SAML Fedration Integration With ServiceNow

Subramanyam k 251 Reputation points
2020-08-18T12:22:07.19+00:00

Hi,

We have integrated Azure AD enterprise application with Servicenow Instance. As per below link there should be a mapping between Azure AD user with a User in Servicenow.

  1. It is a must the Azure AD user should be available in ServiceNow?. Do we have configuration that Azure Ad user is added to Service Now when login to servicenow for the first Time.

https://video2.skills-academy.com/en-us/azure/active-directory/saas-apps/servicenow-tutorial#configure-and-test-azure-ad-single-sign-on-for-servicenow

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
21,430 questions
0 comments No comments
{count} votes

Accepted answer
  1. soumi-MSFT 11,771 Reputation points Microsoft Employee
    2020-08-20T07:32:02.837+00:00

    @Subramanyam k , Just wanted to check if the above response helped in answering your query. Do let me know if there are any more queries around this so that we can help you further.

    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. soumi-MSFT 11,771 Reputation points Microsoft Employee
    2020-08-19T09:15:48.577+00:00

    @Subramanyam k , I believe your understanding is correct. I am not good with service now, but what I can say is ServiceNow does require your AAD users to exits in your ServiceNow Instance and Service now does support auto-provisioning.

    You can refer to the following docs for more info:

    User provisioning in Service Now: https://docs.servicenow.com/bundle/orlando-platform-administration/page/integrate/saml/concept/c_SAMLUserProvisioning.html
    Disclaimer: This response contains a reference to a third-party World Wide Web site. Microsoft is providing this information as a convenience to you. Microsoft does not control these sites and has not tested any software or information found on these sites; therefore, Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. There are inherent dangers in the use of any software found on the Internet, and Microsoft cautions you to make sure that you completely understand the risk before retrieving any software from the Internet.

    Enabling Auto-Provisioning in Azure AD for Service Now: https://video2.skills-academy.com/en-us/azure/active-directory/saas-apps/servicenow-provisioning-tutorial

    Hope this helps.

    Do let us know if this helps and if there are any more queries around this, please do let us know so that we can help you further. Also, please do not forget to accept the response as Answer; if the above response helped in answering your query.

    1 person found this answer helpful.
    0 comments No comments

  2. soumi-MSFT 11,771 Reputation points Microsoft Employee
    2020-08-19T07:24:48.48+00:00

    @Subramanyam k , Thank you for reaching out. The step you mentioned is a must as that step is used to make sure you have at least one AAD user present in the SAML application in your case its ServiceNow with the same NameIdentifier as configured in AAD. This step is referred to as pre-seeding of a user. This step is used to test the SSO for the newly added Gallery SAML application.

    Once the SSO is tested and made sure all the required claims are being passed properly to the SAML app from AAD, then we can enable the auto-provisioning or just normal manual provision of users from AAD to your SAML app.

    Hope this helps.

    Do let us know if this helps and if there are any more queries around this, please do let us know so that we can help you further. Also, please do not forget to accept the response as Answer; if the above response helped in answering your query.

    0 comments No comments

  3. Subramanyam k 251 Reputation points
    2020-08-19T09:08:02.127+00:00

    Thank You @soumi-MSFT .

    Based on the above response. Once the Azure AD is integrated with Servicenow and Tested Successfully with test user.
    The Azure AD users has to provisioned either automatically or manually using Azure AD Provision option.

    Without user provisioning from Azure Ad -> Servicenow, The user cannot login to servicenow instance.

    Please advise if my understanding is correct.

    Thanks

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.