ServiceNow IAM

Integrate with ServiceNow's services to execute CRUD operations for employee lifecycle processes.

Identity and Access Management · ServiceNow

Details

IDServiceNow IAM
ProviderServiceNow
CategoryIdentity and Access Management
From Version6.0.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAttack Surface Management Exposure Management Agentix Cortex Cloud Cloud Runtime Security Cloud Posture Security XSIAM EDR

README

Note: This integration should be used along with our IAM premium pack. For further details, visit our IAM pack documentation.

Integrate with ServiceNow’s services to perform Identity Lifecycle Management operations.
This integration was integrated and tested with London version of ServiceNow.
For more information, please refer to the Identity Lifecycle Management article.

Configure ServiceNow IAM in Cortex

Parameter Description Required
ServiceNow URL (https://domain.service-now.com)   True
ServiceNow API Version (e.g. ‘v1’). Specify this value to use an endpoint version other than the latest.   False
Username   True
Password   True
Trust any certificate (not secure)   False
Use system proxy settings   False
Allow creating users   False
Allow updating users   False
Allow enabling users   False
Allow disabling users   False
Automatically create user if not found in update command   False
Incoming Mapper   True
Outgoing Mapper Cortex XSOAR only parameter. False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

iam-create-user


Creates a user.

Base Command

iam-create-user

Input

Argument Name Description Required
user-profile User Profile indicator details. Required
allow-enable Enable the user. Optional

Context Output

Path Type Description
IAM.Vendor.active Boolean If true, the employee’s status is active, otherwise false.
IAM.Vendor.brand String Name of the integration.
IAM.Vendor.details string Indicates if the API was successful or provides error information.
IAM.Vendor.email String The employee’s email address.
IAM.Vendor.errorCode Number HTTP error response code.
IAM.Vendor.errorMessage String Reason why the API failed.
IAM.Vendor.id String The employee’s user ID in the app.
IAM.Vendor.instanceName string Name of the integration instance.
IAM.Vendor.success Boolean If true, the command was executed successfully, otherwise false.
IAM.Vendor.username String The employee’s username in the app.

Command Example

!iam-create-user user-profile=`{"email":"testdemisto2@paloaltonetworks.com", "givenname":"Test","surname":"Demisto"}`

Human Readable Output

Create User Results (ServiceNow IAM)

brand instanceName success active id email details
ServiceNow IAM ServiceNow IAM_instance_1 true true edab746f1b142410042611b4bd4bcb23 testdemisto2@paloaltonetworks.com calendar_integration: 1
country:
user_password:
last_login_time:
source:
sys_updated_on: 2020-11-11 14:55:48
building:
web_service_access_only: false
notification: 2
enable_multifactor_authn: false
sys_updated_by: admin
sys_created_on: 2020-11-11 14:55:48
sys_domain: {“link”: “https://ven03941.service-now.com/api/now/table/sys_user_group/global”, “value”: “global”}
state:
vip: false
sys_created_by: admin
zip:
home_phone:
time_format:
last_login:
default_perspective:
active: true
sys_domain_path: /
cost_center:
phone:
name: Test Demisto
employee_number:
password_needs_reset: false
gender:
city:
failed_attempts:
user_name:
roles:
title:
sys_class_name: sys_user
sys_id: edab746f1b142410042611b4bd4bcb23
internal_integration_user: false
ldap_server:
mobile_phone:
street:
company:
department:
first_name: Test
email: testdemisto2@paloaltonetworks.com
introduction:
preferred_language:
manager:
locked_out: false
sys_mod_count: 0
last_name: Demisto
photo:
avatar:
middle_name:
sys_tags:
time_zone:
schedule:
date_format:
location:

iam-update-user


Updates an existing user with the data passed in the user-profile argument.

Base Command

iam-update-user

Input

Argument Name Description Required
user-profile A User Profile indicator. Required
allow-enable Enable the user. Optional

Context Output

Path Type Description
IAM.Vendor.active Boolean If true, the employee’s status is active, otherwise false.
IAM.Vendor.brand String Name of the integration.
IAM.Vendor.details string Indicates if the API was successful or provides error information.
IAM.Vendor.email String The employee’s email address.
IAM.Vendor.errorCode Number HTTP error response code.
IAM.Vendor.errorMessage String Reason why the API failed.
IAM.Vendor.id String The employee’s user ID in the app.
IAM.Vendor.instanceName string Name of the integration instance.
IAM.Vendor.success Boolean If true, the command was executed successfully, otherwise false.
IAM.Vendor.username String The employee’s username in the app.

Command Example

!iam-update-user user-profile=`{"email":"testdemisto2@paloaltonetworks.com", "givenname":"Test","surname":"Demisto_updated"}`

Human Readable Output

Update User Results (ServiceNow IAM)

brand instanceName success active id email details
ServiceNow IAM ServiceNow IAM_instance_1 true true edab746f1b142410042611b4bd4bcb23 testdemisto2@paloaltonetworks.com calendar_integration: 1
country:
user_password:
last_login_time:
source:
sys_updated_on: 2020-11-11 14:55:48
building:
web_service_access_only: false
notification: 2
enable_multifactor_authn: false
sys_updated_by: admin
sys_created_on: 2020-11-11 14:55:48
sys_domain: {“link”: “https://ven03941.service-now.com/api/now/table/sys_user_group/global”, “value”: “global”}
state:
vip: false
sys_created_by: admin
zip:
home_phone:
time_format:
last_login:
default_perspective:
active: true
sys_domain_path: /
cost_center:
phone:
name: Test Demisto_updated
employee_number:
password_needs_reset: false
gender:
city:
failed_attempts:
user_name:
roles:
title:
sys_class_name: sys_user
sys_id: edab746f1b142410042611b4bd4bcb23
internal_integration_user: false
ldap_server:
mobile_phone:
street:
company:
department:
first_name: Test
email: testdemisto2@paloaltonetworks.com
introduction:
preferred_language:
manager:
locked_out: false
sys_mod_count: 0
last_name: Demisto_updated
photo:
avatar:
middle_name:
sys_tags:
time_zone:
schedule:
date_format:
location:

iam-get-user


Retrieves a single user resource.

Base Command

iam-get-user

Input

Argument Name Description Required
user-profile A User Profile indicator. Required

Context Output

Path Type Description
IAM.Vendor.active Boolean If true, the employee’s status is active, otherwise false.
IAM.Vendor.brand String Name of the integration.
IAM.Vendor.details string Indicates if the API was successful or provides error information.
IAM.Vendor.email String The employee’s email address.
IAM.Vendor.errorCode Number HTTP error response code.
IAM.Vendor.errorMessage String Reason why the API failed.
IAM.Vendor.id String The employee’s user ID in the app.
IAM.Vendor.instanceName string Name of the integration instance.
IAM.Vendor.success Boolean If true, the command was executed successfully, otherwise false.
IAM.Vendor.username String The employee’s username in the app.

Command Example

!iam-get-user user-profile=`{"email":"testdemisto2@paloaltonetworks.com"}`

Human Readable Output

Get User Results (ServiceNow IAM)

brand instanceName success active id email details
ServiceNow IAM ServiceNow IAM_instance_1 true true edab746f1b142410042611b4bd4bcb23 testdemisto2@paloaltonetworks.com calendar_integration: 1
country:
user_password:
last_login_time:
source:
sys_updated_on: 2020-11-11 14:55:48
building:
web_service_access_only: false
notification: 2
enable_multifactor_authn: false
sys_updated_by: admin
sys_created_on: 2020-11-11 14:55:48
sys_domain: {“link”: “https://ven03941.service-now.com/api/now/table/sys_user_group/global”, “value”: “global”}
state:
vip: false
sys_created_by: admin
zip:
home_phone:
time_format:
last_login:
default_perspective:
active: true
sys_domain_path: /
cost_center:
phone:
name: Test Demisto_updated
employee_number:
password_needs_reset: false
gender:
city:
failed_attempts:
user_name:
roles:
title:
sys_class_name: sys_user
sys_id: edab746f1b142410042611b4bd4bcb23
internal_integration_user: false
ldap_server:
mobile_phone:
street:
company:
department:
first_name: Test
email: testdemisto2@paloaltonetworks.com
introduction:
preferred_language:
manager:
locked_out: false
sys_mod_count: 0
last_name: Demisto_updated
photo:
avatar:
middle_name:
sys_tags:
time_zone:
schedule:
date_format:
location:

iam-disable-user


Disable an active user.

Base Command

iam-disable-user

Input

Argument Name Description Required
user-profile A User Profile indicator. Required

Context Output

Path Type Description
IAM.Vendor.active Boolean If true, the employee’s status is active, otherwise false.
IAM.Vendor.brand String Name of the integration.
IAM.Vendor.details string Indicates if the API was successful or provides error information.
IAM.Vendor.email String The employee’s email address.
IAM.Vendor.errorCode Number HTTP error response code.
IAM.Vendor.errorMessage String Reason why the API failed.
IAM.Vendor.id String The employee’s user ID in the app.
IAM.Vendor.instanceName string Name of the integration instance.
IAM.Vendor.success Boolean If true, the command was executed successfully, otherwise false.
IAM.Vendor.username String The employee’s username in the app.

Command Example

!iam-disable-user user-profile=`{"email":"testdemisto2@paloaltonetworks.com"}`

Human Readable Output

Disable User Results (ServiceNow IAM)

brand instanceName success active id email details
ServiceNow IAM ServiceNow IAM_instance_1 true false edab746f1b142410042611b4bd4bcb23 testdemisto2@paloaltonetworks.com calendar_integration: 1
country:
user_password:
last_login_time:
source:
sys_updated_on: 2020-11-11 14:55:48
building:
web_service_access_only: false
notification: 2
enable_multifactor_authn: false
sys_updated_by: admin
sys_created_on: 2020-11-11 14:55:48
sys_domain: {“link”: “https://ven03941.service-now.com/api/now/table/sys_user_group/global”, “value”: “global”}
state:
vip: false
sys_created_by: admin
zip:
home_phone:
time_format:
last_login:
default_perspective:
active: false
sys_domain_path: /
cost_center:
phone:
name: Test Demisto_updated
employee_number:
password_needs_reset: false
gender:
city:
failed_attempts:
user_name:
roles:
title:
sys_class_name: sys_user
sys_id: edab746f1b142410042611b4bd4bcb23
internal_integration_user: false
ldap_server:
mobile_phone:
street:
company:
department:
first_name: Test
email: testdemisto2@paloaltonetworks.com
introduction:
preferred_language:
manager:
locked_out: false
sys_mod_count: 0
last_name: Demisto_updated
photo:
avatar:
middle_name:
sys_tags:
time_zone:
schedule:
date_format:
location:

Configuration parameters

  • url — ServiceNow URL (https://<domain>.service-now.com) (required)
  • api_version — ServiceNow API Version (e.g. 'v1'). Specify this value to use an endpoint version other than the latest.
  • credentials — Username (required)
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • create_user_enabled — Allow creating users
  • update_user_enabled — Allow updating users
  • enable_user_enabled — Allow enabling users
  • disable_user_enabled — Allow disabling users
  • create_if_not_exists — Automatically create user if not found in update command
  • mapper_in — Incoming Mapper (required)
  • mapper_out — Outgoing Mapper

Commands (5)

  • get-mapping-fields

    Retrieves a User Profile schema, which holds all of the user fields within the application. Used for outgoing-mapping through the Get Schema option.

  • iam-create-user

    Creates a user in ServiceNow.

  • iam-disable-user

    Disable an active user.

  • iam-get-user

    Retrieves a single user resource.

  • iam-update-user

    Updates an existing user with the data passed in the user-profile argument.

## Prerequisites
To use ServiceNow in XSOAR, ensure your user account has the `rest_api_explorer`, `web_service_admin` roles or any other role required to permit working with the `sys_user` table. These roles are required in order to make API calls. However, they may not suffice for viewing records in some tables.

## Enable/Disable CRUD Commands
You can select which CRUD commands are enabled in the integration instance configuration settings. By default, all commands are enabled.

## Add Custom Indicator Fields
Follow these steps to add custom fields to the User Profile indicator.

1. In XSOAR, create the custom indicator and incident field, for example, **Middle Name**.
2. Duplicate the **User Profile - ServiceNow (Incoming)** mapper and/or the **User Profile - ServiceNow (Outging)** mapper.
3. Add and map the custom field to the necessary mapper(s).
4. Go to the ServiceNow IAM integration instance and in the mapper textbox, replace the name of the default mapper with the custom mapper you created.

## Automatically create user if not found in update command
The *create-if-not-exists* parameter specifies if a new user should be created when the User Profile passed was not found in the 3rd-party integration.