CSM self-register process in csm environment and on the instance is SSO activated
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎07-11-2023 01:16 AM - edited ‎07-12-2023 10:14 PM
Hi everyone,
how you handle the ServiceNow self-register process in csm environment and on the instance is SSO activated. You don't want to create every consumer in your AD -> Overhead for the Admins and some consumer just want to report a issue once. And the self service register create you a user without any review of the record he can just login with his credential after he accepted the email. But how you can transfer his password for example to the ad that he can login SSO?
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0719767
Is this common use case that you bypass the SSO for the customer or consumer portal? To avoid overhead of create for every external users an AD account?
And another question.
How does the process work after that? With the registration. How that was done at other companies when SSO is enabled.
e.g. a customer registers in the portal -> SSO for this registration page removed. Then he gets the email -> Confirms his mail and the user is created by SN in the system automatically -> Can log in theoretically without the administrator has activated the account. -> Only not possible because SSO runs on the rest of the portal. But you don't want to create every external customer in the company AD. But also not completely disable SSO on the portal?
Thanks for give maybe some real life insides. Inputs here would be awesome.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
‎01-02-2024 08:43 PM
I'm new to CSM but from what I understand, it is common not to run SSO on the portal and use the local ServiceNow authentication for customers in this manner. You can also add an additional SSO source if they are primarily from the same organisation(s) and there is also OIDC which I believe allows your customers to use google and facebook to authenticate.