Overview
The SCCM integration enables ThreatAware to connect to your SCCM system for data collection and monitoring.Connection Method: Credentials
Setup Time: 15-20 minutes
Access Required: Administrator account
Setup instructions
1
Log in to the ThreatAware dashboard and navigate to **Settings** > **Systems**.
2
Use the search bar to find SCCM.
3
Click **Connect** and the following pop-up will appear.
Input Details**
4
Set up a user in SCCM with 'Read-Only Analyst' permissions.
5
Enter the credentials for this user into the form.
6
Create a port forward on the firewall to the SCCM server. Restrict access to the current ThreatAware AWS egress IP addresses.
For the up-to-date list of AWS IPs to whitelist, see the AWS Account / IP Whitelist Info link at the top of Settings → Integrations. The list is also documented in your tenant’s onboarding pack. (Two specific addresses were previously published here; do not hard-code IPs without checking the current live list.)Note: for tenants that prefer outbound-only connectivity, the PowerShell Relay is an alternative path for SCCM that avoids inbound firewall rules entirely.
7
Enter the public IP address along with the selected forwarded port for the SCCM server.
Troubleshooting
Connection Issues
Connection Issues
If you encounter connection errors:
- Verify your credentials are correct
- Check firewall rules allow outbound connections
- Ensure required ports are accessible
- Review the integration logs in ThreatAware
No Data Appearing
No Data Appearing
If data is not appearing after connecting:
- Wait 5-10 minutes for initial sync
- Verify the account has proper permissions
- Check the integration status in Settings
- Contact support if issues persist