---
sourceDocument: Brazil ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/servicenow-platform

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Microsoft Defender for Endpoint

# Service Graph Connector for Microsoft Defender Endpoint {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Service Graph Connector for Microsoft Defender Endpoint

The Service Graph Connector for Microsoft Defender Endpoint enables ServiceNow customers to import and synchronize data from machines protected by Microsoft Defender for Endpoint into their ServiceNow instance.
This integration supports Microsoft Defender for Endpoint Plan 1 and Plan 2 and is compatible with ServiceNow versions Washington DC, Xanadu, and Yokohama.
The connector enhances the ServiceNow Security Operations applications by providing detailed insights into endpoint security data.
Show full answer Show less  

## Key Features

* **Data Import and Mapping:** Machine-related data from Microsoft Defender for Endpoint is imported into a staging table and then transformed and mapped into relevant ServiceNow CMDB configuration item (CI) classes using the Robust Transform Engine (RTE) and Identification and Reconciliation Engine (IRE).
* **Target CMDB Tables:** Data populates key CMDB tables such as IP Address, Computer, Network Adapter, Windows Server, and Software Installation/Instance/Package tables depending on whether the Software Asset Management (SAM) application is installed.
* **Connection Configuration:** The connector is installed and configured through the SGC Central view within the Service Graph Workspace or CMDB Workspace, which supports full lifecycle management including creation, editing, monitoring, and debugging of connections. The older guided setup method is deprecated and SGC Central is recommended.
* **Monitoring and Troubleshooting:** Integration status, processing results, and errors can be monitored via the CMDB Integrations Dashboard provided by the Integration Commons for CMDB store app. This dashboard allows filtering by integration, time period, and individual runs.
* **Upgrade Consideration:** After upgrading to version 1.2.0, customers must migrate data from the Server CI class to the Computer CI class to maintain data integrity.

## Key Outcomes

* Improved visibility into endpoint security posture by automatically importing Microsoft Defender for Endpoint data into ServiceNow CMDB.
* Streamlined configuration and monitoring through centralized SGC Central and CMDB Integrations Dashboard tools, reducing operational overhead.
* Accurate and consistent CMDB data through robust data transformation and reconciliation processes.
* Support for ongoing data synchronization enabling up-to-date security insights for Security Operations teams.  
Use the Service Graph Connector for Microsoft Defender Endpoint to pull data from machines protected by the Microsoft Defender for Endpoint security solution into your ServiceNow instance.

## Request apps on the Store {#sgc-cmdb-integration-msdefender__id_lz5_rv1_p4b}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) to view all the available apps, and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#sgc-cmdb-integration-msdefender__inline-send-to-store}

## Supported versions {#sgc-cmdb-integration-msdefender__section_jk2_xtn_1xb}

* Supported Microsoft Defender for Endpoint versions:
  * Microsoft Defender for Endpoint Plan 1
  * Microsoft Defender for Endpoint Plan 2
  {#sgc-cmdb-integration-msdefender__ul_svl_ncv_tzb}
* Supported ServiceNow versions:
  * Washington DC
  * Xanadu
  * Yokohama
  {#sgc-cmdb-integration-msdefender__ul_hq4_gtq_wtb}
{#sgc-cmdb-integration-msdefender__ul_d1l_btq_wtb}

## Use cases {#sgc-cmdb-integration-msdefender__section_fmb_gvc_bxb}

The ServiceNow
Security Operations applications have features that interact with the Service Graph Connector to gain insights into machines utilizing the Microsoft Defender for Endpoint security solution.

## Important Information for upgrading Service Graph Connector for Microsoft Defender Endpoint {#sgc-cmdb-integration-msdefender__section_ftl_dwm_dfc}

After you upgrade to Service Graph Connector for Microsoft Defender Endpoint 1.2.0, migrate data from the Server \[cmdb_ci_server\] CI class to the Computer \[cmdb_ci_computer\] CI class. For more information, see the [Service Graph Connector for Microsoft Defender Endpoint - Data migration after upgrade to version 1.2.0 \[KB2096769\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2096769) article in the Now Support Knowledge Base.

## Configuring a connection for the connector {#sgc-cmdb-integration-msdefender__section_cgw_3pf_32c}

Use the SGC Central view in the Service Graph Workspace or CMDB Workspace to install the connector and configure the connection. The view enables you to install and discover connectors and to manage the full life cycle of creating, editing, monitoring, and debugging connections. For instructions, see [Configure Service Graph Connector for Microsoft Defender Endpoint using SGC Central](https://www.servicenow.com/docs/T9jnU5r1c0CtASX8xkbtkg "Set up scheduled import jobs to pull in Microsoft Defender for Endpoint data into your Configuration Management Database (CMDB).").  
Important:  
Unless there are configuration issues, use SGC Central to configure the connection. The guided setup method for configuration is being deprecated.

## CMDB integrations dashboard {#sgc-cmdb-integration-msdefender__section_cjr_s5n_1xb}

The Integration Commons for CMDB store app provides a dashboard with a central view of the status, processing results, and processing errors of all installed integrations. You can see metrics for all integration runs. You
can filter the view to a specific CMDB integration, a specific time duration, or a specific integration run. For more details about monitoring Microsoft Defender for Endpoint integrations in the CMDB Integrations Dashboard, see [Using the CMDB Integrations Dashboard](https://www.servicenow.com/docs/6UR2b9oa6teU8Ntvkupjzg#integration-commons-for-cmdb__section_fxg_lh4_blb).

## Data mapping {#sgc-cmdb-integration-msdefender__section_w1m_mhf_hkb}

Data from the Microsoft Defender for Endpoint data source is mapped and transformed into the ServiceNow
CMDB configuration item (CI) class definitions using the Robust Transform Engine (RTE). Data is inserted into the ServiceNow
CMDB using the Identification and Reconciliation Engine (IRE).

When you complete setting up the connection, you can configure the integration to pull data periodically from the machines utilizing the Microsoft Defender for Endpoint security solution.  
The following data source is included for the Microsoft Defender for Endpoint security solution:

SG-Defender Machines
:   Imports all the machine-related data from the machines utilizing the Microsoft Defender for Endpoint security solution, loads the imported data in the SG-Defender Machines \[sn_defender_integ_sg_defender_machines\] staging table, and then populates the following target tables:

    * IP Address \[cmdb_ci_ip_address\]
    * Software Installation \[cmdb_sam_sw_install\] (If the Software Asset Management (SAM) application is installed.)
    * Software Instance \[cmdb_software_instance\] (If the SAM application is not installed.)
    * Software \[cmdb_ci_spkg\] (If the SAM application is not installed.)
    * SG-Defender Machines Related \[sn_defender_integ_sg_defender_machines_related\]
    * Network Adapter \[cmdb_ci_network_adapter\]
    * Computer \[cmdb_ci_computer\]
    * Windows Server \[cmdb_ci_win_server\]
{#sgc-cmdb-integration-msdefender__ul_zzq_22v_tzb}  
Note:  
Only operating system details are populated in the Software Installation \[cmdb_sam_sw_install\], Software Instance \[cmdb_software_instance\], and Software \[cmdb_ci_spkg\] tables.

For more information on where data is saved when pulling data from the Microsoft Defender for Endpoint security solution, see [CMDB classes targeted in Service Graph Connector for Microsoft Defender Endpoint](https://www.servicenow.com/docs/mr2nGPAG8EwG97_hrWtLMA "When you complete setting up the connection, you can configure the integration to pull data periodically from machines utilizing the Microsoft Defender for Endpoint security solution. The data is saved in tables that extend from the Configuration item [cmdb_ci] table.").

You can use the IntegrationHub ETL app to view the data maps. See [IntegrationHub ETL](https://www.servicenow.com/docs/MvUnD_GHFcty25xoT_q32Q "Use the IntegrationHub ETL store app to create and manage ETL transform maps, which integrate third-party data into the CMDB or into non-CMDB tables without compromising the integrity of data. IntegrationHub ETL provides a simplified user interface that guides you through the integration process end-to-end, including a test integration run of sample data.") for more information.
**Related concepts**   

* [Service Graph Connectors](https://www.servicenow.com/docs/fk0ID7vBvYSz3Nsp9W_hnA "You can use a Service Graph Connector to import and integrate third-party data into CMDB and non-CMDB tables.")

