Microsoft Defender for Cloud Apps
Vulnerabilities and exposure

Protect your ServiceNow environment | Microsoft Defender for Cloud Apps

In brief

The page adds optional instructions for creating a non-admin ServiceNow user with custom read ACLs and a shared role. It also clarifies 90-day token rotation and adds an Australia-specific Scope Restriction instruction.

What Defender admins need to know

Administrators can use the non-admin setup path for the connector. Refresh the token before it expires to prevent the ServiceNow connection from stopping.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How Defender for Cloud Apps helps protect your ServiceNow environment

AsServiceNow is a major CRM cloud provider, ServiceNow incorporates large amounts ofprovider. It stores sensitive informationdata about customers, internal processes, incidents, and reports inside your organization. Beingreports. As a business-critical app, ServiceNow is accessedpeople both inside and used by people insideoutside your organization and by others outside of it (such asuse it, including partners and contractors) for various purposes. In many cases, a large proportioncontractors. Many of yourthese users accessing ServiceNow have low awareness ofmight not follow security and might put yourbest practices. They could share sensitive information at risk by unintentionally sharing sensitive data. In other instances, maliciousdata without meaning to. Malicious actors might gainalso try to access to your most sensitive customer-relatedcustomer assets.

Connecting ServiceNow to Defender for Cloud Apps improves insights into your users' activities. It also helps detect threats using machine-learning anomaly detection and information protection, such as identifying when sensitive customer data is uploaded to ServiceNow.

  • Insufficient security awareness
  • Unmanaged bring your own device (BYOD)

HowProtect your environment with Defender for Cloud Apps helps to protect your environment

Defender for Cloud Apps helpsYou can protect your ServiceNow environment in the followingthese ways:

SaaS security posture management for ServiceNow

Connect ServiceNowConnect ServiceNow to automaticallyMicrosoft Defender for Cloud Apps to get security recommendationstips for ServiceNow in Microsoft Secure Score.

In Secure Score, select Recommended actions and filter. Filter by Product = ServiceNow. For example, recommendations for ServiceNowExamples include:

  • Enable MFA
  • Activate the explicit role plugin

Automate governance controls

In addition to monitoring for potential threats, youYou can apply andalso automate the following ServiceNow governance actions to remediatefix detected threats. These actions are performedrun through Microsoft Entra ID, Microsoft's cloud identity service:ID:

Type Action

Connect ServiceNow to Microsoft Defender for Cloud Apps

The following section provides instructions for connectingUse the app connector API to connect Microsoft Defender for Cloud Apps to your existing ServiceNow account using the app connector API.account. The ServiceNow app connector gives you visibility into and control over ServiceNow use. For information about how Defender for Cloud Apps protects ServiceNow,threat detection, governance controls, and real-time protection guidance, see Protect ServiceNow.

[!INCLUDE security-posture-management-connector]

  • Xanadu
  • Yokohama
  • Zurich
  • Australia

For more information, see ServiceNow OAuth applications documentation.

  1. Increase the Access Token Lifespan to at least 3,600.

  2. Change the Scope Restriction value to Broadly Scoped.

  3. Select the name of the OAuth that was defined, and change the Refresh Token Lifespan to 7,776,000 seconds (90 days).

  4. Establish an internal procedure to ensure that the connection remains active.

    1. In the Microsoft Defender Portal, edit the existing connector, using the same client ID and client secret. This will generate a new refresh token.

Connect ServiceNow to Microsoft Defender for Cloud Apps

:::image type="content" source="media/servicenow-app-connector-details-screenshot.png" alt-text="Screenshot of the ServiceNow App Connector Details Dialog.":::
  1. To find your ServiceNow user name, in the ServiceNow portal, go to Users and then locate your name in the table. (Optional) To use a non-admin user for this step, create a non-admin user by following the steps in the below section.

  2. In the OAuth Details page, enter your Client ID and Client Secret. Select Next.

After connecting ServiceNow, you'll receive events for 1 hour prior to connection.

Optional: Create a non-admin user in ServiceNow

Step 1: Create custom access control lists (ACLs) in ServiceNow

  1. Sign in to ServiceNow with an administrator account.
  2. Open the Elevate Roles menu and enable both admin and security_admin. These elevated roles are required to create ACLs for certain tables.
  3. Navigate to Access Control (ACL) configuration.
  4. Create a Read ACL for each of the following tables:
    • sys_user
    • sys_user_group
    • sys_user_grmember
    • sys_user_has_role
    • sys_properties
    • v_plugin
    • sysevent_script_action
    • sys_attachment
    • sys_attachment_doc
    • sysevent
    • syslog_transaction
    • incident
    • sys_user_role_contains
  5. For each ACL, set Type = record, Operation = read, Name = the table name, and Required Role = a custom role such as custom_table_access.
  6. Use the same custom role across all ACLs to simplify management.

Step 2: Create a non-admin user

  1. In ServiceNow, go to User Administration > Users.
  2. Create a new user account.
  3. Record the username and password for later use in the integration setup.
  4. Open the newly created user profile.
  5. Scroll to the Roles section.
  6. Assign the custom role created in Step 1 (for example, custom_table_access) to the user.

Legacy ServiceNow connection

To connect ServiceNow with Defender for Cloud Apps, you must have admin-level permissions and make sure the ServiceNow instance supports API access.