Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Create a compute security group profile

A compute security group profile applies specified security rules to newly-provisioned resources. You map a compute security group profile to a cloud account, a datacenter, a Compute Security Group template, and security rules for the template.

Before you begin

You must have a cloud account with datacenters. You must run Discovery on the service accounts to populate the datacenters.

Role required: sn_cmp.cloud_admin

Procedure

  1. In the Cloud Admin Portal, navigate to Manage > Resource Profiles.

  2. In the Profiles list, select Compute Security Group Profile and then click New.

  3. Enter a unique and descriptive Name and Description for the profile and then click Submit.

    The profile is created.

  4. Map the profile to a template.

    1. In the list, click the profile that you created.

    2. In the Compute Security Group Profile Mappings related list, click New, fill in the form, and then click Submit.

Image omitted: compute-securitygrp-profile.png
Compute security group profile
FieldDescription
Cloud AccountSelect a cloud account for the profile.
LocationSelect the datacenter that belongs to the cloud account.
Compute Security Group Template \[cmdb\_ci\_security\_grp\_template\]

Select or create a template that the profile should be mapped to.To create a new template, click the list icon and then click New. Enter a name and a template ID and click Submit.

Click the reference icon (

Image omitted: icon-reference.png
Reference image) to view the details of the template.</p></td></tr></tbody>
  1. Add rules to the template.

    You can create more than one rule per template.

    1. In the Security Group Profile Mappings related list, under the Compute Security Group Template heading, click the template name.

    2. In the Compute Security Group Rule Template related list, click New, fill in the form, and then click Submit.

      FieldDescription
      CIDR RangeSpecify a CIDR range. For example, 10.0.0.0/24.
      IP ProtocolSelect an IP protocol. In Azure, the protocols supported are TDP and UDP. ICMP is not supported.
      From PortSpecify the source port number.
      Is OutboundEnter 0 for inbound and 1 for outbound.
      NameSpecify a name for the rule.
      Network TypeSelect the type of network.
      To PortSpecify the destination port number.

Parent Topic:Resource Profiles

Related topics

Discover all datacenters in a service account on-demand

sndocs is an independent community mirror and is not affiliated with or endorsed by ServiceNow.

ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc., in the United States and/or other countries. Other company and product names may be trademarks of the respective companies with which they are associated.

© 2026 ServiceNow, Inc. All rights reserved.

Documentation content is redistributed under the Apache License 2.0 from the ServiceNowDocs repository.