Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Automate incident updates and closures

Automate incident updates and closures based on the incident status. The Microsoft Defender integration has a bi-directional interface that enables incidents to create security incidents and to update the incidents after the security incident is created or closed.

Before you begin

Role required: sn_si.admin, sn_si.ingestion_profile_admin

Procedure

  1. If you aren’t continuing from the previous section of the Scheduling process, access the profile you’re defining.

    1. Navigate to All > Microsoft Defender Integration > Defender Incident Profiles.

    2. Select the profile that you’re continuing to define.

    3. Select Additional Options in the progress bar.

  2. On the form, fill in the fields.

CategoryFieldDescription
Incident Creation UpdatesUpdate Defender Incident status upon SIR Incident CreationOption to use the automated incident update functionality. The Defender incident status is updated with the comments after the SIR incident is created in the ServiceNow AI Platform.
Initial incident status updateInitial incident status that is updated in the Microsoft Defender environment. Options include: Active, In Progress, and Redirected.
Initial comments posted back to IncidentInitial comments that are posted to the incident in the Defender environment.
Incident Closure UpdatesClose Defender Incident upon SIR Incident ClosureOption to use the automated incident status update functionality. Incidents will be closed in Defender with the comments given after the SIR incident is closed in the ServiceNow AI Platform.
Closure Incident Status UpdateStatus update in Defender when the security incident is closed in SIR.
Closure Comments Posted back to incidentComments posted to the incident in Defender when the security incident is closed in SIR.
Incident classificationOption to automatically update Microsoft Defender Incident Classification based on SIR Close Code. When a SIR is closed in ServiceNow, the selected SIR Close Code will automatically determine and update the Incident Classification field in the corresponding Microsoft Defender incident. Options include: - Default incident classification. - Incident classification-SIR close code mapping.
Defender Pull Closed IncidentsPull Closed IncidentsOption to fetch closed incidents during ongoing ingestion and one-time retrieval. Closed SIR incidents won’t be updated with new data from Defender.
Defender Incident Comments and SIR Work notes synchronizationUpdate SIR work notes with Defender incident commentsOption to synchronize Security Incident work notes to Defender incident comments. Work notes added to the Security Incidents in ServiceNow appears with the prefix- Comment from Defender ID.
Update Defender incident comments with SIR work notesOption to update your SIR work notes in the Defender incident comments. The comment in Microsoft Defender appears with the prefix- Comment from ServiceNow.
Image omitted: ms-def-additional-op.png
Options for automating incidents
  1. Select Finish.

  2. Activate the profile.

    1. Select the Name section of the progress bar.

    2. Select the Active check box.

    3. Select Continue.