Skip to main content

Overview

The SCCM integration enables ThreatAware to connect to your SCCM system for data collection and monitoring.
Connection Method: Credentials Setup Time: 15-20 minutes Access Required: Administrator account

Setup instructions

1

Log in to the ThreatAware dashboard and navigate to **Settings** > **Systems**.

2

Use the search bar to find SCCM.

3

Click **Connect** and the following pop-up will appear.

Input Details**
4

Set up a user in SCCM with 'Read-Only Analyst' permissions.

5

Enter the credentials for this user into the form.

6

Create a port forward on the firewall to the SCCM server. Restrict access to the current ThreatAware AWS egress IP addresses.

For the up-to-date list of AWS IPs to whitelist, see the AWS Account / IP Whitelist Info link at the top of Settings → Integrations. The list is also documented in your tenant’s onboarding pack. (Two specific addresses were previously published here; do not hard-code IPs without checking the current live list.)Note: for tenants that prefer outbound-only connectivity, the PowerShell Relay is an alternative path for SCCM that avoids inbound firewall rules entirely.
7

Enter the public IP address along with the selected forwarded port for the SCCM server.

Troubleshooting

If you encounter connection errors:
  • Verify your credentials are correct
  • Check firewall rules allow outbound connections
  • Ensure required ports are accessible
  • Review the integration logs in ThreatAware
If data is not appearing after connecting:
  • Wait 5-10 minutes for initial sync
  • Verify the account has proper permissions
  • Check the integration status in Settings
  • Contact support if issues persist

Additional resources

For more information, contact ThreatAware support.