Install and configure the Service Graph Connector for Microsoft SCCM and the Microsoft Defender Mitigation Control Integration
The Service Graph Connector for SCCM and the Microsoft Defender Mitigation Control Integration require separate configuration steps.
Before you begin
You must install, activate, and configure the Service Graph Connector for SCCM to import asset details. You configure the Microsoft Defender Mitigation Control Integration, that also uses SCCM, to gather additional data about mitigation controls configured on the assets to that are monitored by the Service Graph Connector for SCCM.
Roles required:
- admin for installation and activation of plugins
- SPC Admin Group and SPC Analyst Group for configuration of integrations in the workspace
- Microsoft SCCM credentials that include the Script Authors role. The Script Authors role provides required permissions to create a script that is required to import mitigation information on the SCCM
server.Note:This role must be created and assigned with the following permissions:
Table 1. Script Authors role Category Permission State Collection Run Script No Site Read Yes SMS Scripts Create Yes SMS Scripts Read Yes SMS Scripts Delete Yes SMS Scripts Modify Yes - Microsoft SCCM credentials that include the Script Approvers role. The script created to import mitigation information requires approval in your Microsoft SCCM console by user with the Script Approvers
role.Note:This role must be created and assigned with the following permissions:
Table 2. Script Approver Category Permission State Collection Run Script No Site Read Yes SMS Scripts Read Yes SMS Scripts Approve Yes SMS Scripts Modify Yes