Azure AD integration, User Group Provisioning

Jamsta1912
Tera Guru

Hello all,

We're in the process of setting up SSO and User / Group provisioning through an integration with Azure AD.
We're using the documents here:

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/servicenow-tutorial

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/servicenow-provisioning-tutorial

We have the SSO and User Provisioning working in DEV, but we're not able to get user groups (and user group membership) to come across from Azure. Has anyone out there got this set up and working, and any thoughts on where we might be going wrong? I appreciate this is more likely to be an Azure-side config issue, rather than ServiceNow-side... but I could be wrong about that.

Thanks

Jamie

3 REPLIES 3

Nasir
Giga Contributor

Hi Jamie,

A bit late to reply but yes I have done this in our all environments and group and user provisioning is working.

I think the challenge you might be facing is in attribute mapping, I have attached the screenshot of the attribute mapping I have setup, see if that helps.

 

Please mark helpful is this resolves your issue.

 

find_real_file.png

Thank you Nasir. We did eventually get this working. But... I don't know precisely what our issue was. I was taking care of the ServiceNow side while a colleague took care of the Azure side. He did a slight rework and we were away, so yes I think something to do with the attribute mapping as you say.

Are you guys mapping Azure group owner by chance? Trying to figure out if we can map that from Azure to SN.