Skip to content

Cookie Settings

This site uses cookies that need consent.

Microsoft Defender for Endpoint

The Microsoft Defender for Endpoint Vulnerability Management dashboard within the Microsoft Defender portal provides security administrators and security operations teams with security recommendations, software vulnerabilities, remediation activities and exposed endpoint devices.

The CI Sync Microsoft Defender for Endpoint connector retrieves endpoint devices and their associated vulnerabilities (CVEs) and populates this information into Configuration Management Database (CMDB) enabling organisations to visualise their endpoint exposure. In addition, organisations can use ServiceNow to generate remediation tasks to create end-to-end CVE remediation workflows.

Generate Configuration Items for Endpoints
CI Sync automatically creates new CIs, or correlates to existing CIs, for each Apple Mac, Windows PC or Windows Server found by Microsoft Defender.
Maintain CVE master list and impacted CI relationships
CI Sync automatically generates a master list of CVEs and creates a relationship to the impacted CIs. This allows organisations to every CI impacted by a given CVE. In addition, CI Sync provides customers with a CVSS threshold configuration setting. This allows customers to define the CVSS score used by CI Sync to determine the severity of CVEs to include/exclude when synchronizing CVEs to ServiceNow.
Maintain Per CI Related Lists for Installed Software and CVEs
CI Sync automatically generates the following related lists for each CI: The list of Installed Software per CI (i.e. installed software containing a known CVE). The list of CVEs for each Installed Software product.
Support for CVE lifecycle management
CI Sync works with a typical CVE resolution workflow by maintaining the CVE Status attribute per impacted CI. A typical lifecycle workflow consists of the following: CI Sync initially sets the CVE Status to “Unresolved”. Unresolved CVEs are those requiring a remediation task within the organization. Once the remediation task is completed, the resolver typically sets the CVE Status to “Resolved Pending”. Finally, when CI Sync detects the CVE has been removed from the device within the Microsoft Defender portal, CI Sync sets the CVE status to “Resolved Confirmed”.

Relationships

Frequently Asked Questions

CI Synchronizer Professional Edition provides a streamlined, out-of-the-box solution for businesses looking for efficient, hassle-free CMDB synchronisation without the need for extensive customisation.

CI Synchronizer Enterprise Edition offers advanced customisation and high-volume data handling capabilities, perfect for organisations with complex synchronisation needs and custom configuration requirements.

Many! Check out each source connector page for details of the supported assets and other records.

Yes. CI Synchronizer can detect which source records have changed since the previous synchronisation job and only sync the newly changed source data.

Throughput is affected by factors outside of the control of CI Synchronizer, however we see a typical throughput of between 200,000 and 400,000 records per hour (and even higher rates are possible).

Yes. CI Synchronizer has a highly customisable rules engine.  Amendment of some Standard (simple) default Data Sync Rules can be performed via the CI Sync Web User Interface and supported with Knowledge Base articles.  Amendment of Advanced Data Sync Rules or creation of Custom Data Sync Rules requires an “Extended Implementation and Ongoing Support Plan” available at an additional cost to your CI Sync Subscription Plan.

Visit the Support page for details on amending the Default CI Sync Data Sync Rules relative to the support plan (including no plan) offered by Syncfish.

Yes. Please fill and submit the Book a Demo form to set up a time to meet with one of the Syncfish team.

No. Each customer is provisioned with a dedicated CI Synchronizer instance.

Ultimately the customer decides, however Syncfish recommends hosting each customer instance physically close to the location of their ServiceNow instance (for best performance). It can be hosted in most/all Azure Regions globally (it is still hosted/managed/maintained by Syncfish, but the customer decides which geography it is physically located in).

No. The source asset data (read from the relevant source system by one of the CI Synchronizer connectors) is transited through your dedicated CI Synchronizer instance then deleted after it’s been processed into ServiceNow.

    Find out more

    Talk with us to find discover CI Synchronizer, the available connectors and the services we offer to help you achieve CMDB excellence.

    Book a Demo

    Schedule a demo. See up close how CI Synchronizer works and how quickly you can start syncronising your IT Asset data into your CMDB.

    Request a Trial

    Syncfish offers customers the chance to trial CI Synchronizer. Contact Sales or book a demo to find out how to get setup with a trial.