- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2025 02:29 AM
Time Limited Roles (Elevated Access) Active Directory - ServiceNow integration
Dear ServiceNow Community,
The client I am working with has a requirement to establish a solution/configuration, whereby Users are given Elevated Access levels (in Active Directory), but only for a period of time (time limited).
This elevated access has to be enabled/disabled in Active Directory, but triggered from a ServiceNow Catalog Item and Flow. So for example the catalog request & Flow would be configured to trigger the enablement of the Role access (in AD) for the user, then after a specific period of time elapses (eg 2 hours or 1 day etc) the access (in AD) would be revoked, but triggered from ServiceNow (via the SN-AD spoke).
So I understand we can set up the ServiceNow - Active Directory spoke to automate Role access, but how would the solution/configuration look like, to achieve time-limited access in Active Directory, triggered from ServiceNow Flow & Catalog Request Item, as the original source?
Has anyone had to create this solution or can suggest a potential way of achieving this, through configuration in the Catalog Item and Flow.
I would really appreciated any advice/guidance/ideas, in case you may have come across this Use Case before.
Many Thanks.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2025 05:43 AM
If you already have the role access setup, it is just a matter of when to trigger. Make sure you have the start and end time available from the catalog item and trigger the integration on those times to set or remove the access.
Please mark any helpful or correct solutions as such. That helps others find their solutions.
Mark
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-09-2025 05:43 AM
If you already have the role access setup, it is just a matter of when to trigger. Make sure you have the start and end time available from the catalog item and trigger the integration on those times to set or remove the access.
Please mark any helpful or correct solutions as such. That helps others find their solutions.
Mark