Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Install and configure the Servicenow application for Microsoft Graph Security API alert ingestion integration

Before you run the integration on your ServiceNow AI Platform® instance, complete these installation and configuration steps so the application properly integrates with the Security Incident Response and Security Operations products on your ServiceNow AI Platform instance.

Before you begin

Role required: sn_si.admin

Procedure

  1. If you have not installed the Microsoft Graph Security API application from the ServiceNow Store for the integration, see Install a Security Operations integration and follow the steps to install it.

  2. After you have successfully installed the application, navigate to Integrations > Integrations Configurations and locate the Microsoft Graph Security API - Alert Ingestion tile.

Image omitted: ms-graph-config-tile.png
Microsoft Graph Security API: configure
  1. To configure the application, select Configure.

  2. In the Alert Ingestions Configuration dialog that is displayed, fill in the fields.

FieldDescription
NameName of the Microsoft Azure Cloud instance. You can enter only alphanumeric values and hyphens \(-\) in this field.
Tenant IDThe Microsoft Azure Tenant ID. This is the instance from which all the alerts in the Microsoft Azure portal are retrieved.
Client IDThe Client ID for the application that you have registered in the Microsoft Azure portal. See Configure the Microsoft Azure portal for details.
Client SecretThe password for your registered application.
  1. Select Submit.

    After it is successfully validated and submitted, each alert ingestions server configuration is saved on the Security Integrations page as a tile. If your saved configuration tiles are not displayed on the Security Integrations page, on the top right corner of the page, from the Show Configurations list, select Yes.

What to do next

You have successfully installed and configured the application. The next step is to create an alert profile.