We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

Minimum role requirments for ServiceNow user for Cisco Catalyst CMDB Integration

PriyaranjanJ
Tera Contributor

Hi Team,
We are currently implementing the ServiceNow Cisco Catalyst Integration strictly for CMDB Synchronization. We do not plan to use any ITSM functionalities (like Incident or Change management) at this stage.

The Cisco documentation states that the ServiceNow integration user requires the admin role. To comply with our company's security policies and the principle of least privilege, we cannot grant admin access to this integration account. Since our scope is limited to asset and configuration item syncing, what are the minimum granular roles other than mid_server/ cisco related roles that should be required to successfully run the CMDB synchronization?

Attaching documentation for reference.

https://store.servicenow.com/store/app/3cf8ab2e1be06a50a85b16db234bcbbb

https://www.cisco.com/c/en/us/support/docs/cloud-systems-management/catalyst-center/225381-walk-thro...

Thank you!!

1 REPLY 1

Tanushree Maiti
Tera Patron

Hi  @PriyaranjanJ 

 

In the installation guide -- It is clearly written , following persona with mentioned role is required for this integration.

 

      User Profiling : 

Ensure that there are 3 different users set up in your ServiceNow instance with the below mentioned access privileges.

Refer: https://store.servicenow.com/store/app/3cf8ab2e1be06a50a85b16db234bcbbb#linksAndDocuments

 

TanushreeMaiti_0-1782835418178.png

 

User 1: Admin User

  • Has admin role.
  • Will be able to install the app.
  • Will be able to perform ITOM set up to install and configure the mid sever.
  • Will be able to view the artefacts in the scoped app from sys_metadata.LIST and edit the artefacts.

 

User 2: AppAdmin User

  • Has the below rules
  • itil (itil default supplied ServiceNow role include other inherited roles. If the customer modifies the default itil role, then their Cisco Catalyst Center Integration may fail)
  • personalise_choices
  • x_caci_cisco_dna.incident_dna_update_user
  • x_caci_cisco_dna.change_dna_update_user
  • x_caci_cisco_dna.inventory_list_user
  • x_caci_cisco_dna.cisco_dna_controller_user
  • x_caci_cisco_dna.app_admin
  • The other inherited roles the user will have are,
    • dependency_views (inherited form itil)
    • cmdb_read (inherited form itil)
    • template_read_global (inherited form itil)
    • agent_workspace_user (inherited form itil)
    • workspace_user (inherited form itil)
    • interaction_agent (inherited form itil)
    • tracked_file_reader (inherited form itil)
    • snc_platform_rest_api_access (inherited form itil)
    • app_service_user (inherited form itil)
    • cmdb_query_builder (inherited form itil)
    • template_editor (inherited form itil)
    • view_changer (inherited form itil)
    • certification (inherited form itil)
    • import_transformer (inherited from x_caci_cisco_dna.app_admin)
  • x_caci_cisco_dna.IntegrationUser (inherited from x_caci_cisco_dna.app_admin)
  • x_caci_cisco_dna.issue_category_user (inherited from x_caci_cisco_dna.app_admin)
  • x_caci_cisco_dna.deviceimages_user (inherited from x_caci_cisco_dna.app_admin)
  • x_caci_cisco_dna.wireless_lan_controller_user (inherited from x_caci_cisco_dna.app_admin)

 

  • Can perform CMDB synchronization.
  • Can also enrich incident tickets created in ServiceNow with network context data from Cisco Catalyst Center.

 

User 3: Integration User

  • Has the below roles
  • Itil (itil default supplied ServiceNow role include other inherited roles. If the customer modifies the default itil role, then their Cisco Catalyst Center Integration may fail)
  • personalise_choices
  • import_transformer
  • x_caci_cisco_dna.change_dna_update_user
  • x_caci_cisco_dna.issue_category_user
  • x_caci_cisco_dna.IntegrationUser
  • The other inherited roles the user will have are,
    • dependency_views (inherited form itil)
    • cmdb_read (inherited form itil)
    • template_read_global (inherited form itil)
    • agent_workspace_user (inherited form itil)
    • workspace_user (inherited form itil)
    • interaction_agent (inherited form itil)
    • tracked_file_reader (inherited form itil)
    • snc_platform_rest_api_access (inherited form itil)
    • app_service_user (inherited form itil)
    • cmdb_query_builder (inherited form itil)
    • template_editor (inherited form itil)
    • view_changer (inherited form itil)
    • certification (inherited form itil)

 

  • Can transform the events received in the import set and map them to the target tables and perform closed loop integration.
  • Can perform CMDB synchronization

Note: It is recommended that we wnable the ‘Web service access only’ check box while creating the ‘Integration User’ so that this user can perform the integration related activities to create tickets, but cannot login to ServiceNow directly using this credential.

 

Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti