SAM license consumption allocation for single SSO with multiiple AD Groups

Juraj3
Tera Contributor

In ServiceNow SAM, how can license consumption be split when one SSO account is associated with multiple Active Directory groups representing different licensed products? We need to allocate distinct license costs to each product accordingly.

6 REPLIES 6

fknell
Kilo Patron

Hi @Juraj3,

In ServiceNow SAM Pro, you can split license consumption for a single SSO account across multiple products by mapping each Active Directory (SSO) group to a separate software model / entitlement and then using consumption rules or group allocations to tie each group to its own licensed product.

 

Key concept

- Each SSO group pulled from Azure AD / Entra ID appears as an SSO group in SAM Pro and can be linked to a Software Model for a specific licensed product.

- A single SSO account can belong to multiple SSO groups; SAM Pro reconciles consumption per group / software model, not per user account.

 

If you need to control which group consumes which entitlement, use group allocations or consumption rules so SAM Pro attributes licenses correctly per product.

 

Hope this helps!

Juraj3
Tera Contributor

Thank you for your reply. I have one more question.

We also use some direct integrations, but users are assigned to AD groups via SSO as well. How can I link different products from the direct integration to entitlements?

I can see that some software models were created automatically, but I expected more. I can find additional models created from Entra, so I am considering using the software models from Entra (SSO application) instead of those from the direct integration.

Would that change anything?

MikeW0609686430
Giga Guru

Alot depends on the use case. Are you referring to data which has been imported into SAM Pro from Entra or Okta? Or are you referring to on-prem AD license groups?

Juraj3
Tera Contributor

We receive data from Entra. As I understand it, there is an option in the SSO profile called “Enable group-based software model.” Once this option is checked, it creates the ability to link AD groups to software models.

Are there any additional requirements or settings for the associated software model records, such as conditions or other configurations?