Microsoft Defender for Cloud
Cloud and workloads

Create a ticket in Defender for Cloud

In brief

The article now introduces prerequisites, clarifies supported incident, change request, and problem ticket types, explains that deleting the integration removes associated assignments within up to 24 hours, and updates the next-steps heading and anchor.

What Defender admins need to know

Administrators have clearer guidance when configuring or deleting the Defender for Cloud–ServiceNow integration.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you create tickets in ServiceNow, make sure the following prerequisites are met:

  1. Select the ticket type.

:::image type="content" border="true" source="./media/create-ticket-servicenow/assignment-type.png" alt-text="Screenshot of how to complete the assignment type.":::

After the assignment is created, the Ticket ID assigned to this affected resource will appear next to the resource in the recommendation. The Ticket ID represents the ticket created in the ServiceNow portal. You can select the Ticket ID to navigate to the newly created incident in the ServiceNow portal.

Next steps

[!div class="nextstepaction"] Assign an owner to a recommendation or severity level