Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

Managing New and Termed AD accounts

DaveThibode
Tera Contributor

Hello everyone,

I'm interested in learning how other organizations are using ServiceNow to automate employee onboarding and offboarding processes.

Today, our process looks something like this:

  1. HR enters a new employee into our HR system.
  2. An API creates the user record in ServiceNow, and a separate tool creates the Active Directory account.
  3. The account is automatically added to a specific AD group using yet another tool so Microsoft Entra ID can provision the user into additional platforms.
  4. We then assign the appropriate distribution groups, security groups, and application access based on the employee's role manually.

We are evaluating whether ServiceNow could take on more of this automation, and I'd like to understand how others are approaching it.

A few questions:

  • Are you using ServiceNow to automatically assign AD security groups, distribution groups, or Organizational Units (OUs) based on attributes such as department, title, location, or manager?
  • Are you using HRSD lifecycle events, Flow Designer, Integration Hub, or custom workflows to drive provisioning activities?
  • Do you have integrations or APIs connected to downstream applications that automatically create, update, or remove accounts when a hire, transfer, or termination event occurs?
  • For offboarding, does ServiceNow orchestrate account deactivation and access removal across systems, or is that handled by other identity management tools?
  • If you're leveraging Entra ID, Okta, SailPoint, or another IAM platform, how are responsibilities divided between ServiceNow and your identity platform?

I'm particularly interested in hearing how organizations have automated application provisioning and deprovisioning across multiple platforms and what has worked well for you.

Thanks in advance for sharing your experiences.

0 REPLIES 0