Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

ServiceNow Azure AD integration with SCIM for user provisioning

manish62
Tera Contributor

Hello Team, 

I am doing the integration with Azure AD with SCIM plugin for user provisioning and completed the steps till connection, Azure AD is successfully connected with ServiceNow but when we try to create one user the getting error any sort of permission do we need to use in Azure side .

I have created one integration account but  not sure where to use this account as for generating the auth token using the client id and secret.

Tenant Url - https://instancename.service-now.com/api/now/scim

I am getting error when creating a single user from Azure to Servicenow-

Error-User 'abce@abc.com' will be created in customappsso (User is active and assigned in Microsoft Entra ID, but no matching User was found in customappsso)

Failed to create User 'abce@abc.com' in customappsso

Error code

Error message
UpdateForUnconnectedEntry

Please let me know any insight on this issue how could i resolve it.

Thanks,

Manish

5 REPLIES 5

AndersBGS
Tera Patron

Hi @manish62 

 

Just for information... We tried the same, but made a SOAP integration instead as recommend here: https://learn.microsoft.com/en-us/entra/identity/saas-apps/servicenow-provisioning-tutorial We unfortunatly hade to many errors with the SCIM solution.

 

If my answer has helped with your question, please mark my answer as the accepted solution and give a thumbs up.

Best regards
Anders

Rising star 2024
MVP 2025
linkedIn: https://www.linkedin.com/in/andersskovbjerg/

manish62
Tera Contributor

Thank you for your response

We selected the SCIM option because, when we tried using the out-of-the-box ServiceNow application, a message was displayed indicating that SCIM provisioning is required for this integration. Based on that recommendation, we proceeded with the SCIM-based configuration. we had no option to go with SOAP base integration.
 
Thanks
Manish Gupta

masonreed11
Tera Contributor

This looks more like a user-matching or attribute-mapping issue than an Azure permission problem. Check that the SCIM account has the required ServiceNow roles and that Azure’s userName/email mapping exactly matches the ServiceNow user record. Also verify the SCIM endpoint and authentication token, then test with a user whose UPN matches an existing ServiceNow user.

Thanks @masonreed11  for response.

We have created a dedicated integration account for this integration; however, we are unable to understand where this account is mapped or associated within the configuration. As part of the Azure AD integration, the connection is established using the tenant SCIM endpoint:

https://<instance_name>.service-now.com/api/now/v2/scim

along with the secret token that was generated through the OAuth Registry configuration as part of the SCIM plugin setup. We have also verified that the necessary attribute mappings are configured in the SCIM configuration. Given that the authentication appears to rely on the tenant URL and bearer token, we are trying to understand where and how the integration account is actually linked or utilized during the provisioning process.