Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

ServiceNow and Entra ID Integration – Add User to On-Prem AD Group

abhijee
Tera Contributor

Hello Community,

 

We have a requirement where a user submits a ServiceNow Catalog Request for software access. Based on the selected software, ServiceNow should add/remove the user from the corresponding AD group.

We are planning to use ServiceNow → Microsoft Entra ID for this integration.

The issue is that the existing software groups are on-prem AD groups. They are synchronized and visible in Entra ID, but they are still managed by on-prem AD, so Entra cannot modify their membership.

We also cannot currently migrate these groups to cloud-native Entra groups due to an application dependency.

My question: What is the recommended/supported ServiceNow approach to add/remove users from these existing on-prem AD groups? Can this be done using a MID Server, AD integration, or any OOTB ServiceNow capability?

Thanks!

1 REPLY 1

Mehta
Tera Contributor

 , 

 

The Best way possible is to use "Microsoft Active Directory V2 Spoke". It will integrate your servicenow with onPrem System using Mid server. In the Spoke you have spoke for group management where you remove or add the account from groups. The above spokes uses PowerShell scripting and can be copied for customization easily to achieve your goals if not achieved through oob spokes.

In Microsoft Intra Id , you might not be able to achieve the same as it use Microsoft Graph API which do not have ability to manage all the groups. 

 

Reference: https://www.servicenow.com/docs/r/australia/integrate-applications/integration-hub/ms-ad-v2-spoke.ht...

 

Please Mark the reply as Correct or Helpful , if it solves your concern