How to integrate ADManager Plus with ServiceNow to streamline identity life cycle management

How to integrate ADManager Plus with ServiceNow to streamline identity life cycle management

How to integrate ADManager Plus with ServiceNow to streamline identity life cycle management

Overview

ServiceNow is a cloud-based platform that provides a unified solution for managing tasks, processes, and services within an organization. Integrating ServiceNow with ADManager Plus for user life cycle management can aid businesses to efficiently manage the entire journey of an user within an organization, from their initial onboarding to eventual offboarding.

Integrating ServiceNow with ADManager Plus for user life cycle management can aid businesses to efficiently manage the entire journey of an user within an organization, from their initial onboarding to eventual offboarding. This integration streamlines the user access request process, reducing manual effort, ensuring prompt access to resources, and enhancing compliance and security.

Key highlights of integrating ADManager Plus with ServiceNow

  • Role-based access controls: Assign and adjust permissions for users in ServiceNow based on role changes in AD using ADManager Plus, ensuring secure, accurate access aligned with job responsibilities.

  • Automated user account management: Fetch account details from the tickets submitted through ServiceNow for new user account creation, modification, or deletion, and automatically execute them. These requests can include all necessary details such as employee name, department, role, and required access levels.

 

How to integrate ADManager Plus and ServiceNow

ADManager Plus offers flexible endpoint configuration options to suit your organizational goals and needs. Two types of webhooks, inbound and outbound webhooks, determine how data can be synchronized between ServiceNow and ADManager Plus. ADManager Plus can be integrated with ServiceNow by performing the following steps:

  1. Authorization configuration

Configure the authorization method to authorize API requests.

  1. Inbound webhook configuration

Configure endpoints to fetch user data from ServiceNow.

  1. Outbound webhook configuration

Configure an API to sync data from ADManager Plus to ServiceNow.

 

Pre-requisites 

Please ensure to provide the user account credentials with permissions to retrieve desired information and perform tasks in ServiceNow. Refer to ServiceNow API references for more details.  

 Authorization configuration 

  1. Log in to ADManager Plus and navigate to the Automation tab.

  2. In the left pane, under Configuration, click Application Integrations.

  3. Under Enterprise Applications, click ServiceNow.

  4. Toggle the Enable ServiceNow Integration button on.

  5. In the ServiceNow Configuration page, click Authorization.

  6. ServiceNow uses Basic Authentication to authorize API requests. Specify your ServiceNow credentials in the Username and Password fields

  7. Select Header from the Add To drop-down list.

  8. Click Configure.

 

Inbound webhook configuration

Inbound webhook enables you to fetch users' data from ServiceNow to ADManager Plus. The pre-configured API allows you to import all the user from ServiceNow. However, if you would like to selectively import users, you can either modify the pre-configured endpoint, configure a new endpoint as per ServiceNow's API references, or use Advanced Filters in automation. The attribute mapping configured in this section can be selected as the data source while setting up an automation configuration. To configure an inbound webhook for ServiceNow:

  1. Under Inbound Webhook, click ServiceNow Endpoint Configuration.

  2. In the Endpoint Configuration tab, the Endpoint URL, API Method, Headers, and Parameters fields are pre-configured. You can either use the pre-configured endpoint or configure and use a new endpoint using the + Add API endpoint button. Click here to learn how to configure a new endpoint.

  3. In the Settings tab, Repeat Calling This Endpoint option is enabled to repeatedly call the API until you get the required response. In the Repeat Call Configuration drop-down menu, select the headers and parameters and specify the value, along with whether it needs to be incremented, appended or replaced. You can also set a condition in the Repeat Call Criteria field, which when satisfied calls the endpoint repeatedly.

  4. For instance, this option can be configured to repeatedly call the endpoint through the pages by increasing the page value in the concurrent calls until the response is empty.

Note:

    • You can add macros to your endpoint URL to dynamically change it as per your requirement while fetching object-related data from the endpoint.

    • Refer to ServiceNow's API references to know the Parameters that must be configured to fetch only specific parameters.

    • The Message Type field can be customized as per your organization's needs.

  • Once done, click Test & Save. A response window will display all the requested parameters that can be fetched using the API call. Click Proceed.

Note:

  • Refer to ServiceNow's API references to know the Parameters that must be configured to fetch only specific parameters.

  • You can configure multiple endpoints for ServiceNow using the + Add API endpoint button. Click here to learn how.

  1. Click Data Source - LDAP Attribute Mapping to match endpoints and to map AD LDAP attributes with the respective attributes in ServiceNow.

  2. Click + Add New Configuration and perform the following:

    • Enter the Configuration Name and Description and select the Automation Category from the drop-down menu.

    • In the Select Endpoint field, select the desired endpoint and a Primary Key that is unique to a user (e.g. employeeIdenifier).

Note: When multiple endpoints are configured, this attribute must hold the same value in all the endpoints.

    • In the Attribute Mapping field, select the attribute from the LDAP Attribute Name drop-down menu and map it with the respective column in ServiceNow.

  • Click Save.

 

Outbound webhook configuration

Outbound webhook allows you to send changes made in AD using ADManager Plus to ServiceNow Suite. The webhooks configured in this section can be included in Orchestration Templates, which in turn can be used during event-driven and scheduled automations. They can also be applied directly on desired users to perform a sequence of actions on them (Management > Advanced Management > Orchestration). To configure an outbound webhook for ServiceNow:

  1. Under Outbound Webhook, click ServiceNow Webhook Configuration.

  2. Click + Add Webhook.

  3. Enter a name and description for this webhook.

  4. Decide on the action that has to be performed and refer to ServiceNow's API references for API details such as URL, headers, parameters, and other requirements.

  5. Select from the drop-down menu the HTTP method that will enable you to perform the desired action on the endpoint.

  6. Enter the endpoint URL.

  7. Configure the Headers, Parameters, and Message Type in the appropriate format based on the API call that you would like to perform.

  8. Click Test and Save.

  9. A pop up window will then display a list of AD users and groups to test the configured API call. Select the desired AD user or group over which this API request has to be tested and click OK. This will make a real-time call to the endpoint URL, and the selected objects will be modified as per the configuration.

  10. The webhook response and request details will then be displayed. Verify them for the expected API behavior and click Save.

 

Actions that can be automated in ADManager Plus  

Upon integration, administrators can configure automations to carry out the desired tasks. These automations can be monitored and controlled by implementing multi-level business workflows, which ensure that they are reviewed and approved before execution. The following are some sample actions that can be automated:

  • Create user accounts

  • Add users to groups

  • Modify user attributes

  • Remove users from groups

  • Modify user accounts by template

  • Create mailbox

  • Reset passwords

  • Disable or delete mailbox

  • Unlock user accounts

  • Move Home Folder

  • Enable user accounts

  • Delete Home Folder

  • Disable user accounts

  • Revoke Microsoft 365 licenses

  • Delete user accounts

  • Manage users' photos

  • Run custom scripts

  • Disable Lync accounts

  • Move users across groups

  • Configure auto reply settings

 

This list is not exhaustive; to get a list of all the actions that can be automated by selecting ServiceNow as the data source, click here

                  New to ADSelfService Plus?