---
sourceDocument: Xanadu Create Integrations with Applications
sourceDocumentLink: https://www.servicenow.com/docs/r/xanadu/integrate-applications

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Create Integrations with Applications

ft:clusterId :

    - crint

bundleId :

    - crint

workflow :

    - Creator


---

# Microsoft Entra Entitlement Management Spoke

# Microsoft Entra Entitlement Management Spoke {#ariaid-title1}

* Release version: Xanadu
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Retrieves details of access packages and access package assignments in Microsoft Entra Entitlement Management from your ServiceNow instance.

## Integration Hub subscription {#ms-entra-ent-mgmt-spk__section_qqr_nvt_33c}

This spoke requires an Integration Hub subscription. For more information, see [Legal schedules - IntegrationHub overview](https://www.servicenow.com/content/dam/servicenow-assets/public/en-us/doc-type/legal/snc-addendum-integrationhub.pdf).

## Supported versions {#ms-entra-ent-mgmt-spk__section_shk_1vt_33c}

This spoke was built for Microsoft Entra Entitlement Management v1.0, but may be compatible with later versions.

## Spoke dependencies {#ms-entra-ent-mgmt-spk__section_xhk_1vt_33c}

If you're having trouble installing the app, ensure that these dependent plugins are installed:

* Complex Object (com.glide.cobject)
* ServiceNow IntegrationHub Runtime (com.glide.hub.integration.runtime)
* ServiceNow IntegrationHub Action Template - Data Stream (com.glide.hub.action_type.datastream)
* ServiceNow IntegrationHub Action Step - REST (com.glide.hub.action_step.rest)
{#ms-entra-ent-mgmt-spk__ul_yhk_1vt_33c}  
Note:  
Some of these plugins are licensable features and require appropriate licenses, if used outside the spoke implementation.

## Microsoft Entitlement Management account requirements {#ms-entra-ent-mgmt-spk__section_y2y_3wt_33c}

The Microsoft Entitlement Management spoke requires creating a custom app on your Microsoft Entra account to generate OAuth 2.0 tokens. See: [Create a custom application in Azure portal](https://www.servicenow.com/docs/ONFm1DlMdlPVhYIIamis4Q#create-app-entra-ent-spk-azure "Create a custom app using your Azure portal to enable OAuth 2.0 authentication with the Microsoft Entra Entitlement Management spoke.").

## Spoke actions {#ms-entra-ent-mgmt-spk__section_d3k_1vt_33c}

The Microsoft Entra Entitlement Management spoke provides actions to automate entitlement management tasks when events occurs in your ServiceNow instance. Available actions include:  
Note:  
To use the actions, ensure that you provide at least one of the required permissions.  
{#ms-entra-ent-mgmt-spk__table_e3k_1vt_33c__entry__4}

| Category | Action | Description | Permissions Required (from least to most privileged) ||
|-|-|-|-|-|
| Access Package Assignment Management | Look up Access Package Assignment | Retrieves the details of the specified access package assignment. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Assignment Management | Look up Access Package Assignment | Retrieves the details of the specified access package assignment. | Delegated (personal Microsoft account) | Not supported |
| Access Package Assignment Management | Look up Access Package Assignment | Retrieves the details of the specified access package assignment. | Application | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Assignment Management | Look up Access Package Assignments Stream | Retrieves the list of all the assignments (both active and expired) that the caller has access to read, across all catalogs and access packages. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Assignment Management | Look up Access Package Assignments Stream | Retrieves the list of all the assignments (both active and expired) that the caller has access to read, across all catalogs and access packages. | Delegated (personal Microsoft account) | Not supported |
| Access Package Assignment Management | Look up Access Package Assignments Stream | Retrieves the list of all the assignments (both active and expired) that the caller has access to read, across all catalogs and access packages. | Application | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Assignment Management | Look up Access Package Assignments Stream by User | Retrieves the list of all the assignments (active and expired) that the caller has access to read, across all catalogs and access packages where the signed-in user is the target. Signed-in user is the user whose Entra credentials were used while generating the token. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Assignment Management | Look up Access Package Assignments Stream by User | Retrieves the list of all the assignments (active and expired) that the caller has access to read, across all catalogs and access packages where the signed-in user is the target. Signed-in user is the user whose Entra credentials were used while generating the token. | Delegated (personal Microsoft account) | Not supported |
| Access Package Assignment Management | Look up Access Package Assignments Stream by User | Retrieves the list of all the assignments (active and expired) that the caller has access to read, across all catalogs and access packages where the signed-in user is the target. Signed-in user is the user whose Entra credentials were used while generating the token. | Application | Not supported |
| Access Package Management | Look up Access Package | Retrieves the details of the specified access package. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Management | Look up Access Package | Retrieves the details of the specified access package. | Delegated (personal Microsoft account) | Not supported |
| Access Package Management | Look up Access Package | Retrieves the details of the specified access package. | Application | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Management | Look up Access Packages Stream | Retrieves the list of all access packages across all catalogs. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Management | Look up Access Packages Stream | Retrieves the list of all access packages across all catalogs. | Delegated (personal Microsoft account) | Not supported |
| Access Package Management | Look up Access Packages Stream | Retrieves the list of all access packages across all catalogs. | Application | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Management | Look up Access Packages Stream by User | Retrieves the list of all access packages across all catalogs for which the signed-in user is allowed to submit access requests. Signed-in user is the user whose Entra credentials were used while generating the token. | Delegated (work or school account) | EntitlementManagement.Read.All, EntitlementManagement.ReadWrite.All |
| Access Package Management | Look up Access Packages Stream by User | Retrieves the list of all access packages across all catalogs for which the signed-in user is allowed to submit access requests. Signed-in user is the user whose Entra credentials were used while generating the token. | Delegated (personal Microsoft account) | Not supported |
| Access Package Management | Look up Access Packages Stream by User | Retrieves the list of all access packages across all catalogs for which the signed-in user is allowed to submit access requests. Signed-in user is the user whose Entra credentials were used while generating the token. | Application | Not supported |
[ ]

{#ms-entra-ent-mgmt-spk__table_e3k_1vt_33c}

## Connection and credential alias requirements {#ms-entra-ent-mgmt-spk__section_k3k_1vt_33c}

Integration Hub uses aliases to manage connection and credential information, and OAuth credentials. Using an alias eliminates the need to configure multiple credentials and connection information
profiles when using multiple environments. If the connection or credential information changes, you don't need to update any actions that use the connection.

