Integrating with Microsoft Entra ID
You can integrate your ServiceNow instance with Microsoft Entra ID to view software usage for all connected SSO applications.
| Process | Required user role in the Microsoft Entra ID application | Authentication scopes |
|---|---|---|
|
Application developer |
|
| Download applications | Application developer |
|
|
|
|
| Reclaim subscriptions | User Administrator | User.ReadWrite.All |
Create a Microsoft Entra ID application
Create an app in the Microsoft Entra ID portal to integrate with the ServiceNow AI Platform.
始める前に
Microsoft Entra ID Role required: Refer to the Minimal users permission table.
手順
Create a Microsoft Entra ID integration profile
Create a Microsoft Entra ID integration profile in your ServiceNow instance.
始める前に
To create a Microsoft Entra ID integration profile, request the Software Asset Management - SaaS License Management plugin (sn_sam_saas_int) from the ServiceNow Store.
ServiceNow Role required: sam_integrator
このタスクについて
If you’re using Software Asset Workspace, the option to create the Microsoft Entra ID integration profile in Core UI is inactive.
手順
タスクの結果
After you publish the integration profile and connect applications to the profile, you can view events performed by individual users up to 60 days prior to the current date. For more information, see Review a software reclamation rule.
Connect SSO apps
Connect a Single Sign-On (SSO) app to view all users and groups with access to the app. Track user login data and reclaim unused licenses.
始める前に
Role required: sam_integrator
このタスクについて
- If the Assignment required toggle button is set to Yes, you must assign this application to the Microsoft Entra ID users and related applications and services. After you assign the application, Microsoft Entra ID users, associated applications, and services can access it.
- If the Assignment required toggle button is set to No, all users can log in to the application. The associated applications and services can also obtain an access token to this service.
SaaS License Management offers direct integrations with select applications. Direct integrations provide the most robust usage data. For a list of available direct integrations, see Integrate with SaaS applications. If you have a direct integration for an app, connecting the same app in an SSO integration creates duplicate subscription records in your ServiceNow instance. If you connect an SSO app and later decide to create a direct integration for that app, disconnect the app before creating a direct integration.
手順
タスクの結果
- If the Assignment required toggle button is set to Yes for an application in the Microsoft Entra ID portal, the subscription is created only for users assigned to that specific application.
- If the Assignment required toggle button is set to No for an application in the Microsoft Entra ID portal, the subscription is created for all Microsoft Entra ID users.
次のタスク
Review all automatically generated reclamation rules to meet your specifications for reclaiming user subscriptions. For more information, see Review a software reclamation rule.
- SSO Applications
- Directory Users
- Scheduled Jobs
- Scheduled Job Results
- Directory Jobs
- Directory Job Results
- Subscription User Exclusion Rule
After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see Subscription exclusions for SaaS and SSO applications.
Create software entitlements for the automatically generated software models to track used software against owned software. For more information on creating software entitlements in the Software Asset Management classic application, see Create entitlements in Software Asset Management classic. For more information on creating software entitlements in the Software Asset Workspace, see Create entitlements in workspace. For more information on creating software entitlements using the Software Asset Management Playbook, see Create entitlements using the guided walk-through.
Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the License Workbench (Software Asset Management classic application) or the License usage view (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance. For more information on running reconciliation in the Software Asset Management classic application, see Run software reconciliation in Software Asset Management classic. For more information on running reconciliation in the Software Asset Workspace, see Run software reconciliation in the workspace.