Servicenow and LDAP integration through the MID Server for Auth/Authz

iammi
Kilo Explorer

Hello,

We have just purchased Servicenow and are about to set up the architecture.

The first things we are interested in are authentication/authorization.

As we don't have an IDP (Identity Provider), we are unable to produce SAML v2.0 token, so there is no way to implement SSO, do you Agree ?

If there is no way for SSO, then the second option is to use the corporate Active Directory for authentication via LDAPS : http://wiki.servicenow.com/index.php?title=LDAP_Integration

Please tell me if something is wrong in the following statements summarizing my understanding of Servicenow authentication/authorization mechanism.

  • LDAP integration for authentication is possible through the MID Server, so no need to think to put the LDAP instance on the DMZ (http://wiki.servicenow.com/index.php?title=LDAP_Integration_via_MID_Server_Setup)
  • The LDAP instance reside in the corporate Intranet (LAN) and we must set up a rooting rules form the MID Server (located in the DMZ), to the LDAP (port 636), in order to fulfill read-only operations.
  • The users (some of their attributes), must be imported into Servicenow database, via LDAP, it is recommended to do a regular refresh for keeping information up to date.
  • The authorization is managed at Servicenow level, and on Serviceow database, no way to manage authorizations based on LDAP groups located on the LDAP instance in the corporate LAN.
  • The MID Server is the only spot exposed to the public network in the company, no need to open a VPN connection with Servicenow.

In which case we can be obliged to have a VPN connection with Servicenow ?

If you have any ideas or best practices regarding our need, please do not hesitate to give us details.

  1. Regards.
1 ACCEPTED SOLUTION

tony_barratt
ServiceNow Employee
ServiceNow Employee

Hi AMMI,



Consider marking the question as answered, or marking replies as helpful as appropriate.


This will add value to Community Members reading this thread.



Best Regards



Tony


View solution in original post

11 REPLIES 11

tony_barratt
ServiceNow Employee
ServiceNow Employee

Hi AMMI,



Consider marking the question as answered, or marking replies as helpful as appropriate.


This will add value to Community Members reading this thread.



Best Regards



Tony


Hi,



We have just set up SSO integration for our development instance, after that SSO is working fine, but users getting logged in with only one users account : 'snowmidseruser'



we don't remember giving this user details during SSO set up.



urgent please help.



Regards


Yogish