.
    • Credential Validation: Fixed validation messaging to accurately reflect credential status during configuration.
    • UI Improvements: Fixed dark theme application consistency and general UI fixes for better user experience.
    • Performance and Dependency Updates: Removed dependency on new UI, updated dependent plugins, and applied performance optimizations.
    • API Upgrades: Integration upgraded to Microsoft Graph Security API V2.0, enabling improved functionality and data mapping.
    • Data Integrity Fixes: Resolved issues related to field mapping when alert source fields are missing or null, ensuring accurate data ingestion without losing existing values.

    Practical Implications for ServiceNow Customers

    • Customers can leverage this integration to centralize security alerts from multiple Microsoft and partner sources directly into their ServiceNow Security Incident Response, enhancing operational efficiency.
    • The robust mapping to MITRE ATT&CK data supports better threat analysis and prioritization within the ServiceNow platform.
    • Security enhancements and strict read-only enforcement help maintain data integrity and prevent unauthorized changes, critical for compliance and audit readiness.
    • Improved polling and error handling ensure higher reliability and completeness of alert ingestion, reducing the risk of missing critical security events.
    • Ongoing fixes and updates reflected in the version history demonstrate active maintenance and responsiveness to customer needs, ensuring smoother integration and user experience.
    • Customers should refer to the application listing on the ServiceNow Store for detailed system requirements and compatibility information before installation or upgrade.

    Version history for the Microsoft Graph Security API Alert Ingestion integration for Security Operations on the ServiceNow Store.

    Important:
    For details on system requirements and family compatibility, view the application listing on the ServiceNow Store website.

    Version history

    Version 10.5.5 - July 2026
    Fixed: Restored the buildInputValue function in the Graph Security API transform, fixing SIR fields being mapped as empty when a referenced source field is missing from the alert response.
    Version 10.5.3 - June 2026
    Changed: Replaced hardcoded endpoint path to system properties.
    Version 10.5.2 - March 2026
    Fixed: Reintroduced a new column to filter alerts.
    Version 10.5.1 - February 2026
    Fixed: Successful validation message getting displayed during configuration tile validation despite invalid credentials.
    Version 10.5.0 - December 2025
    New: Upgraded all dictionary-level read-only fields to Strict Read-Only to enhance security and prevent unauthorized changes.This update ensures the server consistently enforces read-only behaviour across all UIs, scripts, and integrations.
    Version 10.4.13 - August 2025
    Fixed: Improved Handling of Next Poll Date for Microsoft Graph Security Alert Integration on HTTP Failures.
    Version 10.4.8 - May 2024
    The dependency on the new UI is removed.
    Version 10.4.7 - November 2023
    Fixed: Updated the dependent application's (Common Plugin for SecOps SIEM Integration) version to the latest version.
    Version 10.4.6 - May 2023
    • New:
      • The Microsoft Graph Security API - ServiceNow Security Incident Response integration has been upgraded to V2.0 API.
      • Provides you with the ability to map MITRE ATT&CK data in the Graph Security alert to the MITRE ATT&CK field in the security incident.
    • Fixed:
      • One-Time Retrieval is not working on the scheduling page of the profile when we change the date format to dd-MM-YYYY for the Graph Security API.
      • Microsoft Graph Security API Alert Ingestion Integration: Dark theme is not applied to all fields.
    Version 10.4.5 - September 2022
    Changed: Performance fix.
    Version 10.4.4 - June 2022
    Fixed: When there is a Business Rule on Observable/CI and task M2M records, which updates the SIR fields automatically. This occurs since SIR was not persisted at the creation time using SIEM, and the SIR fields are not getting updated. This issue has been resolved, and now SIR would persist first in DB, and then the M2M records are created.
    Version 10.4.2 - December 2021
    Fixed: UI fixes.
    Version 10.4.1 - October 2021
    Fixed: Added additional password-related policies.
    Version 10.4.0 - May 2021
    • Changed: When multiple alert fields are mapped to a SIR field and if one of the alert field value is NULL or blank, that doesnt empty the SIR field instead will map the values available.
    • New: Alerts ingestion mechanism is improved to avoid missing alerts injestion during polling intervals
    Version 10.3.3 - December 2020
    Changed: With Key Management Framework plugin, developers will have an ability to manage keys used for Password2 fields through crypto module definition.
    Version 10.0.6 - May 2020
    • The Microsoft Graph Security API is an intermediary service (or broker) that provides a single programmatic interface to connect multiple security providers (Native to Microsoft as well as ServiceNow Partners).
    • The Microsoft Graph Security Alert Ingestion integration allows you to automatically fetch alerts from multiple security providers and convert them into security incidents and enable automated response actions.