---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Vulnerability Response patch orchestration integration with Microsoft SCCM

# Vulnerability Response patch orchestration integration with Microsoft SCCM {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 6 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Vulnerability Response Patch Orchestration Integration with Microsoft SCCM

The Vulnerability Response integration with Microsoft System Center Configuration Manager (SCCM) enables ServiceNow customers to manage and deploy patches for critical vulnerabilities across their IT assets efficiently.
This integration links vulnerability detection data with patch updates from Microsoft SCCM, allowing users to submit patch requests, schedule deployments, and track remediation progress from within the ServiceNow AI Platform instance.
Show full answer Show less  
The integration uses two connections: a JDBC connection to pull ingestion data (collections, devices, patches, deployments) directly from the SCCM database, and a WMI connection via the Microsoft SCCM API to deploy patches to target machines.

## Key Features

* **Comprehensive Visibility:** Vulnerability managers can view detailed patch types, vendor solutions, and monitor remediation progress through Vulnerability Response Workspaces.
* **Scheduled Patch Deployment:** IT specialists can deploy patches for Windows, CentOS, macOS, Oracle, and other assets during off-hours to minimize disruption.
* **Unpatched Asset Identification:** Detect and manage assets with outstanding vulnerabilities or failed patch updates using imported scanner detection data.
* **Patch Scheduling:** Schedule patches directly from the IT Remediation Workspace or classic UI on vulnerable item or remediation task records.
* **Multi-patch Deployment:** Starting September 2026, deploy multiple patches to multiple collections simultaneously. This bundles patches into Software Update Groups in SCCM for efficient management.
* **Integration Roles and Security:** The integration requires specific ServiceNow AI Platform roles for installation, configuration, patch management, and approval workflows.
* **CI Lookup Rules:** Automated identification and association of configuration items (CIs) in the CMDB with imported SCCM data using Resource ID matching and Service Graph Connector.
* **MID Server Requirements:** This on-premises integration requires a dedicated Windows MID Server that handles JDBC connections for data ingestion and WMI connections for patch deployment.

## Practical Benefits for ServiceNow Customers

* **Centralized Patch Management:** Manage vulnerability remediation and patch deployment seamlessly from the ServiceNow AI Platform without switching tools.
* **Improved Patch Efficiency and Control:** Schedule patch deployments to reduce operational impact and address multiple vulnerabilities in one deployment batch.
* **Accurate Asset Vulnerability Tracking:** Automatically correlate SCCM device data with vulnerabilities in the CMDB, improving visibility and prioritization for remediation efforts.
* **Streamlined Approval Process:** Utilize built-in ServiceNow roles and approver groups to enforce patch request approvals before deployment, enhancing governance.
* **Integration Flexibility:** Supports multiple SCCM instances and leverages JDBC and WMI connections to optimize data retrieval and patch deployment workflows.

## Implementation Considerations

* Ensure the CMDB integration is installed and running before configuring the SCCM integration to enable accurate CI matching.
* Configure JDBC and WMI connections on the SCCM Patch Orchestration Integration form within ServiceNow to establish communication.
* Assign appropriate roles (such as admin, vulnerabilityadmin, and patch orchestration roles) to manage installation, configuration, and patch deployment effectively.
* Deploy the dedicated Windows MID Server outside of a MID Server cluster to support on-premises SCCM integration activities.  
The Vulnerability Response integration with the Microsoft System Center Configuration Manager (SCCM) supports patch management and deployment for critical vulnerabilities across your assets.

## Patch orchestration with Vulnerability Response {#mspatch-integration__section_al1_vly_5sb}

Patch orchestration with Vulnerability Response uses scheduled imports from third-party solution integrations, patch vendors, and vulnerability scanners. Scanner detection data matches the assets in your environment to vulnerabilities and to the
patch updates that can fix them. You submit patch requests for approval, schedule patch updates to resolve vulnerable items, and monitor remediation progress all from your ServiceNow AI Platform® instance.

The integration uses two separate connections to communicate with Microsoft SCCM. A JDBC connection retrieves ingestion data (collections, devices, patches, and deployments) directly from the SCCM database. A WMI connection uses the Microsoft SCCM API to deploy patches to target machines.

## Key capabilities {#mspatch-integration__section_tbl_1my_5sb}

When the Vulnerability Response Patch Orchestration with the Microsoft SCCM application is used with the ServiceNow®
Vulnerability Solution Management, Patch Orchestration, and Vulnerability Response applications, vulnerability managers and analysts can perform the following tasks:

* View context and information about patch types and vendor solutions.
* View and monitor vulnerability and solution data and remediation progress from records in the Vulnerability Response Workspaces.

{#mspatch-integration__ul_vnr_jmy_5sb}

IT specialists and remediation owners can perform the following tasks:

* Deploy patches supported by the Microsoft SCCM product for their Windows, CentOS, macOS, Oracle, and other assets at regular, scheduled intervals during off-hours to avoid conflicts with work.
* Identify unpatched assets with vulnerabilities, or assets that or were not successfully updated by scheduled patches from imported detection data from third-party scanners.
* Schedule available patches from either the IT Remediation Workspace or from the classic UI for vulnerable, unpatched assets from patch update, remediation task, and discovered item records.
* Starting with the September 2026 release, deploy multiple patches to multiple collections in a single deployment, instead of one patch to one collection at a time. Multi-patch deployments automatically create a Software Update Group in Microsoft SCCM to bundle the patches.
{#mspatch-integration__ul_ps3_nmy_5sb}

## Key terms in the Vulnerability Response and Microsoft SCCM applications {#mspatch-integration__section_qxf_tmy_5sb}

{#mspatch-integration__table_btn_pvx_zjc__entry__2}

| Term | Description |
|-|-|
| Configuration item (CI) | Existing assets listed in your Configuration Management Database (CMDB). Microsoft SCCM calls CIs devices. |
| Collections and device collections | A group of assets in the Microsoft SCCM product. |
| Vulnerable item | An imported vulnerability that matches an existing asset in your CMDB. |
| Instance | A distinct account of the Microsoft SCCM application. Each user account can be an instance in the Microsoft SCCM application. This term also refers to a unique, secure web address for a ServiceNow AI Platform instance. |
| Integration | A scheduled job in the ServiceNow AI Platform that retrieves information from a third-party source, such as the Microsoft SCCM integration. |
| JDBC connection | The connection the integration uses to retrieve ingestion data (collections, devices, patches, and deployments) directly from the SCCM SQL Server database, established over Java Database Connectivity (JDBC) and resolved on the MID Server. |
| WMI connection | The connection the integration uses to deploy patches to target machines through the Microsoft SCCM API over Windows Management Instrumentation (WMI), resolved on the MID Server. |
| Solution | There are two types of solutions: potential and preferred. A potential solution might address a vulnerability. Vulnerabilities often have many potential solutions. A preferred solution is the most effective solution for a specific, detected vulnerability. |
| Patches | Software updates that fix vulnerabilities. In the Microsoft SCCM application, patches are called Patches. For example, Microsoft SCCM has patches for Windows, CentOS, macOS, Oracle, and other products. |
| Preferred patch | Software updates that fix specific vulnerabilities. After deployment, patches map to the vulnerable items related to specific vulnerabilities and fix them. |
| Remediation task (vulnerability groups before v15.0 of Vulnerability Response) | Lists of vulnerable items in the Vulnerability Response application that require action to fix vulnerabilities. |
| Deployment | For this integration, deployment refers to applying, initiating, or scheduling a patch to a machine. Deploy patches downloaded from Microsoft SCCM in your ServiceNow AI Platform by selecting discovered items, patches, or remediation tasks from individual records in Vulnerability Response. Deploy patches with scheduled jobs to individual machines or computer groups. Deployment in the ServiceNow AI Platform can also refer to an integration that supports multi-source. A single integration instance is referred to as a deployment. A deployment refers to the integrations and products across your environment. For example, you might have multiple deployments of the Microsoft SCCM Vulnerability integration in your environment. |
[Table 1. Key terms]

{#mspatch-integration__table_btn_pvx_zjc}

## Vulnerability Solution Management and the Vulnerability Response patch orchestration integration with Microsoft SCCM {#mspatch-integration__section_k43_l4y_5sb}

The Vulnerability Solution Management application is a ServiceNow AI Platform application that correlates your vulnerability findings with the breakdown of the solutions (patches) that remediate them. Identify the software patches from third parties for products and services,
configuration updates, and other controls that have the highest impact for your organization. Along with third-party scanner information, the Solution Management for Vulnerability Response, Vulnerability Response, and the Vulnerability Response Patch Orchestration with Microsoft SCCM applications work together to roll preferred patches up from the solution, to the vulnerability, to the vulnerable item to help you fix and close vulnerabilities to your environment. The Solution Management for Vulnerability Response, Vulnerability Response, and the Vulnerability Response Patch Orchestration Microsoft SCCM integration applications are all available in the ServiceNow® Store.

## Required ServiceNow AI Platform roles {#mspatch-integration__section_lyy_52p_hsb}

The integration installation, configuration, and remediation tasks require the following roles in your  ServiceNow AI Platform instance.
{#mspatch-integration__table_ctn_pvx_zjc__entry__2}

| Role | Description |
|-|-|
| admin | Obtains entitlements for applications in the ServiceNow Store and installs them on ServiceNow AI Platform instances. |
| sn_vul.vulnerability_admin | Activates applications in the ServiceNow AI Platform instance and completes configuration of the Vulnerability Response application. This role has complete access to the Vulnerability Response (VR) application and its records. This admin user configures all VR applications, rules, and third-party integrations. |
| sn_vul_sccm.configure_integration | Configures the Microsoft SCCM Patch Orchestration Integration application. This role contains the sn_vul_sccm.read_integration granular role. |
| sn_vul_sccm.read_integration | Provides read-only access to records in the Vulnerability Response and Microsoft SCCM Patch Orchestration Integration application and patch orchestration data. |
| sn_vul_patch_orch.configure_patch | Configures and applies patches. |
| sn_vul_patch_orch.read_patch | Provides read-only access to patch information. |
| Approvers | Assign users to the Approver level 1 and Approver level 2 approver groups to require approval of submitted patch requests before deployment. |
[Table 2. Required roles]

{#mspatch-integration__table_ctn_pvx_zjc}

For more information about assigning these roles using the Setup Assistant, see [Assign the Vulnerability Response persona roles using Setup Assistant](https://www.servicenow.com/docs/b6sj5FGr3R7iHcYDAB4efA "Assign the Vulnerability Response persona roles to groups or users with Setup Assistant.").

## CI lookup rules {#mspatch-integration__section_sg2_nqy_5sb}

When data is imported from the Microsoft SCCM application, the Vulnerability Response application automatically searches for matches in the Configuration Management Database (CMDB) using Resource ID data. CI lookup rules are used to identify CIs (assets) and add them automatically to vulnerable item (VI) records when VIs are created. The following CI lookup
rules are shipped with the base system and are used to identify CIs (assets) and add them to the discovered items.

This lookup rule relies on the data brought in by the Service graph connector with SCCM. Install and run the CMDB integration before running the SCCM integrations. If you have multiple installations of the SCCM server, you can
configure the Service graph connector connection alias in the SCCM patch orchestration configuration page.

## MID Server {#mspatch-integration__section_ryn_bsy_5sb}

The Vulnerability Response Patch Orchestration with Microsoft SCCM is an on-premises integration. It requires a standalone Windows MID Server that is not part of a MID Server cluster.  
Starting August 2026 release, the MID Server is used differently depending on what the integration is doing:

* For data ingestion (collections, devices, patches, and deployments), the integration connects directly to the SCCM database using Java Database Connectivity (JDBC) over a SQL Server connection resolved on the MID Server. JDBC ingestion doesn't require opening a firewall port for Windows Management Instrumentation (WMI) remote procedure calls.
* For patch deployment, the integration continues to use the Microsoft SCCM API over WMI, run through the same MID Server.

Both connections are configured on the Microsoft SCCM Patch management Integration configuration form, on separate JDBC Connection and WMI Connection tabs. See [Configure Microsoft SCCM Patch Orchestration](https://www.servicenow.com/docs/zIanoddWIPXZuYIFvpmfsA "Configure the Microsoft SCCM Patch Orchestration integration with your account credentials to enable data ingestion and patch deployment.").
**Related tasks**   

* [Prepare for the Vulnerability Response patch orchestration integration with Microsoft SCCM](https://www.servicenow.com/docs/770yU5OED3RK9XvPPZa4Rw "Prepare for the integration by performing the following setup tasks.")

