Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Connect to the Microsoft Defender for IoT (Azure)

Connect to Microsoft Defender for IoT (Azure) to begin the Vulnerability Integration setup.

Before you begin

Review that you have Security Reader permission enabled on Microsoft Defender for IoT Azure, which provides the following user actions:

  • Download sensor endpoint details
  • View values on the Sites and sensors page
  • View Azure device inventory
  • View Azure workbooks
  • View Defender for IoT settings
  • Download OT threat intelligence packages

For more information, see Azure user roles and permissions for Defender for IoT.

Role required: admin

Procedure

  1. Navigate to All > Azure D4IoT Vulnerability Integration > Admin > Guided Setup.

  2. In the Connect to Microsoft Defender for IoT (Azure) section, select the Setup Connections task.

  3. On the Setup Connections task page, select Configure.

    The Connect to Microsoft Azure Defender for IoT page opens.

  4. On the form, fill in the following fields.

  1. Select Update.

  2. Select Test Connection.

    If the connection test is successful, a Results 200 output message appears. An unsuccessful connection attempt displays the error code and the message received from Microsoft Defender for IoT (Azure).

Parent Topic:Navigate to Guided Setup for the Vulnerability Response Integration with Microsoft Defender for IoT (Azure)

sndocs is an independent community mirror and is not affiliated with or endorsed by ServiceNow.

ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc., in the United States and/or other countries. Other company and product names may be trademarks of the respective companies with which they are associated.

© 2026 ServiceNow, Inc. All rights reserved.

Documentation content is redistributed under the Apache License 2.0 from the ServiceNowDocs repository.

FieldDescription
OAuth Token URLThe OAuth 2.0 token URL for login.microsoftonline.com. For example, `https://login.microsoftonline.com//oauth2/v2.0/token`.
OAuth Client IDYour client ID.
OAuth Client SecretYour client secret.
Page Size LimitThe maximum number of records to pull for each page of data. The default is 500.
Minimum CVSS ScoreOnly vulnerabilities with a CVSS score greater than or equal to this value are imported. The default is 0.0 for all vulnerabilities.
Run After Service Graph Connector Import

This is a recommended field that runs the vulnerability import immediately after the Service Graph Connector for Microsoft Defender for IoT (Azure) devices import is completed. This ensures the best probability of matching incoming vulnerability data to the CMDB.

Most commonly, the value is SG-OT Microsoft Azure D4IoT Devices Scheduled Import. When selecting this field, leave the Azure D4IoT Vulnerability Detection Integration - Full Import scheduled job set to run On Demand. This ensures that the Service Graph Connector device import can execute it as a child job once the devices import is complete.

Daily Import TimeIf you're not using the Run After Service Graph Connector Import field, you can set the daily import time of the integration using this field.Note: If you have a scheduled import selected for the Run After Service Graph Connector Import field, this field is unavailable.